Senior Application Security Engineer
Global fintech company offering payments, banking-as-a-service, and crypto on/off-ramp solutions.
About Unlimit
Unlimit (formerly Unlimint; unlimit.com) is a London-headquartered global fintech providing cross-border payments, banking-as-a-service, and crypto on/off-ramp products for merchants worldwide.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will drive secure software development practices, perform application security assessments, secure design reviews, and threat modelling. You will conduct manual source code reviews, integrate security testing into the SDLC, build automated security workflows in GitLab CI/CD, improve ASPM capabilities, support penetration testing, develop AI-powered security workflows, research attack techniques, and create reusable security guidance and engineering standards.
Requirements
- 5+ years of experience in Application Security, Software Security, DevSecOps, or security-focused Software Engineering
- Experience with modern application architectures
- Experience with threat modelling, secure design reviews, and manual code reviews
- Understanding of Secure SDLC principles
- Experience implementing automated security testing in CI/CD pipelines
- Hands-on experience with SAST, DAST, SCA, API security testing, ASPM, and application security tooling
- Understanding of attack techniques, exploitation methods, and secure coding practices
- Experience remediating vulnerabilities with engineering teams
- Strong scripting or programming skills in Java, Go, Python, Node.js, PHP, or Dart
- Experience with GitLab-based development workflows
- Practical penetration testing or offensive security experience
- Bug bounty or responsible vulnerability disclosure experience
- OSCP, OSWE, or similar offensive security certification
- Experience with secure architecture design and security patterns
- Experience developing AI-powered or agentic security automation
Responsibilities
- Drive secure software development practices across the organisation
- Perform application security assessments, secure design reviews, and threat modelling
- Conduct manual source code reviews and support remediation of complex security issues
- Integrate and optimise SAST, DAST, SCA, API security testing, and IaC security throughout the SDLC
- Build and improve automated application security workflows in GitLab CI/CD pipelines
- Own and continuously improve ASPM capabilities
- Partner with software engineering teams to identify vulnerabilities and implement security controls
- Coordinate external penetration testing assessments, validate findings, and drive remediation
- Develop AI-powered and agentic application security workflows
- Research emerging attack techniques and improve secure development and security testing
- Develop security guidance, reusable patterns, and engineering standards
