Jobiglo

No results.

Application Security Engineer

Pepperstone · Limassol

Senior 🇬🇧 English
Threat modelling Secure code review Penetration testing SAST DAST SCA Secrets detection Burp Suite OWASP ZAP Semgrep Checkmarx Snyk Responsible disclosure

Job description

About the role

The Application Security Engineer will embed security throughout Pepperstone's software development lifecycle. Working closely with engineering and product teams, you will ensure that security is a first‑class citizen in every release and help foster a security‑aware culture.

Key responsibilities

  • Perform application security assessments, including threat modelling, secure code reviews, and penetration testing for web, mobile, and API surfaces.
  • Integrate security controls into CI/CD pipelines using SAST, DAST, SCA, and secrets‑detection tooling.
  • Identify, triage, and track vulnerabilities through remediation, providing actionable guidance to developers.
  • Define and maintain application security standards, secure coding guidelines, and developer‑facing documentation.
  • Champion security‑by‑design principles during design and architecture phases.
  • Lead bug bounty and responsible disclosure programmes, coordinating triage and remediation of external reports.
  • Conduct security training and awareness sessions for software engineers.
  • Evaluate third‑party libraries, open‑source components, and vendor integrations for security risk.
  • Collaborate with the broader Security team on incident response related to application‑layer vulnerabilities.

Required profile

  • 8+ years of experience in information security, with at least 3 years focused on application or software security engineering.
  • Strong understanding of common vulnerability classes, including OWASP Top 10, business logic flaws, and API security risks.
  • Proven ability to work with development teams to embed security into agile processes.

Required skills

  • Threat modelling and secure code review.
  • Penetration testing of web, mobile, and API applications.
  • SAST, DAST, SCA, and secrets‑detection tools.
  • Burp Suite, OWASP ZAP, Semgrep, Checkmarx, Snyk.
  • CI/CD pipeline integration for security controls.
  • Bug bounty program management and responsible disclosure.
  • Evaluation of third‑party and open‑source components for security risk.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Pepperstone.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Cyprus.

Salaries by job title

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 2 weeks ago

Expires 1 month from now

16 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Pepperstone

Limassol