Salmon
Hey
International technology-driven financial company Salmon looking for: Application Security Lead
Location - remote (exlude Belarus and Russia)
🏽7+ years in application security, with meaningful ownership over both technical work and process.
🏽Has built or substantially improved a secure SDLC in a fast-moving product org.
🏽Has run threat modeling on real product features and influenced design decisions as a result.
🏽Has owned vulnerability management end-to-end: triage, remediation tracking, SLA management, risk acceptance.
🏽Has done hands-on mobile security testing (iOS and/or Android) in a production context, not just UAT.
🏽Understands modern supply chain attack vectors like compromised packages (npm, PyPI), malicious IDE plugins, typosquatting, dependency confusion - and knows how to reduce exposure at the tooling and process level.
🏽Comfortable writing Python or Bash to automate repetitive security work.
SAST, DAST, SCA in CI/CD pipelines: knows how to tune for signal, not just coverage
API security: authentication flows, token handling, common abuse patterns
Mobile security: OWASP ASVS/MASVS applied in practice
Supply chain: SBOM generation and dependency risk management
Secrets management: detection, remediation, and structural prevention
Working knowledge of AWS and containers sufficient to understand where application risks extend into infrastructure
Southeast Asia's fintech moment starts here.
Сontact me
or apply
Обновлено 30 июля