What You'll Be Doing:
- Conduct architecture reviews, threat modeling, and security assessments for business systems leveraging AI-driven analysis where applicable.
- Drive root cause analysis and post-incident reviews to strengthen resilience.
- Contribute to the development and enforcement of corporate security policies, standards, and procedures.
- Lead the design and implementation of security controls in product development and architecture following everything-as-code principles.
- Perform threat modeling, secure design reviews, and code-level security assessments for fintech applications.
- Drive the integration of application security testing (SAST, DAST, IAST, SCA) into CI/CD pipelines with AI-powered triage and prioritization.
- Define and enforce secure coding practices, frameworks, and guidelines through codified policies and secure-by-default templates.
- Embed security controls and tooling into DevOps pipelines to enable continuous security validation through infrastructure-as-code and policy-as-code approaches.
- Champion “shift-left” practices ensuring vulnerabilities are identified and remediated early.
- Develop automated solutions for vulnerability detection, dependency management, and compliance monitoring utilizing AI agents and modern automation frameworks.
- Oversee vulnerability management, penetration testing, and bug bounty/VDP programs.
- Provide input into security risk assessments for new features, integrations, and third-party components.
- Act as a subject matter expert for product security, advising engineering and product teams.
- Lead and mentor security engineers and developers in secure development practices.
- Collaborate with IT, Infrastructure Security, and Risk teams to ensure end-to-end security.
- Represent Product Security in regulatory audits, customer security reviews, and executive briefings.
Qualifications You Bring:
- Bachelor’s or Master’s degree in Computer Science, Information Security, Software Engineering, or a related discipline.
- Certifications (preferred): CISSP, CCSP, CSSLP, or equivalent. Offensive security or application-focused certifications (e.g., OSWE, OSCP, GWAPT, GIAC GWEB).
- Minimum 7 years of experience in cybersecurity or software security, with at least 3 years in a senior or lead product/application security role.
- Fluency in English.
Top Skills
What We Do
From London to Singapore and from San Francisco to São Paulo, we help businesses enter new markets, explore new industries, and reach new milestones. We are driven by a deep-seated determination to be the best possible partner for our customers – giving you the support you need to capitalize on a world that’s changing at breakneck speed.
Our mission is to provide innovators with a convenient and simple financial interface that enables payments to flow freely and invisibly across borders. We offer a wide range of services, including payment gateway, card acquiring, business accounts, card issuing, alternative payment methods, and more.
That’s the reason why we are called Unlimit: we provide unlimited growth opportunities for our customers, freeing them from the payment constraints.
Unlimit - Borderless Payments