OANDA

Senior Application Security Engineer

OANDA
Apply
17 days ago
Kraków, PolandSenior

Responsibilities

  • Provide technical leadership in application security, threat modeling, design reviews, and secure coding practices.
  • Build security-critical components and remediate vulnerabilities across JavaScript, Go, Python, C++, and Java.
  • Apply defense-in-depth through system hardening, Terraform-based cloud security, code review, cryptography, PKI, hashing, and secrets management.
  • Automate SAST, DAST, IAST, software composition analysis, fuzzing, and other DevSecOps practices.
  • Lead threat-modeling exercises to identify application risks, threats, and vulnerabilities during development.
  • Develop secure AI development practices and AI security tooling.
  • Identify, track, and remediate third-party library vulnerabilities and software supply-chain risks.

Requirements

  • 2–5 years of relevant technical experience, including 1–2+ years focused on application security or security engineering.
  • Expert-level knowledge of web application vulnerabilities, OWASP Top 10, attack vectors, and secure code review.
  • Ability to develop in and navigate security pitfalls in at least one primary language such as Python, Go, Java, C#, JavaScript, or C++.
  • Hands-on experience with SAST, DAST, IAST, SCA, and penetration-testing frameworks.
  • Working knowledge of AWS, Azure, or GCP; networking; databases; and containerized or infrastructure-as-code environments.
  • Ability to simplify complex security challenges and drive proactive solutions collaboratively.
  • Preferred: fintech or financial-services experience, Terraform and cloud-secrets experience, AI security exposure, knowledge of SOC2, ISO27001, NIST, and GDPR, and involvement in the cybersecurity community.
OANDA

About OANDA

501-1,000 employees
Contact me