We are seeking an experienced Application Security Engineer to lead and enhance the security posture of Bykea’s applications and infrastructure. In this role, you will be responsible for driving secure design principles, implementing scalable security solutions, and integrating security practices early in the development lifecycle. You will work closely with engineering teams to identify and remediate vulnerabilities, promote a security-first culture, and ensure robust protection across all products and services.
Key Responsibilities
- Lead threat modeling and secure design reviews to ensure secure-by-default architectures for applications and infrastructure.
- Design and implement scalable security solutions aimed at proactive vulnerability detection and remediation.
- Drive “shift-left” security by integrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and other security tools within CI/CD pipelines.
- Conduct advanced dynamic and static security analyses across microservices and mobile applications.
- Identify, prioritize, and remediate security risks spanning products, features, and infrastructure components.
- Define and enforce best practices for application security throughout the software development lifecycle (SDLC).
- Assess and mitigate risks associated with third-party libraries and dependencies.
- Lead vulnerability triage and remediation efforts in close collaboration with engineering teams.
- Act as a security champion by mentoring teams and fostering a strong security-first mindset across the organization.
Required Qualifications
- Minimum of 5 years of hands-on experience in Application Security, with a proven track record of delivering measurable security improvements.
- Strong proficiency in scripting and development, preferably with Python and JavaScript.
- Demonstrated experience integrating and managing security tools such as SAST and DAST within CI/CD environments.
- Solid background in cloud and infrastructure security, including working knowledge of AWS, Kubernetes, and infrastructure-as-code tools like Terraform or CloudFormation.
- Deep understanding of web security principles, including TLS/SSL, authentication mechanisms, and network protocols such as HTTP/HTTPS and TCP/IP.
- Experience securing mobile applications, web applications, and microservices-based architectures.
- Proven ability to secure high-scale, high-availability systems.
- Familiarity with cloud platforms such as AWS or GCP and their security best practices.
- Strong collaboration and communication skills, with the ability to influence and work effectively across cross-functional teams.
Preferred Qualifications and Benefits
- Relevant security certifications such as OSCP or AWS Security Specialty are considered a plus.
- Opportunity to work in a dynamic environment where you can lead security initiatives and make a significant impact.
- Chance to mentor and develop security awareness across diverse teams, promoting a culture of security excellence.
This role offers the chance to be at the forefront of application security within a fast-growing organization, working on cutting-edge technologies and complex systems. If you are passionate about building secure systems and enjoy collaborating with engineering teams to embed security into the development process, this position is an excellent fit.