Application Security Lead

Posted Yesterday
Be an Early Applicant
7 Locations
In-Office or Remote
Senior level
Fintech • Financial Services
The Role
Lead application security across mobile banking, payments, and regulated products. Conduct threat modeling, secure SDLC design, CI/CD tuning, supply-chain and secrets posture, and vulnerability management. Translate security risk for engineers, regulators, and the CISO while owning processes, tooling, and remediation workflows.
Summary Generated by Built In
The Role

You'll own application security across our mobile banking platform, payments stack, and a growing set of regulated products. The work is hands-on, you’ll conduct a threat modeling, security reviews, CI/CD tooling - with real process ownership. You'll report to the Group CISO and work closely with both our engineering teams and the Bank IS function.

 
 
Responsibilities
 

Risk-driven security ownership

  • Identify which systems, data flows, and product changes carry the highest real-world risk and build your work around that, not around tool coverage or compliance checklists

  • Decide when a security gate is worth slowing down a release and when it isn't, own that call, and be able to explain it to engineering and the CISO

  • Maintain a risk register for application-layer exposures: what's open, what's accepted, what's being fixed, and why in that order

Secure SDLC

  • Figure out where in our delivery process security decisions are actually being made and put controls there

  • Run threat modeling for high-stakes product changes before design is locked, not after

  • Build a mobile security testing baseline that the team runs themselves

CI/CD and supply chain

  • Assess what the current pipeline actually catches versus what it produces as noise, and fix the ratio before adding more scanners

  • Own supply chain posture: dependency pinning, SBOM, internal registry, and the response process when a package gets compromised

  • Own secrets detection and remediation end-to-end

Regulatory and cross-team work

  • Translate application security gaps into language that satisfies BSP examiners without over-engineering the evidence

  • Coordinate security input into new product launches across our Group and Bank structure

 
Requirements
 

Experience

  • 7+ years in application security, with meaningful ownership over both technical work and process

  • Has built or substantially improved a secure SDLC in a fast-moving product org

  • Has run threat modeling on real product features and influenced design decisions as a result

  • Has owned vulnerability management end-to-end: triage, remediation tracking, SLA management, risk acceptance

  • Has done hands-on mobile security testing (iOS and/or Android) in a production context, not just UAT

  • Understands modern supply chain attack vectors like compromised packages (npm, PyPI), malicious IDE plugins, typosquatting, dependency confusion - and knows how to reduce exposure at the tooling and process level

  • Comfortable writing Python or Bash to automate repetitive security work

Technical skills

  • SAST, DAST, SCA in CI/CD pipelines: knows how to tune for signal, not just coverage

  • API security: authentication flows, token handling, common abuse patterns

  • Mobile security: OWASP ASVS/MASVS applied in practice

  • Supply chain: SBOM generation and dependency risk management

  • Secrets management: detection, remediation, and structural prevention

  • Working knowledge of AWS and containers sufficient to understand where application risks extend into infrastructure

Nice to have

  • Experience in a regulated environment (financial services or similar)

  • Familiarity with PCI-DSS, ISO 27001, or BSP MORB

  • Certifications: OSCP, GWEB, GWAPT, CSSLP

Communication

  • Strong written English; most day-to-day alignment is async

  • Can explain a security issue clearly to an engineer and summarize the same issue for a non-technical stakeholder

Skills Required

  • 7+ years in application security with ownership of technical work and process
  • Built or significantly improved a secure SDLC in a fast-moving product organization
  • Practical experience running threat modeling on real product features
  • End-to-end vulnerability management: triage, remediation tracking, SLA management, risk acceptance
  • Hands-on mobile security testing experience (iOS and/or Android) in production contexts
  • Practical knowledge of modern supply chain attack vectors (npm, PyPI, typosquatting, dependency confusion) and mitigations
  • Comfortable writing automation scripts in Python or Bash
  • Experience integrating and tuning SAST, DAST, and SCA tools in CI/CD pipelines
  • API security expertise (authentication flows, token handling, common abuse patterns)
  • Applied mobile security using OWASP ASVS/MASVS
  • SBOM generation and dependency risk management experience
  • Secrets detection, remediation, and structural prevention experience
  • Working knowledge of AWS and container platforms to assess application-to-infrastructure risks
  • Strong written English and ability to communicate security issues to technical and non-technical stakeholders asynchronously
  • Experience in regulated environments (financial services or similar)
  • Familiarity with PCI-DSS, ISO 27001, or BSP MORB
  • Certifications such as OSCP, GWEB, GWAPT, CSSLP
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
1,189 Employees
Year Founded: 2022

What We Do

Salmon Group Ltd is a financial technology company serving Filipino consumers with modern, inclusive financial services. Its platform combines technology, product design, security, data analytics and customer care to make finance easier to access. Salmon offers consumer-focused products including short-term loans and digital banking services, with the broader mission of improving convenience, affordability and financial inclusion while operating securely around the clock.

Similar Jobs

Deepgram Logo Deepgram

Solutions Engineer

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
Remote
EU
150 Employees

Deepgram Logo Deepgram

Senior Solutions Architect

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
Remote
EU
150 Employees

Feldera, Inc. Logo Feldera, Inc.

Product Engineer

Artificial Intelligence • Big Data • Database • Analytics
Remote
2 Locations
14 Employees

Feldera, Inc. Logo Feldera, Inc.

Infrastructure Engineer

Artificial Intelligence • Big Data • Database • Analytics
Remote
2 Locations
14 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account