Senior Application Security Engineer
Distribusion Technologies
Seniority
Senior
Model
Remote
Sector
Salary
Undisclosed
Contract
Full-Time
Build the AppSec practice from the ground up as the first dedicated Application Security Engineer. You will own secure development, define what gets reviewed, implement security gates, and build the "paved road" for ~150 engineers with a real attack surface: public partner-facing APIs and payment flows.
What you'll do
- Lead threat modeling and secure design reviews for high-risk changes, partner integrations, and payment flows.
- Implement, tune, and enforce security gates in GitLab CI/CD (SAST, SCA, secrets scanning, and DAST) while minimizing developer friction.
- Act as the primary technical owner for triaging, reproducing, and prioritizing findings from bug bounties, partner pentests, and automated scanners.
- Work hands-on with the DevOps team to implement GCP organizational policies, IAM least-privilege architectures, and Cloud Armor (WAF/rate limiting).
- Establish a security-champions network across engineering squads and leverage automation/AI-assisted tooling to scale code reviews effectively.
- Own vulnerability management end to end: a risk-ranked backlog, remediation SLAs, an escalation path, and closing findings together with the teams.
What you'll need
- 5+ years in AppSec (or 3+ years plus a strong software engineering/web-pentesting background), with a track record of true ownership.
- Read and write production code (Python, Go, TypeScript, Ruby, etc.) and deeply understand web frameworks, CI/CD, and Kubernetes.
- Deep knowledge of web and API security, specifically authentication/authorization models (OAuth2, JWT), rate limiting, tenant isolation, IDOR, and XSS.
- Strong cloud security fundamentals (GCP preferred), specifically regarding public exposure, secrets hygiene, and WAF rules.
- Experience running threat modelling and secure design reviews on real systems (STRIDE or similar).
- Hands-on with SAST/SCA/secrets scanning in CI (Aikido, Semgrep, Snyk or similar).
- Prioritize by real-world risk, propose trade-offs rather than demanding perfection, and communicate complex risks plainly to engineers and leadership.
Nice to have
- Experience securing high-volume, multi-tenant B2B APIs and utilizing AI tooling to accelerate triage and review.
What they offer
- Flat organizational structure with exciting opportunities, ownership, and responsibility.
- International team of talented and driven people with a clear mission.
- Flexible work policy with remote work options and international opportunities.
- Competitive salary.

