Applications Security Specialist

5 hours, 31 minutes ago
Full-time
Mid Level
Software Development

Marathon Talent

Marathon Talent is a human resources and talent advisory firm that helps companies hire top bilingual talent from Latin America through recruitment, fractional people and talent strategy, market insights, salary studies, and advisory/mentorship services.

Human Resources
1-10
Founded 2023

Description

  • Conduct secure code reviews for Go-based microservices and identify vulnerabilities early in development.
  • Perform security testing of APIs, web applications, and backend services before production releases.
  • Establish and evolve secure coding standards, guardrails, and reusable engineering patterns.
  • Lead threat modeling sessions with engineering and product teams during feature and service design.
  • Define and enforce security gates in CI/CD pipelines, including SAST, DAST, SCA, and secrets scanning.
  • Own the end-to-end DAST process, including tool selection, scheduling, escalation, and remediation tracking.
  • Integrate container image scanning and infrastructure-as-code security checks into deployment pipelines.
  • Support hardening efforts across Kubernetes, ingress, and workloads.
  • Define and tune security observability alerts for authentication anomalies and suspicious API usage.
  • Triage, prioritize, and track remediation of security findings across the platform.
  • Coordinate external penetration tests and work with vendors on scope, debriefs, and remediation plans.
  • Build and maintain security documentation, runbooks, and standards.

Requirements

  • 3–5 years of experience in application security, product security, or a similar role.
  • Hands-on experience with SAST/DAST tools such as Snyk, Checkmarx, OWASP ZAP, Burp Suite, or equivalent.
  • Solid knowledge of OWASP Top 10 for web and APIs and real-world exploitability assessment.
  • Experience reviewing code in Go or similar compiled languages.
  • Familiarity with Kubernetes, containers, and cloud-native architectures.
  • Strong written and verbal communication skills with the ability to explain security risks to technical and non-technical stakeholders.
  • Self-driven and comfortable working with autonomy in a fast-paced environment.
  • English proficiency in both written and spoken communication.
  • Certifications such as OSCP, OSWE, CEH, or eWPT are a plus.
  • Experience with Istio or service mesh security is a plus.
  • Familiarity with compliance frameworks such as ISO 27001, GDPR, or SOC 2 is a plus.
  • Threat modeling experience with STRIDE, PASTA, or similar is a plus.
  • Experience in fintech or regulated environments is a plus.

Benefits

  • Opportunity to join a high-impact, mission-driven fintech with regional scale.
  • Cross-functional collaboration with strong teams across Latin America.
  • Equipment provided by R2.
  • Training budget for professional development.
  • Career growth opportunities within R2.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Product Security Engineer

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Product Security Engineer in the UK to secure advanced defense technologies, including AI systems, command and control platforms, aerospace vehicles, and long-range sensors.

C C++ Cybersecurity Embedded Systems Go IoT Linux Network Security Python Rust
5 hours, 1 minute ago

Application Security Engineer — Secure Mission Systems

Rackner 11-50 Internet Software & Services

Rackner is hiring a remote Application Security Engineer to strengthen secure software for Department of Defense mission systems through hands-on testing, vulnerability remediation, and secure delivery support.

CI/CD Git GitLab Kubernetes OpenShift
1 day, 4 hours ago

Product Security Engineer

Action1 11-50 Internet Software & Services

Action1 is seeking a Product Security Engineer to help secure its multi-tenant SaaS platform by partnering with engineering, product, and security teams to identify risks early and strengthen secure development practices.

AWS C++ Cybersecurity DevSecOps JavaScript Network Security Penetration Testing
1 day, 4 hours ago

Sr. Application Security Engineer

Mitek Systems 251-1K Communications Equipment

Mitek is hiring an Application Security Engineer to own the security of its internet-hosted banking and financial software, driving vulnerability remediation and secure development practices across the engineering organization.

1 day, 5 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers