Application Security Engineer - Senior
Posted 445 days ago, which is unusual. The employer's own board was still carrying it when we last read it, 1 hour ago.
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked just now — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 445d ago
The date the source published, not the day we noticed it (2025-06-27). Last seen at its source 1h ago.
Is it remote?
The listing says yes
The location field doesn't say remote, so our assessment is based on the title or the description. Read the listing before applying.
Who may apply?
Available worldwide
The description states no restriction of its own. This is the source's own tag.
Pay not stated
Similar roles pay $110k–164.5k/yr
Middle 50% of 25 listings that do state pay — Engineering · all levels · Worldwide · USD/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
greenhouse employer's own board first seen 1h ago · last seen 1h ago
The listing
We are looking for an Application Security Engineer to join our Information Security team.
The Information Security team is responsible for protecting Plata’s products, systems, and data by embedding security throughout the technology lifecycle. We work closely with engineering teams to identify and mitigate security risks, strengthen application defenses, and ensure security is integrated into every stage of software development.
As an Application Security Engineer, you will serve as a key link between development and security teams, designing, implementing, and maintaining robust application security controls. You’ll help embed security across the entire software development lifecycle — from design and development to testing and deployment — while continuously improving our application security practices.
Challenges that await you:
- Collaborate with Dev & Ops teams. Guide secure coding practices, participate in code reviews, and embed security seamlessly into the SDLC
- Conduct security reviews & threat modeling. Analyze application architecture, define threat models, and drive proactive risk identification
- Integrate security tools. Deploy and manage SAST, DAST, IAST, RASP, and SCA tools within CI/CD pipelines to automate early detection and remediation
- Handle security incidents
- Implement “shifting left” strategies, enforce continuous testing, fast remediation, and embed security culture across teams
- Educate and train. Conduct workshops to elevate developer security awareness and promote adherence to OWASP, ASVS, and secure design standards
What makes you a great fit:
- Proficient in programming languages (web/mobile)
- Strong understanding of web architectures (microservices)
- Deep knowledge of OWASP Top 10, threat modeling, and security testing frameworks
- Familiarity with security tools such as ZAP, Dependency-Track, Burp
- Strong analytical skills with precise and thorough attention to detail
Your bonus skills:
- Security certifications (OSCP, OSWE, GWAPT, GCPN)
- Contributions to or experience with bug bounty or ethical-hacking programs
- SaaS or cloud-native environments experience
- Familiarity with Kubernetes or container security
Our ways of working:
- Innovative Spirit: A commitment to creativity and groundbreaking solutions
- Honest Feedback: valuing open, transparent communication
- Supportive Team: a strong, collaborative community
- Celebrating Achievements: recognizing our wins together
- High-Tech Environment: a team full of smart and revolutionary people who date to challenge the status quo of incumbent finances
Our benefits:
- Relocation support to Kazahstan, Cyprus, Serbia or Spain with full visa & permit support to the employee and family
- Flexible work from one of our offices or remote
- Healthcare Coverage
- Education Budget: Language lessons, professional training and certifications
- Wellness Budget: Mental health and fitness activity reimbursements
- Vacation policy: 20 days of annual leave and paid sick leave