





Recognizable fintech brand and metro locations increase candidate density despite specialized security skill requirements.
Application security is technical and specialized but skills like pentesting and cloud security transfer moderately across industries.
Explicit 2+ years plus mandatory pen-testing, code-review, cloud, WAF, and language skills create strict filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Conduct penetration testing and source code reviews for web, mobile, and API applications to identify vulnerabilities.
Embed security practices into Secure SDLC including threat modelling, design reviews, and release gating.
Manage and tune WAF rules and automate security testing to protect production systems and streamline assessments.
2+ years of hands-on experience in application or product security.
Proficiency in at least one programming language: Python, Go, or Rust.
Working knowledge of cloud platforms, preferably AWS.
Experience with manual and/or tool-assisted source code reviews and penetration testing across web, mobile, and APIs.
Experienced in offensive security with capability to both find and remediate vulnerabilities collaboratively with engineering teams.
Familiar with Secure SDLC practices including threat modelling and security automation.
Comfortable working with cloud infrastructure security and managing WAF configurations (Cloudflare/AWS).