Senior Application Security Engineer
Your Challenge
As a Senior Application Security Engineer, you’ll be a hands-on technical expert responsible for improving the security of Unlimit’s applications, APIs, and development processes. You’ll help engineering teams identify and remediate security risks early, automate security testing, and integrate security seamlessly into modern CI/CD pipelines.
This role is ideal for someone who combines strong software engineering fundamentals with practical offensive security knowledge and enjoys building scalable, developer-friendly security solutions through automation and AI.
Your Challenge
As a Senior Application Security Engineer, you’ll be a hands-on technical expert responsible for improving the security of Unlimit’s applications, APIs, and development processes. You’ll help engineering teams identify and remediate security risks early, automate security testing, and integrate security seamlessly into modern CI/CD pipelines.
This role is ideal for someone who combines strong software engineering fundamentals with practical offensive security knowledge and enjoys building scalable, developer-friendly security solutions through automation and AI.
What You’ll Do
Drive secure software development practices across the organisation.
Perform application security assessments, secure design reviews, and threat modelling for new and existing products.
Conduct manual source code reviews for business-critical applications and support remediation of complex security issues.
Integrate and optimise security testing throughout the SDLC, including SAST, DAST, Software Composition Analysis (SCA), API security testing, and Infrastructure as Code (IaC) security.
Build and improve automated application security workflows within GitLab CI/CD pipelines.
Own and continuously improve Application Security Posture Management (ASPM) capabilities.
Partner closely with software engineering teams to identify vulnerabilities early and implement practical, scalable security controls.
Support penetration testing activities by coordinating external assessments, validating findings, and driving remediation.
Contribute to the development of internal AI-powered and agentic application security workflows, including automated security reviews, code analysis, and vulnerability triage.
Research emerging attack techniques and translate them into practical improvements across secure development and security testing.
Develop security guidance, reusable patterns, and engineering standards that enable developers to build secure software at scale.
What We’re Looking For
5+ years of experience in Application Security, Software Security, DevSecOps, or Software Engineering with a strong security focus.
Previous experience in fintech is preferred; experience in cryptocurrency is a strong plus.
Strong software development background with hands-on experience across modern application architectures.
Experience performing threat modelling, secure design reviews, and manual code reviews.
Strong understanding of Secure SDLC principles and practical application security engineering.
Experience implementing and maintaining automated security testing within CI/CD pipelines.
Hands-on experience with SAST, DAST, SCA, API security testing, ASPM, and modern application security tooling.
Practical understanding of modern attack techniques, exploitation methods, and secure coding practices.
Experience collaborating directly with engineering teams to remediate vulnerabilities and improve application resilience.
Strong scripting or programming skills in one or more of the following: Java, Go, Python, Node.js, PHP, or Dart (Flutter).
Experience working with GitLab-based development workflows.
A pragmatic, engineering-first mindset with a passion for automation and AI-assisted security.
Nice to Have
Practical penetration testing experience or an offensive security background.
Bug bounty participation or responsible vulnerability disclosure experience.
OSCP, OSWE, or similar offensive security certifications.
Experience with application or software architecture, including secure architecture design and security patterns.
Experience developing AI-powered or agentic security automation.
Contributions to open-source security projects, security research, or technical community initiatives.