





Known fintech brand, mid-level appsec role, and metro location drive high candidate competition.
Core AppSec skills are transferable, but fintech PCI/GDPR and payment-specific requirements raise domain specificity.
Explicit years, mandatory appsec experience and numerous technical standards/tools increase shortlisting strictness.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead security and privacy initiatives through design reviews, threat modeling, and securing applications across their lifecycle.
Own security posture for various applications by running vulnerability assessments, penetration tests, and ensuring secure configurations for web/mobile/DB environments.
Serve as security engineering expert by mentoring developers/QA, evaluating bug bounty reports, and improving security tooling and processes.
4+ years in developing large-scale internet or SaaS applications with 2 to 3 years specifically in web/mobile application security engineering or development.
Bachelor's or Master's degree in Computer Science or equivalent from Tier-1 engineering institution.
Hands-on experience with vulnerability assessments and penetration testing for web, mobile, SDK, API, and network.
Familiarity with OWASP Top 10, Secure SDLC, threat modeling, secure coding, and security tools like Burpsuite, AppScan, OWASP ZAP, Snyk, Veracode, etc.
Experienced in both offensive and defensive security measures including executing penetration tests and handling bug bounty programs.
Strong technical coding ability (Java), knowledge of cloud infrastructure security (AWS/Azure), containerization, and continuous integration environments.
Prior work experience in FinTech or handling payment security, cryptographic key management and familiarity with compliance frameworks (PCI DSS, GDPR, NIST) is highly desirable.