Application Security Engineer
Transak is payments infrastructure for stablecoins and crypto, enabling financial applications to provide fiat-to-crypto and crypto-to-fiat flows, virtual-account payments, compliance, and settlement.
Maintainer signals as of 9/2/2026
Funding history
Projects
About Transak
Transak provides API- and widget-based crypto payment infrastructure for financial applications. Its offering covers on-ramp, off-ramp, NFT checkout, virtual-account payments, OTC trading, KYC, compliance, payment-method integration, and stablecoin settlement across multiple jurisdictions and blockchain networks.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will own application and product security from design through deployment. You will integrate security into development workflows, review code and architecture, automate security testing, manage software supply-chain risks, oversee vulnerability remediation, perform penetration testing, develop secure coding standards, run security training and bug bounty activities, and provide evidence for regulatory and compliance requirements.
Requirements
- 5+ years of security engineering experience focused on application or product security
- Deep knowledge of web and API security including OWASP Top 10 authentication authorisation and session management
- Hands-on experience with Burp Suite OWASP ZAP Snyk or Aikido
- Strong programming skills in JavaScript Node.js or Python
- Experience integrating security tools into GitLab CI Jenkins or GitHub Actions
- Practical software composition analysis and SBOM experience
- Experience owning vulnerability management programmes
- Experience applying threat modelling to business flows and distributed systems
- Understanding of cryptography secrets management and identity and access management
- Excellent communication skills for engineering audiences
- Ability to build a security capability from scratch
- Cryptocurrency blockchain fintech payments or custody security experience is advantageous
- Knowledge of SBOM formats build provenance SLSA EPSS and CISA KEV is advantageous
- Knowledge of DORA MiCA SOC 2 ISO 27001 or GDPR is advantageous
- Experience managing penetration testing vendors or bug bounty programmes is advantageous
- OSCP OSWE GWAPT or CSSLP certification is advantageous
Responsibilities
- Embed security into the software development lifecycle
- Conduct code reviews threat modeling and architecture reviews
- Implement and tune SAST DAST and SCA solutions
- Automate application security testing in CI/CD pipelines
- Manage SBOMs dependencies provenance standards and approved base images
- Maintain the vulnerability register and drive remediation
- Perform penetration testing and vulnerability assessments
- Manage external penetration testing engagements
- Develop secure coding standards and reusable security components
- Deliver role-based security training
- Create a security champions programme
- Run the bug bounty programme
- Research application and supply-chain threats
- Evidence controls for DORA MiCA SOC 2 and ISO 27001
Benefits
- Equity options
- Comprehensive benefits offering
