Application Security Engineer - Senior at Plata Card

on-site · full-time · Visa sponsorship

Apply for this role at Plata Card

Responsibilities:
- Partner with development and operations teams to embed security into the SDLC, including design, code reviews, testing, and deployment.
- Perform threat modeling and security reviews of application architecture to identify and prioritise risks.
- Integrate, configure and maintain SAST, DAST, IAST, RASP and SCA tools in CI/CD pipelines for automated detection and fast remediation.
- Drive “shift-left” practices: enable early testing, triage findings, and track remediation across teams.
- Respond to application security incidents, perform root-cause analysis, and recommend fixes.
- Run developer training, workshops and guidance on OWASP, ASVS, secure design and secure coding standards.

Requirements:
- Strong knowledge of web/mobile application security, OWASP Top 10, ASVS and threat modeling techniques.
- Practical experience with SAST/DAST/IAST/RASP/SCA tools (eg. ZAP, Burp, Dependency-Track) and integrating them into CI/CD.
- Comfortable with microservices, container platforms (Kubernetes) and container security concepts.
- Proficiency in at least one programming language used for web/mobile development and ability to read/review code.
- Strong analytical mindset, attention to detail, and experience communicating risk to engineers and stakeholders.
- Nice-to-have: security certifications (OSCP/OSWE/GWAPT/GCPN), bug-bounty/ethical-hacking experience, SaaS or cloud-native environment experience.