- Страна
- Нигерия
Откликайтесь
на вакансии с ИИ

Senior Application Security Engineer
Отличная вакансия в ведущем финтехе Африки с высокой социальной значимостью. Предлагается конкурентный пакет, включая опционы (ESOP), удаленный формат работы и возможность влиять на архитектуру безопасности крупной платежной системы.
Сложность вакансии
Высокая сложность обусловлена требованиями к глубоким техническим знаниям (Java, Python, Go), опытом проведения наступательного анализа (пентестинг) и необходимостью лидерских качеств для менторства и разработки стратегии. Процесс найма включает техническое задание и несколько этапов интервью, включая уровень Executive.
Анализ зарплаты
Зарплата для Senior AppSec ролей в нигерийских компаниях с глобальным охватом обычно выше среднего по локальному рынку, но может варьироваться в зависимости от валюты выплаты. Учитывая масштаб Moniepoint, предложение, скорее всего, соответствует верхнему децилю рынка для удаленных специалистов в регионе.
Сопроводительное письмо
I am writing to express my strong interest in the Senior Application Security Engineer position at Moniepoint. With over five years of experience in application security and a deep background in securing high-growth fintech ecosystems, I am impressed by Moniepoint’s scale and its commitment to processing $22 billion monthly while maintaining a culture of innovation. My expertise in threat modeling using STRIDE, performing deep code reviews in Java and Python, and building custom security automation tools aligns perfectly with your mission to embed security into the fabric of the SDLC.
In my previous roles, I have successfully led security architecture reviews for complex microservices and mentored engineering teams to adopt a security-first mindset. I am particularly drawn to Moniepoint’s focus on adversarial security analysis and the opportunity to solve novel security problems in a cloud-native environment. I am confident that my technical leadership and ability to translate complex risks into actionable business insights will contribute significantly to safeguarding customer trust as Moniepoint continues to expand its financial ecosystem.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в moniepoint уже сейчас
Присоединяйтесь к лидеру финтеха Африки и станьте ключевым экспертом по безопасности в Moniepoint!
Описание вакансии
Who we are
Moniepoint Inc. is Africa’s all-in-one financial ecosystem, helping 10 million businesses and individuals access seamless payments, banking, credit, and business management tools since 2019.
As Nigeria’s largest merchant acquirer, it powers most of the country’s Point of Sale (POS) transactions. Through its subsidiaries, Moniepoint Inc. processes $22 billion monthly for its customers while operating profitably.
Curious about what makes Moniepoint an incredible place to work? Check out posts on how we cultivate a culture of innovation, teamwork, and growth.
About the role
As a Senior Security Engineer, you will champion secure innovation by embedding security into the fabric of our software development lifecycle. You'll partner closely with engineering teams to safeguard customer trust while they build cutting-edge services. Your expertise will directly shape secure design through threat modeling and code review, drive efficiency via security automation, and mentor developers to elevate our collective security posture.
The ideal candidate is a technical leader who blends deep security expertise with exceptional influence. You possess broad security knowledge anchored by specialization in critical areas, and excel at translating complex risks into actionable insights for both engineers and executives. Your strength lies in harmonizing diverse perspectives, strategically prioritizing risks, and guiding partners to implement resilient, secure solutions that balance speed and safety.
Key Responsibilities
Security Strategy & Leadership
- Define and execute security strategy for product teams, aligning with business objectives.
- Lead threat modeling, security architecture reviews, and design guidance for diverse software projects.
- Mentor engineers technically and professionally, fostering a culture of security excellence.
Advanced Technical Execution
- Conduct adversarial security analysis using automated tools and manual techniques (e.g., custom exploit development).
- Perform manual/automated secure code reviews across Java, Python, JavaScript, and cloud-native stacks.
- Develop security automation tools to scale vulnerability detection (SAST/DAST/IAST enhancements).
Risk Mitigation & Innovation
- Identify complex risks through offensive security research; advocate for cutting-edge mitigation technologies.
- Solve novel security problems lacking predefined solutions (e.g., zero-day vulnerabilities, emergent attack vectors).
- Maintain and evolve threat models for critical applications and microservices architectures.
Collaboration & Enablement
- Partner with the engineering team to embed security controls into CI/CD pipelines and development practices.
- Design/deliver security training programs tailored to development teams and business stakeholders.
- Lead incident response for application security events and drive root-cause analysis.
Qualifications Required
- 5+ years in application security, including 2+ years in a senior/lead role.
- Expertise in threat modeling (e.g., STRIDE, PASTA), penetration testing, and secure SDLC implementation.Proficiency in code review for Java/Python/JavaScript and cloud platforms (AWS/Azure/GCP).
- Hands-on experience building security tools (e.g., scanners, CI plugins) with Python/Go.
- Proven track record in security architecture design and risk-based decision-making.
Preferred
- OSCP, OSCE, GXPN, or similar offensive security certifications.
- Contributions to security tooling/open-source projects.
- Experience with container security (Kubernetes, Docker), serverless, or infrastructure-as-code.
Skills
- Leadership: Ability to define team strategy, mentor engineers, and influence stakeholders.
- Innovation: Aptitude for researching/implementing novel solutions to ambiguous security challenges.
- Technical Depth: Mastery of application security frameworks (OWASP, NIST) and exploit techniques.
- Communication: Translate technical risks to business impact for executives and engineers alike.
- Execution: Drive implementation of security controls
What we can offer you
- Culture -We put our people first and prioritize the well-being of every team member. We’ve built a company where all opinions carry weight and where all voices are heard. We value and respect each other and always look out for one another. Above all, we are human.
- Learning - We have a learning and development-focused environment with an emphasis on knowledge sharing, training, and regular internal technical talks.
- Compensation - You’ll receive an attractive salary, pension, health insurance,, Employee Stock Options, annual bonus, plus other benefits.
What to expect in the hiring process
- Preliminary phone call with the recruiter
- Take home assessment
- Technical interview with a Lead in our Engineering Team
- Behavioural and technical interview with a member of the Executive team.
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- Java
- Python
- JavaScript
- Go
- AWS
- Azure
- GCP
- Kubernetes
- Docker
- SAST
- DAST
- IAST
- STRIDE
- PASTA
- OWASP
- NIST
- CI/CD
- Microservices
- Penetration Testing
- Threat Modeling
Возможные вопросы на собеседовании
Проверка навыков стратегического планирования и приоритизации рисков в продуктовой среде.
Как вы определяете приоритетность внедрения мер безопасности, когда бизнес-цели требуют высокой скорости выпуска продукта?
Оценка практического опыта в моделировании угроз для сложных систем.
Опишите ваш процесс проведения моделирования угроз (например, по STRIDE) для новой микросервисной архитектуры. Какие критические уязвимости вы находили таким образом?
Проверка навыков автоматизации и разработки собственных инструментов безопасности.
Расскажите о самом сложном инструменте безопасности или плагине для CI/CD, который вы разработали на Python или Go. Какую проблему он решил?
Оценка опыта в проведении глубокого анализа кода и поиске уязвимостей.
С какими специфическими уязвимостями в приложениях на Java или Python вы сталкивались чаще всего и как вы помогали разработчикам внедрять превентивные меры?
Проверка лидерских качеств и умения работать с командой.
Как вы подходите к обучению разработчиков принципам безопасного программирования, если они воспринимают проверки безопасности как помеху работе?
Похожие вакансии
Senior Security Engineer
Senior Security Engineer
Senior Software Engineer, Application Security
Senior Software Engineer, Application Security
Staff Incident Response Specialist
Senior Software Engineer - SecEng
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- Нигерия