Match Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessLog in to see why each signal reads the way it does.
Job Description
Structured overview of role & requirementsAbout This Role
Lead penetration testing and vulnerability identification across web, mobile (Android/iOS), and API platforms before production deployment.
Conduct manual and tool-assisted source code reviews and embed security controls within the Secure Software Development Lifecycle (SDLC).
Manage WAF configurations (Cloudflare, AWS WAF), perform threat modelling, automate security testing scripts, and track vulnerability remediation with engineering teams.
Minimum Requirements
Minimum 2+ years hands-on experience in application or product security focusing on penetration testing of web, mobile apps, and APIs.
Proficiency in at least one programming language: Python, Go, or Rust.
Working knowledge of AWS cloud platform and experience with Cloudflare and/or AWS WAF.
Understanding of Secure SDLC, threat modelling, authentication protocols (SAML, OAuth, OIDC), and software supply chain security.
Ideal Candidate Profile
Experience working directly with engineering teams to integrate security into product development cycles and resolve vulnerabilities efficiently.
Strong offensive security foundation with practical skills in penetration testing, security tool automation, and cloud security analysis in an AWS environment.
Comfortable operating in a high-scale fintech environment with exposure to API, mobile, web, and cloud security challenges.
