We’re looking for an Senior Application Security Engineer to build and scale our product security function across the Group. As the first dedicated AppSec specialist, you’ll own security practices end to end — from Secure SDLC and CI/CD security gates to vulnerability management, security testing, and developer enablement. You’ll work closely with the Group CISO and security team to help build secure, scalable fintech products.
Secure SDLC
Roll out our Secure SDLC process to all products, one by one. The pilot is done; you scale it.
Run security design reviews for critical changes (auth, payments, admin, crypto). Use lightweight threat modeling.
Keep the security review process fast. Target: first response within 1 working day, async review within 3.
Security tooling in CI/CD
Own SAST, SCA, secret scanning, and IaC scanning in GitLab CI (Semgrep, Trivy, gitleaks, Checkov).
Write custom Semgrep rules based on real findings in our code.
Make the pipelines stable and useful. Low noise, clear signal, blocking gates where it matters.
Vulnerability management
Triage findings from pentests, scanners, and our attack surface monitoring. SLA: triage within 2 working days.
Verify fixes with confirmation scans before closing.
Re-test old pentest findings so they do not come back.
Product security testing
Do hands-on security testing of our web apps and APIs: payment flows, back-office panels, partner integrations.
Review source code for security issues (Go, PHP, JavaScript).
Help dev teams design secure APIs: request signing, key rotation, replay protection, rate limiting.
Bug bounty
Prepare and launch our private bug bounty program. Later, take it public.
Own triage, researcher communication, and reward decisions.
People and compliance
Train developers: short secure-coding sessions, based on our own findings.
Support the Security Champions program in dev teams.
Provide evidence for PCI DSS and DORA audits (secure development, payment page integrity, change control).
4+ years in application security and/or penetration testing
Strong web and API security skills: OWASP Top 10 is your comfort zone, business logic flaws are your interest
You can analyze source code and identify security flaws. Experience with Go, PHP, or JavaScript is required, with Go being a plus
Hands-on experience adding security tools to CI/CD pipelines (any of: Semgrep, Trivy, gitleaks, or similar)
Ability to write clear, actionable security reports and communicate findings effectively with development teams
Strong prioritization skills - you understand risk impact and can distinguish critical issues from lower-priority findings
B1+ level of English proficiency is required to work with technical documentation
Practical certificates: OSCP, OSWE, BSCP, or similar
Experience running or managing a bug bounty program
Experience with AI-assisted vulnerability triage and review
Kubernetes and AWS security basics
Mobile (Android) security testing
Experience in fintech or another regulated industry (PCI DSS is a strong plus)
Opportunity to shape the future of fintech solutions within a growing company
Collaborative, horizontal team structure that values your expertise and ideas
Continuous learning and development opportunities to enhance your skills and career growth
Competitive salary and benefits package
* This position is offered within the COLIBRIX ONE. Employment will be under the appropriate legal entity based on the role and location.
Published on: 8/4/2026

Colibrix ONE
From seamless acquiring solutions to smart virtual cards and modern bank account services, COLIBRIX ONE empowers your business to manage, grow, and scale your financial operations – all in one place. Tailored, efficient, and future-ready, our tools are built to support your unique journey in the digital economy.
A broad range of services is offered: global card processing coverage, digital wallet operations around the globe, cross-border merchant accounts and payment solutions, multiple APMs support, and current corporate accounts for legal entities.
Please let Colibrix ONE know you found this job on Wantapply.com. It helps us to get more jobs on our site. Thanks!
Unlock access with Plus