FREE ACCESS
5,000–10,000 jobs/day

See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Application Security Engineer
PepperstoneApplication Security Engineer ensuring security in software development lifecycle at Pepperstone. Partnering with engineering and product teams to assess and remediate security vulnerabilities.
Tech Stack
Tools & technologiesAWSAzureCloudGoGoogle Cloud PlatformJavaJavaScriptJenkinsPython
About the role
Key responsibilities & impact- Perform application security assessments including threat modelling, secure code reviews, and penetration testing across web, mobile, and API surfaces.
- Partner with development teams to integrate security controls into CI/CD pipelines using SAST, DAST, SCA, and secrets detection tooling.
- Identify, triage, and track vulnerabilities through to remediation, working closely with engineering teams to provide actionable guidance.
- Define and maintain application security standards, secure coding guidelines, and developer-facing security documentation.
- Champion security-by-design principles and provide hands-on guidance during the design and architecture phases of new features and products.
- Lead and support bug bounty and responsible disclosure programmes, coordinating triage and remediation of externally reported issues.
- Conduct security training and awareness sessions for software engineers, embedding secure development practices across teams.
- Evaluate third-party libraries, open-source components, and vendor integrations for security risk.
- Collaborate with the broader Security team on incident response activities related to application-layer vulnerabilities.
Requirements
What you’ll need- 8+ years of experience in information security, with at least 3 years specialising in application security or software security engineering.
- Solid understanding of common vulnerability classes including OWASP Top 10, business logic flaws, and API security risks.
- Hands-on experience with security testing tools such as Burp Suite, OWASP ZAP, Semgrep, Checkmarx, Snyk, or equivalent.
- Proficiency in at least one programming or scripting language (Python, JavaScript, Java, Go, or similar) to support code review and automation.
- Experience integrating security tooling into CI/CD pipelines (GitHub Actions, Jenkins, GitLab CI, or similar).
- Familiarity with cloud security principles across AWS, Azure, or GCP, particularly as they relate to application hosting and deployment.
- Strong communication skills with the ability to articulate security risk to both technical and non-technical stakeholders.
- Relevant certifications such as OSCP, GWEB, CEH, or equivalent are advantageous.
- Experience in a regulated financial services or fintech environment is a plus.
- Fluency in English; Hungarian language skills are an advantage.
- Ability to live the Pepperstone values.
- Committed to ongoing learning and development
Benefits
Comp & perks- Competitive salary structure including company bonus scheme
- Flexible and hybrid working
- Remote working option - work from anywhere for up to 4 weeks per year
- 10 days of Company paid sick leave annually
- 21 days of paid vacation within the first year of employment, increasing to 25 days after one year
- 3 paid volunteering days per year & Workplace Giving Program
- Comprehensive medical insurance with coverage for your healthcare needs
- Pension fund
- Employee referral bonuses for referring top talent to the company
- Ongoing personal development & learning opportunities
- Periodic recognition and reward programs for outstanding performance and achievements
- Frequent events and celebrations
- Genuinely collaborative and friendly culture
- Employee Assistance Program & Wellbeing Initiatives
- Convenient and cozy office located near the Limassol Municipal Garden
ATS Keywords
✓ Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
application securitythreat modellingsecure code reviewspenetration testingvulnerability assessmentsecure coding guidelinessecurity testing toolsprogramming languagesCI/CD integrationcloud security principles
Soft Skills
strong communication skillscollaborationguidancetrainingleadershipproblem-solvingarticulation of security riskchampioning security-by-designongoing learningcommitment to values
Certifications
OSCPGWEBCEH