Application Security Lead
Hey International technology-driven financial company Salmon looking for: Application Security Lead Location - remote (exlude Belarus and Russia) What makes you a strong fit: 🏽 7+ years in application security, with meaningful ownership over both technical work and process. 🏽 Has built or substantially improved a secure Sdlc in a fast-moving product org. 🏽 Has run threat modeling on real product features and influenced design decisions as a result. 🏽 Has owned vulnerability management end-to-end: triage, remediation tracking, SLA management, risk acceptance. 🏽 Has done hands-on mobile security testing (iOS and/or Android) in a production context, not just UAT. 🏽 Understands modern supply chain attack vectors like compromised packages (npm, PyPI), malicious IDE plugins, typosquatting, dependency confusion - and knows how to reduce exposure at the tooling and process level. 🏽 Comfortable writing Python or Bash to automate repetitive security work. Technical skills: Sast, Dast, SCA in CI/CD pipelines: knows how to tune for signal, not just coverage API security: authentication flows, token handling, common abuse patterns Mobile security: Owasp Asvs/Masvs applied in practice Supply chain: Sbom generation and dependency risk management Secrets management: detection, remediation, and structural prevention Working knowledge of AWS and containers sufficient to understand where application risks extend into infrastructure Southeast Asia's fintech moment starts here. Сontact me or apply https://careers.salmon.ph/open-roles?ashby_jid=51d03b6c-aad1-4d1f-9f68-c09cb2866a69
Apply at the original listing — get the contact there.
Find jobs that match my skills
Tell us what you can do — we'll find jobs that need it and show how the pay compares.
Find jobs — freeThis listing may be posted directly or aggregated from a public source. We are a platform, not the employer. Verify details before applying and never pay for employment.