
Application Security Engineer
Pepperstone3 months ago
Budapest, HungarySenior
Responsibilities
- Perform application security assessments, including threat modelling, secure code reviews, and penetration testing across web, mobile, and API surfaces.
- Integrate security controls and testing tools into CI/CD pipelines using SAST, DAST, SCA, and secrets detection tooling.
- Identify, triage, track, and help remediate application vulnerabilities with engineering teams.
- Maintain application security standards, secure coding guidelines, and developer-facing documentation.
- Provide security-by-design guidance during product and feature design and architecture.
- Lead and support bug bounty and responsible disclosure programs.
- Conduct security training and awareness sessions for software engineers.
- Evaluate third-party libraries, open-source components, and vendor integrations for security risk.
- Collaborate on incident response activities involving application-layer vulnerabilities.
Requirements
- 8+ years of information security experience, including at least 3 years specializing in application security or software security engineering.
- Understanding of OWASP Top 10, business logic flaws, and API security risks.
- Hands-on experience with security testing tools such as Burp Suite, OWASP ZAP, Semgrep, Checkmarx, or Snyk, or equivalent.
- Proficiency in at least one programming or scripting language, such as Python, JavaScript, Java, or Go.
- Experience integrating security tooling into CI/CD pipelines, such as GitHub Actions, Jenkins, or GitLab CI.
- Familiarity with cloud security principles across AWS, Azure, or GCP.
- Strong communication skills for explaining security risks to technical and non-technical stakeholders.
- Relevant certifications such as OSCP, GWEB, or CEH are advantageous.
- Experience in regulated financial services or fintech is a plus.
- Fluency in English; Hungarian language skills are advantageous.
- Commitment to Pepperstone’s values and ongoing learning and development.
Benefits
- Hybrid working arrangement.
- Remote working option for up to 4 weeks per year.
- 10 days of company-paid sick leave annually.
- 21 days of paid vacation in the first year, increasing to 25 days after one year.
- 3 paid volunteering days per year and a Workplace Giving Program.
- Comprehensive medical insurance.
- Pension fund.
- Employee referral bonuses.
- Personal development and learning opportunities.
- Recognition and reward programs.
- Frequent events and celebrations.
- Employee Assistance Program and wellbeing initiatives.
- Convenient office located near the Limassol Municipal Garden.