wagey.ggwagey.gg
31,365  jobs31,365  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(31,365)/Application Security Engineer Role(56)/MoonPay (19) - Application Security Engineer
MoonPay

MoonPay - Application Security Engineer

Remote - Portugal$250k - $250k+ Equity5mo ago
RemoteEMEACryptocurrencyFintechApplication Security EngineerJavaScriptTypeScriptTraining DevelopmentCloudflareDocumentation

Requirements

• You contribute or have contributed to the security community through open source involvement, participation in CTFs, or speaking at local information security meetups and conferences. • Your background includes experience working with disruptive technologies and successfully launching products, ideally within FinTech, SaaS, or Crypto. • You hold one or more security relevant certifications such as OSCP or OSWE. • BLOCK Values

Responsibilities

• Conduct threat modelling reviews of Technical Design Documents (TDDs) for new and existing features, providing clear, actionable security recommendations early in the design process. • Perform and support application security assessments, including penetration testing, vulnerability assessments, and proof-of-concept (PoC) development where appropriate. • Investigate, triage, and respond to Bug Bounty program submissions, validating findings and working with engineering teams to drive timely remediation. • Own and continuously improve application-layer protections, including managing and tuning Cloudflare WAF and related security controls. • Partner closely with engineering teams to embed security best practices throughout the SDLC, from design and development through deployment and maintenance. • Research and track emerging threats and vulnerabilities, translating findings into practical mitigation strategies relevant to our technology stack. • Develop and deliver security guidance, training, and awareness for engineering teams to raise the overall security maturity of the organization. • Contribute to the creation, maintenance, and evolution of security standards, processes, and documentation. • Participate in and eventually lead incident response activities, supporting investigation, containment, remediation, and post-incident improvements. • You have developed a breadth of experience across multiple security domains, including web and mobile application security, infrastructure and cloud security, and can connect these areas to drive a holistic security approach. • You have hands-on experience performing white-box, source code-assisted web and mobile application penetration testing, from vulnerability discovery through triage and exploitation. • You have the ability to read, understand, and review source code to identify security issues, with ideally, a particular focus on JavaScript and TypeScript codebases. • You have a strong understanding of Threat Modelling principles and their practical application to the secure software development lifecycle (SDLC). • You have experience working with web application firewalls to help protect applications, assess coverage, and support tuning rules to mitigate common attack patterns. • You have experience embedding application security practices into CI/CD pipelines, enabling early detection of vulnerabilities and close collaboration with engineering teams throughout the development lifecycle. • You have collaborated closely with engineering teams to clearly communicate security findings, explain vulnerabilities, attack paths, and mitigations, and support the implementation of effective fixes for both technical and non-technical audiences. • You are self-motivated, proactive, and take strong ownership of your work, operating effectively in a remote environment while maintaining a collaborative, team-focused mindset. • You have experience in JavaScript and TypeScript, including the ability to read, understand, and reason about modern web application codebases. • You have experience working with Cloudflare, including its hosting and Web Application Firewall (WAF) capabilities, to help secure and operate internet-facing applications. • You have experience testing and securing GraphQL, REST APIs, including understanding common GraphQL/REST-specific attack vectors and security considerations. • You have experience or a strong interest in Web3 security testing, including assessing smart contracts, blockchain-based applications, or Web3 integrations. • You have an interest in agentic engineering, including emerging patterns in autonomous systems, tooling, or workflows, and their security implications.

Benefits

• Pay for performance equity bonus: • 🚀 Moonshot award. • Unlimited holidays: • Hybrid working schedule: • Enhanced parental leave: • Annual training budget: • Remote working allowance: • Monthly budget to spend on our products and zero fee crypto transactions: • Employee referral programme: • Regular remote company offsites: • 🚀 Working in a disruptive and fast-growing company where excellence is rewarded • Commitment To Diversity

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

CAISCAIS - Lead Application Security Engineer2w ago
·London, England·Equity
In OfficeEMEAStaffCloud ComputingSoftwareApplication Security EngineerJavaJavaScriptAWSKotlinTypeScriptReactDocumentation
igaminghuntigaminghunt - Application Security Engineer1w ago
·Hybrid - Europe *
In OfficeEMEACloud ComputingSoftwareApplication Security EngineerPythonShellPerformance ReviewsJavaScriptTypeScriptTerraformHelmDockerIstioKubernetesAWS
writerwriter - Security engineer, application security (UK)2mo ago
·London, England, United Kingdom - Hybrid·Equity
In OfficeEMEAMidGenomicsArtificial IntelligenceSecurity EngineerApplication Security EngineerJavaGoPythonJavaScriptTypeScript
Thought MachineThought Machine - Senior Application Security Engineer1mo ago
·Lisbon, Portugal·€80k - €105k/year
In OfficeEMEASeniorCloud ComputingSoftwareApplication Security EngineerGoJavaPythonPerformance ReviewsAWS
BugcrowdBugcrowd - Application Security Engineer II5mo ago
·Remote - UK
RemoteEMEAMidPublic SectorApplication Security EngineerProgram ManagementLinuxPhoenix
AlphaSenseAlphaSense - Senior Application Security Engineer2mo ago
·Remote - USA·$157k - $157k/year + Equity
RemoteNASeniorCloud ComputingSoftwareApplication Security EngineerFounderPublic SpeakingTraining DevelopmentJavaScriptTypeScriptJava
Spring HealthSpring Health - Senior Application Security Engineer II2w ago
·Remote - USA·$180k - $206k/year
RemoteNASeniorDigital HealthCloud ComputingApplication Security EngineerGoRubyPythonJavaScriptDocumentationPerformance ReviewsRisk ManagementAWSAzureGCPCross-functional CollaborationPhoenixVector
Neko HealthNeko Health - Security Engineer – Application Security4mo ago
·Remote - Germany, Sweden, United Kingdom
RemoteEMEASoftwareSecurity EngineerApplication Security EngineerPerformance ReviewsWagmiDocumentation
QualiaQualia - Senior Application Security Engineer2mo ago
·Remote - United States of America·$180k - $210k/year + Equity
RemoteNASeniorFintechCloud ComputingApplication Security EngineerReportingAWSDockerKubernetesTerraform

Browse more by category

Show 56 moreApplication Security EngineerShow 1,262 moreJavaScriptShow 2,089 moreTypeScriptShow 625 moreTraining DevelopmentShow 74 moreCloudflareShow 5,262 moreDocumentation
Privacy·Terms··Contact·FAQ·Wagey on X