See all jobs on JobTailor
Search thousands of fresh jobs every day.
- Fresh listings
- Fast filters
- No subscription required

Senior Application Security Engineer
COLIBRIX ONEApplication security engineer building Secure SDLC, CI/CD security gates, and vulnerability management for COLIBRIX ONE’s AI-powered payment products. Testing fintech web apps, APIs, and integrations while supporting PCI DSS and DORA compliance.
Core Competencies
Role fitUse this summary to align your resume positioning with the role.
Demonstrates expertise in application security and penetration testing, with a strong focus on web and API security, secure coding practices, and the implementation of security tools within CI/CD pipelines. Proficient in analyzing source code for vulnerabilities and effectively communicating security findings to development teams.
ATS Keywords
Tailor your resumeTip: use these terms in your resume and cover letter to boost ATS matches.
Tech Stack
Tools & technologiesAbout the role
Key responsibilities & impact- Roll out the Secure SDLC process to all products, scaling the completed pilot
- Run security design reviews and lightweight threat modeling for critical authentication, payment, administration, and cryptographic changes
- Maintain rapid security review response times
- Own SAST, SCA, secret scanning, and IaC scanning in GitLab CI using tools such as Semgrep, Trivy, gitleaks, and Checkov
- Write custom Semgrep rules based on code findings
- Stabilize CI/CD pipelines and implement effective blocking security gates
- Triage findings from penetration tests, scanners, and attack surface monitoring
- Verify remediation with confirmation scans and re-test historical penetration-test findings
- Perform hands-on security testing of web applications and APIs, including payment flows, back-office panels, and partner integrations
- Review Go, PHP, and JavaScript source code for security issues
- Help development teams design secure APIs with request signing, key rotation, replay protection, and rate limiting
- Prepare and launch a private bug bounty program, later making it public
- Own bug-bounty triage, researcher communication, and reward decisions
- Train developers through secure-coding sessions based on internal findings
- Support the Security Champions program
- Provide evidence for PCI DSS and DORA audits covering secure development, payment-page integrity, and change control
- Work closely with the Group CISO and security team to build secure, scalable fintech products
Requirements
What you’ll need- 4+ years in application security and/or penetration testing
- Strong web and API security skills, including OWASP Top 10 and business logic vulnerabilities
- Ability to analyze source code and identify security flaws
- Experience with Go, PHP, or JavaScript required; Go is a plus
- Hands-on experience adding security tools to CI/CD pipelines, such as Semgrep, Trivy, gitleaks, or similar
- Ability to write clear, actionable security reports and communicate findings effectively with development teams
- Strong prioritization skills and ability to distinguish critical issues from lower-priority findings
- B1+ level of English proficiency required for technical documentation
Benefits
Comp & perks- Opportunity to shape the future of fintech solutions within a growing company
- Collaborative, horizontal team structure that values your expertise and ideas
- Continuous learning and development opportunities to enhance your skills and career growth
- Competitive salary and benefits package