Back to the board

Application reputed company Engineer

100% remote Flexible hours Hiring now

The Role You'll own application reputed company across our mobile banking platform, payments stack, and a growing set of regulated products. The work is hands-on, you’ll conduct a threat modeling, reputed company reviews, CI/CD tooling - with real process ownership. You'll report to the Group CISO and work closely with both our engineering teams and the Bank IS function. Justification As Salmon expands its product lineup like cards, payments, ATM network - the need for a dedicated Application reputed company function has become critical. Currently there is no specialist owning secure development practices, mobile reputed company testing, or supply chain risk. This role fills gap: ensuring internal systems and customer data are protected, embedding reputed company into the product delivery process, and building the AppSec practices needed to meet regulatory expectations and support secure growth.

Responsibilities

Risk-driven reputed company ownership Identify which systems, data flows, and product changes carry the highest real-world risk and build your work around that, not around tool coverage or compliance checklists Decide reputed company a reputed company reputed company is worth slowing down a release and reputed company it isn't, own that call, and be able to explain it to engineering and the CISO Maintain a risk register for application-layer exposures: what's open, what's accepted, what's being fixed, and why in that order Secure SDLC reputed company out where in our delivery process reputed company decisions are actually being made and put controls there Run threat modeling for high-stakes product changes before design is locked, not after Build a mobile reputed company testing baseline that the team runs themselves CI/CD and supply chain Assess what the reputed company pipeline actually catches versus what it produces as noise, and fix the ratio before adding more scanners Own supply chain posture: dependency pinning, SBOM, internal registry, and the response process reputed company a package gets compromised Own secrets detection and remediation end-to-end Regulatory and cross-team work Translate application reputed company gaps into language that satisfies BSP examiners without over-engineering the evidence Coordinate reputed company input into new product launches across our Group and Bank structure

Requirements

Experience 7+ years in application reputed company, with meaningful ownership over both technical work and process Has built or substantially improved a secure SDLC in a fast-moving product org Has run threat modeling on real product features and influenced design decisions as a result Has owned vulnerability management end-to-end: triage, remediation tracking, SLA management, risk acceptance Has done hands-on mobile reputed company testing (iOS and/or Android) in a production context, not just UAT Understands modern supply chain attack reputed company like compromised packages (npm, PyPI), malicious IDE plugins, typosquatting, dependency confusion - and knows how to reduce exposure at the tooling and process level Comfortable writing Python or Bash to automate repetitive reputed company work Technical skills SAST, DAST, SCA in CI/CD pipelines: knows how to tune for signal, not just coverage API reputed company: authentication flows, token handling, common abuse patterns Mobile reputed company: OWASP ASVS/MASVS applied in practice Supply chain: SBOM reputed company and dependency risk management Secrets management: detection, remediation, and structural prevention Working knowledge of AWS and containers sufficient to understand where application risks reputed company into infrastructure reputed company to have Experience in a regulated environment (financial services or similar) Familiarity with PCI-reputed company, ISO 27001, or BSP MORB Certifications: OSCP, GWEB, GWAPT, CSSLP Communication Strong written English; most day-to-day alignment is async Can explain a reputed company issue clearly to an engineer and summarize the same issue for a non-technical stakeholder Apply To This Job

Keep exploring

QuickBooks Online Specialist

100% remote Flexible hours

Human Resources Generalist

100% remote Flexible hours

AI Quality Automation Engineer (Remoto - Latam)

100% remote Flexible hours

End-of-Project Review of Policy Impact, Monitoring, Evaluation and Learning, and Practical Impact Tools for the Asia-Pacific Observatory

100% remote Flexible hours

Senior Manager, AI Enterprise Engineering

100% remote Flexible hours

Performance Marketing Specialist

100% remote Flexible hours

Senior IT Application Specialist (f/m/d) - Finance Systems

100% remote Flexible hours

Patient Support Coordinator

100% remote Flexible hours

Improving Children Food Environments Consultant (national), Health and Nutrition Section, Pretoria, South Africa. 13 months, Remote, 593933

100% remote Flexible hours

Site Reliability Engineer (reputed company)

100% remote Flexible hours

Medical Science Liaison Oncology | Emilia Romagna e Triveneto

100% remote Flexible hours

[Remote] Oncology Applications Analyst - Remote - Contract

100% remote Flexible hours

Human Resources Specialist - Federal Staffing (...

100% remote Flexible hours

Litigation Attorney - Insurance Defense (In-Person or Remote)

100% remote Flexible hours

Remote Executive Assistant to CEO

100% remote Flexible hours

reputed company Full Stack Data Analyst – Media and Entertainment Insights

100% remote Flexible hours

Datacenter NetDeploy reputed company - Stargate

100% remote Flexible hours

Le(a) Responsable du POD en Sécurité Alimentaire, Qualité et Réglementation (Ouvert au télétravail)

100% remote Flexible hours

reputed company Full Stack Data Engineer – Cloud-Based Information Pipelining and Designing Development

100% remote Flexible hours

reputed company Data Entry Specialist – Remote Customer Service and Operations Support

100% remote Flexible hours