yandex
S
Salmon
Страна
Россия
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
LeadУдалённоПолная занятость

Application Security Lead

ИИОценка ИИ

Привлекательная позиция уровня Lead в международном финтехе с возможностью удаленной работы. Четкие требования и современный стек технологий делают вакансию отличным выбором для опытных AppSec специалистов.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
ИИОценка ИИ

Высокая сложность обусловлена требованием 7+ лет опыта, глубокой экспертизой в мобильной безопасности и необходимостью выстраивания процессов S-SDLC с нуля в быстрорастущем финтехе.

Анализ зарплаты

Медиана7 500 $
Рынок6 000 $ – 9 500 $
ИИОценка ИИ

Зарплата не указана, но для позиции Lead AppSec в международном финтехе рыночный диапазон составляет от $6,000 до $9,000+ в зависимости от региона проживания кандидата. Данная роль предполагает высокую ответственность, что обычно коррелирует с верхней границей рынка.

Сопроводительное письмо

I am writing to express my strong interest in the Application Security Lead position at Salmon. With over 7 years of experience in application security and a proven track record of building secure SDLC processes in fast-paced product organizations, I am confident in my ability to drive Salmon's security initiatives forward. My expertise in mobile security testing for iOS and Android, combined with a deep understanding of modern supply chain attack vectors, aligns perfectly with the technical requirements of this role.

Throughout my career, I have successfully managed end-to-end vulnerability management and conducted extensive threat modeling that directly influenced product design. I am particularly drawn to Salmon's mission in the Southeast Asian fintech space and am eager to apply my skills in SAST/DAST integration, API security, and automated security tooling to protect your innovative financial solutions. I look forward to the possibility of discussing how my background can contribute to the continued success and security of Salmon.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в Salmon уже сейчас

Присоединяйтесь к Salmon и возглавьте направление безопасности в одном из самых быстрорастущих финтехов Юго-Восточной Азии!

Описание вакансии

#vacancy #appsec

Hey

International technology-driven financial company Salmon looking for: Application Security Lead

Location - remote (exlude Belarus and Russia)

What makes you a strong fit:

🏄🏽‍♂️7+ years in application security, with meaningful ownership over both technical work and process.

🏄🏽‍♂️Has built or substantially improved a secure SDLC in a fast-moving product org.

🏄🏽‍♂️Has run threat modeling on real product features and influenced design decisions as a result.

🏄🏽‍♂️Has owned vulnerability management end-to-end: triage, remediation tracking, SLA management, risk acceptance.

🏄🏽‍♂️Has done hands-on mobile security testing (iOS and/or Android) in a production context, not just UAT.

🏄🏽‍♂️Understands modern supply chain attack vectors like compromised packages (npm, PyPI), malicious IDE plugins, typosquatting, dependency confusion - and knows how to reduce exposure at the tooling and process level.

🏄🏽‍♂️Comfortable writing Python or Bash to automate repetitive security work.

Technical skills:🏄SAST, DAST, SCA in CI/CD pipelines: knows how to tune for signal, not just coverage

🏄API security: authentication flows, token handling, common abuse patterns

🏄Mobile security: OWASP ASVS/MASVS applied in practice

🏄Supply chain: SBOM generation and dependency risk management

🏄Secrets management: detection, remediation, and structural prevention

🏄Working knowledge of AWS and containers sufficient to understand where application risks extend into infrastructure

Southeast Asia's fintech moment starts here.

Сontact me

Откликнуться

or apply

Откликнуться

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Application Security
  • SDLC
  • Threat Modeling
  • Vulnerability Management
  • Mobile Security
  • iOS
  • Android
  • Python
  • Bash
  • SAST
  • DAST
  • SCA
  • CI/CD
  • API Security
  • OWASP ASVS
  • OWASP MASVS
  • SBOM
  • AWS
  • Docker

Возможные вопросы на собеседовании

Проверка опыта внедрения процессов безопасности в разработку.

Расскажите о вашем опыте построения или улучшения Secure SDLC: с какими основными препятствиями вы столкнулись и как их преодолели?

Оценка практических навыков в мобильной безопасности, критически важной для финтеха.

Какие специфические уязвимости вы чаще всего находили при тестировании мобильных приложений на iOS/Android и как вы выстраивали процесс их устранения?

Проверка понимания современных угроз цепочки поставок.

Как бы вы организовали процесс управления рисками зависимостей (SCA) и генерации SBOM в компании с большим количеством микросервисов?

Оценка навыков архитектурного анализа.

Опишите случай, когда результаты моделирования угроз (Threat Modeling) привели к существенному изменению дизайна продукта.

Проверка умения автоматизировать рутину.

Какие задачи по безопасности вы автоматизировали с помощью Python или Bash и какой профит это принесло команде?

Похожие вакансии

CH
crossing hurdles
50 $ – 90 $

OFFENSIVE SECURITY ENGINEER / RED TEAM LEAD

LeadУдалённо
Offensive Security · Red Teaming · Exploit Development · Vulnerability Research · Cloud Security · Malware Analysis · Reverse Engineering · Social Engineering · AppSec
+9 навыков
O
Okko
Не указана

Ведущий специалист по информационной безопасности

LeadУдалённо
ISO 27001 · NIST · GDPR · PCI DSS · SIEM · EDR · DLP · WAF · IDS/IPS · IAM · VPN · Risk Management · Cybersecurity · IT Audit
+14 навыков
P
playson
Не указана

SECURITY LEAD / SECURITY ENGINEER

LeadУдалённо
ISO 27001 · GDPR · SIEM · EDR · DLP · IAM · SSO · MFA · Datadog · CrowdStrike · Cloudflare · Google Workspace · NIST CSF · NIS2 · AWS · Kubernetes · CI/CD · DevSecOps · Incident Response
+19 навыков
XG
X5 Group
Не указана

Руководитель группы управления доступов

LeadГибрид
Active Directory · IDM · PowerShell · Information Security · Access Management · Audit · Risk Assessment
+7 навыков
T
TaxDome
Не указана

Principal Security Engineer (DRI)

LeadУдалённо
Application Security · Product Security · SaaS Security · DevSecOps · CI/CD Security · AI Security · LLM Security · Code Review
+8 навыков
N
nebius
Не указана

Offensive Security Lead

LeadУдалённо
Red Teaming · Penetration Testing · Kubernetes · Python · Go · Cloud Security · IAM · Docker · Adversary Simulation · Offensive Security
+10 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

S
Salmon
Россия