We are seeking a seasoned Application Security Engineer to lead the security efforts for Bykea’s applications and infrastructure. In this role, you will be responsible for driving secure-by-default architectures through threat modeling and secure design reviews. You will design and implement scalable security solutions that proactively detect and remediate vulnerabilities, ensuring robust protection across all products and services. This position requires close collaboration with engineering teams to embed security into the software development lifecycle and promote a security-first culture throughout the organization.
Key Responsibilities
- Lead threat modeling and secure design reviews for applications and infrastructure to ensure secure-by-default architectures.
- Design and implement scalable security solutions aimed at proactively identifying and remediating vulnerabilities.
- Drive “shift-left” security practices by integrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and other security tools into CI/CD pipelines.
- Conduct advanced dynamic (DAST) and static (SAST) security analysis across microservices and mobile applications.
- Identify, prioritize, and remediate security risks across products, features, and infrastructure components.
- Define and enforce best practices for application security throughout the software development lifecycle (SDLC).
- Assess and mitigate risks associated with third-party libraries and dependencies.
- Lead vulnerability triage and remediation efforts in close collaboration with engineering teams.
- Act as a security champion by mentoring teams and fostering a strong security-first culture across the organization.
Required Qualifications
- Minimum of 5 years of hands-on experience in Application Security with a proven track record of delivering measurable security improvements.
- Strong proficiency in scripting and development, preferably with Python and JavaScript.
- Demonstrated experience integrating and managing security tools such as SAST and DAST within CI/CD environments.
- Solid understanding and practical experience with cloud and infrastructure security, including AWS, Kubernetes, and infrastructure-as-code tools like Terraform or CloudFormation.
- Deep knowledge of web security principles, including TLS/SSL, authentication mechanisms, and network protocols such as HTTP/HTTPS and TCP/IP.
- Experience securing mobile applications, web applications, and microservices-based architectures.
- Proven ability to secure high-scale, high-availability systems.
- Familiarity with cloud platforms such as AWS or GCP and their associated security best practices.
- Strong collaboration and communication skills, with the ability to influence and work effectively across cross-functional teams.
Preferred Qualifications and Benefits
- Relevant security certifications such as OSCP (Offensive Security Certified Professional) or AWS Security Specialty are considered a plus.
- Opportunity to work in a dynamic environment where you can lead impactful security initiatives.
- Chance to mentor and grow security awareness within a forward-thinking organization.
This role offers the chance to be at the forefront of application security, shaping the security posture of a fast-growing company while working alongside talented engineering teams. If you are passionate about building secure systems and driving security excellence, this position provides a rewarding and challenging career path.