We are seeking a skilled Application Security Engineer to lead the security efforts for Bykea’s applications and infrastructure. In this role, you will be responsible for ensuring secure-by-default architectures through threat modeling and secure design reviews. You will design and implement scalable security solutions that proactively detect and remediate vulnerabilities, while driving a shift-left security approach by integrating security tools within CI/CD pipelines. This position requires close collaboration with engineering teams to identify, prioritize, and mitigate security risks across products, features, and infrastructure, fostering a strong security-first culture throughout the organization.
Key Responsibilities
- Lead threat modeling and secure design reviews to ensure robust security architectures across applications and infrastructure.
- Design and implement scalable security solutions for proactive vulnerability detection and remediation.
- Integrate Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and other security tools into CI/CD pipelines to promote shift-left security.
- Conduct advanced dynamic (DAST) and static (SAST) analysis on microservices and mobile applications.
- Identify, prioritize, and remediate security risks across products, features, and infrastructure.
- Define and enforce best practices for application security throughout the software development lifecycle (SDLC).
- Assess and mitigate risks associated with third-party libraries and dependencies.
- Lead vulnerability triage and remediation efforts in collaboration with engineering teams.
- Act as a security champion by mentoring teams and promoting a security-first mindset across the organization.
Required Qualifications
- Minimum of 5 years of hands-on experience in Application Security, with a proven track record of delivering measurable security improvements.
- Strong proficiency in scripting and development, preferably in Python and JavaScript.
- Demonstrated experience integrating and managing security tools such as SAST and DAST within CI/CD environments.
- Solid expertise in cloud and infrastructure security, including AWS, Kubernetes, and Infrastructure as Code tools like Terraform or CloudFormation.
- Deep understanding of web security principles, including TLS/SSL, authentication mechanisms, and network protocols such as HTTP/HTTPS and TCP/IP.
- Experience securing mobile applications, web applications, and microservices-based architectures.
- Proven ability to secure high-scale, high-availability systems.
- Familiarity with cloud platforms such as AWS or GCP and their security best practices.
- Strong collaboration and communication skills, with the ability to influence and work effectively across cross-functional teams.
Preferred Qualifications and Benefits
- Relevant industry certifications such as OSCP or AWS Security Specialty are considered a plus.
- Opportunity to work in a dynamic environment focused on innovation and security excellence.
- Chance to lead and shape security practices across a rapidly growing technology platform.
This role offers a unique opportunity to make a significant impact on the security posture of a fast-paced organization by embedding security deeply into the development lifecycle and infrastructure. If you are passionate about application security and enjoy working collaboratively to solve complex security challenges, this position is an excellent fit.