wagey.ggwagey.gg
Open Tech JobsCompaniesPricing
Log InGet Started Free
Jobs/Mobile Engineer Role/AppSec Engineer

AppSec Engineer

AddiBogotá, Colombia1mo ago
In OfficeMidLATAMBankingSoftwareMobile EngineerJavaPythonDocumentationTeam ManagementSprint Planning

Upload My Resume

Drop here or click to browse · PDF, DOCX, DOC, RTF, TXT

Apply in One Click

Requirements

• Hands-on Expertise in Application Security Testing & Tooling • Experienced in using and maintaining application security tools such as Burp Suite, MobSF, trufflehog, Nuclei, and manual code review, including SAST, DAST, and mobile testing solutions. • Tunes tools to reduce false positives and ensures findings are actionable and developer-friendly. • Integrates automated security testing seamlessly into CI/CD pipelines and developer workflows. • Demonstrated Ability to Lead Threat Modeling & Secure Design • Conducts structured threat modeling sessions using frameworks such as DREAD, PASTA, and STRIDE to identify and assess design-level risks. • Translates threat model outputs into clear, prioritized security requirements and architectural controls. • Applies deep understanding of common threat patterns, including OWASP Top 10, API security, mobile, web, and AI-related risks. • Strong Capability in Vulnerability Management & Remediation Support • Manages application vulnerabilities end to end, from identification through remediation verification and closure. • Prioritizes vulnerabilities based on technical severity, exploitability, and business impact. • Partners closely with engineering teams to guide remediation efforts and reduce recurring issues. • Track Record of Delivering Security Assessments, Pentesting & Adversarial Testing • Brings 3+ years of experience coordinating and supporting penetration tests, security assessments, and red team or adversarial exercises. • Analyzes assessment outcomes to identify root causes and drive measurable security improvements. • Ensures findings are systematically tracked, remediated, and incorporated into continuous improvement cycles. • Experienced in Cross-Functional Collaboration & Developer Enablement • Acts as a trusted security partner to engineering teams, balancing risk management with delivery velocity. • Possesses hands-on development experience in at least one programming language (e.g., Java or Python) to enable practical, code-level guidance. • Communicates security risks clearly and pragmatically, contributes to secure coding education, and leverages AI to automate controls or expand security coverage.

Responsibilities

• Design and implement a standardized Secure Software Development Lifecycle (SSDLC) across web, mobile, API, and AI-enabled services, embedding security into SDLC and CI/CD workflows to achieve ≥90% coverage of critical business flows and ≥50% team adoption by the end of 2026, with measurable reduction in post-release high-severity vulnerabilities. • Establish and operate a consistent threat modeling practice for new and high-risk applications using recognized frameworks, ensuring ≥60% of critical services have documented threat models and approved security requirements before production by the end of Q3 2026, while preventing ≥70% of high-risk design issues prior to implementation. • Own the end-to-end application vulnerability management lifecycle across code, dependencies, APIs, and mobile applications, ensuring ≥70% of critical vulnerabilities are remediated within SLAs by the end of Q2 2026, with continuous quarter-over-quarter reduction in open critical findings. • Implement and operate automated application security testing within CI/CD pipelines, including secret detection, SAST, dependency, DAST, and mobile testing, achieving ≥80% production application coverage by the end of 2026, reducing false positives by ≥30%, and enabling developers to remediate ≥75% of high-severity findings within the same sprint. • Plan and manage application security assessments, penetration tests, and adversarial exercises for critical applications, ensuring 100% of high-risk findings are tracked and remediated within SLAs, and demonstrating year-over-year reduction in recurring high-risk issues.

Benefits

• Work on a problem that truly matters – We are redefining how people shop, pay, and bank in Colombia, breaking down financial barriers and empowering millions. Your work will directly impact customers' lives by creating more accessible, seamless, and fair financial services. • Be part of something big from the ground up – This is your chance to help shape a company, influencing everything from our technology and strategy to our culture and values. You won’t just be an employee—you’ll be an owner • Unparalleled growth opportunity – The market we’re tackling is massive, and we’re growing faster than almost any fintech lender at our stage. If you’re looking for a high-impact role in a company that’s scaling fast, this is it. • Competitive compensation & meaningful ownership – We believe in rewarding our talent. You’ll receive a generous salary, equity in the company, and benefits that go beyond the basics to support your growth. • How the hiring process looks like • We believe in a fast, transparent, and engaging hiring experience that allows both you and us to determine if there's a great fit. Here’s what our process looks like: • Step 1: People Interview (30 min) • A conversation with a recruiter or hiring manager to get to know you, your experience, and what you're looking for. We’ll also share more about Addi, our culture, and the role. • Step 2: Initial Interview (60 min) • A more in-depth conversation with our Head of Cybersecurity, where we explore your skills, experience, and problem-solving approach. We want to understand how you think and work. • Step 3: Deep Dive Interview (60 min) • You'll meet future colleagues and cross-functional team members to get a feel for how we work together. We’re looking for strong contributors and cultural fits, so bring your questions, too! • Step 4: Case Study (3-5 Days) • You may receive a real-world challenge or case study to complete. This is a chance to showcase your expertise and how you approach key problems relevant to the role. • Step 5: Co-Founder Interview • If there’s a strong match, you’ll have a final conversation with our Founder to align on expectations, cultural fit and ensure mutual excitement. From there, we’ll move quickly to an offer and discuss next steps. • We value efficiency and respect for your time, so we aim to complete the process as quickly as possible. Our goal is to make this experience insightful and exciting for you, just as much as it is for us. Regardless of the outcome, we are committed to always providing feedback, ensuring that you walk away with valuable insights from your experience with us.

Similar Jobs

Manager, Solution Engineering - Commercial, ASEAN5h ago
snowflakesnowflake·SG-Singapore
In OfficeAPACMidFintechCloud ComputingSolutions EngineerAdvisorCoachingProduct MarketingSnowflakeCross-functional CollaborationANZAWSGCPAzureCustomer SuccessSQLdbtKafkaAirflowMLOpsJavaPythonVector
Staff Research Engineer5h ago
TuringTuring·San Francisco, California, United States·$250k – $350k/year + Equity
In OfficeNAStaffArtificial IntelligenceResearch EngineerStaff EngineerC++JavaGoRustPythonTeam ManagementTraining DevelopmentReportingData QualitySales Enablement
Senior Applied Researcher AI/ML (US)5h ago
PointClickCarePointClickCare·Remote - US - Hybrid·$178k – $198k/year
In OfficeNASeniorCybersecurityCloud ComputingSenior Data ScientistRecruiterJavaSQLPythonTraining DevelopmentAzureApache SparkTransformersHugging FaceDatabricksPandasAWSscikit-learnROAS
Frontier Data Lead5h ago
TuringTuring·San Francisco, California, United States·$250k – $350k/year + Equity
In OfficeNAStaffArtificial IntelligenceHead of DataC++JavaGoRustPythonTeam ManagementTraining DevelopmentReportingData QualitySales Enablement
Software Engineer Intern (Chicago)5h ago
LogicGateLogicGate·Chicago - United States - Hybrid
In OfficeNAInternCloud ComputingHigher EducationSoftware EngineerInternJavaC#C++RubyPythonJavaScriptSpringJiraClaudeSpring BootNeo4jAngularKotlinSlackAWSSCSSKubernetesDockerTypeScriptTerraformAnsible

Stop filling. Start chilling.Start chilling.

Get Started Free

No credit card. Takes 10 seconds.

© 2026 Dominic Morris. All rights reserved.·Privacy·Terms·