Senior Application Security Engineer
Colibrix One · Limassol, Limassol, Cyprus
Financial Services · 51-200 employees
About the role
You will own the end-to-end product security function, including implementing Secure SDLC, managing CI/CD security gates, and performing vulnerability assessments. Additionally, you will conduct security design reviews, provide developer training, and ensure compliance with industry standards like PCI DSS.
What they look for
Requirements
The role requires 4+ years of experience in application security or penetration testing with strong proficiency in web and API security. Candidates must have hands-on experience with security tooling in CI/CD pipelines and familiarity with Go, PHP, or JavaScript.
Benefits
Full description
Join COLIBRIX ONE – Innovating the Future of Payments
At COLIBRIX ONE*, we’re building advanced, AI-powered payment technologies that support Payment Service Providers (PSPs), Electronic Money Institutions (EMIs), and neobanks across the EU and the UK. As a fully licensed Electronic Money Institution (FCA Reference No. 927920) and holder of a Financial Institution Licence issued by the MFSA, as well as a principal member of both VISA and Mastercard, we provide comprehensive, real-world financial solutions that include:
- Global card processing
- Digital wallet infrastructure
- Cross-border merchant accounts
- Alternative payment methods (APMs)
- Corporate accounts for legal entities
We’re a fast-growing team with a passion for innovation, security, and scalability. Our culture values curiosity, collaboration, and impact - and we’re looking for talented professionals who are ready to shape the future of fintech.
At COLIBRIX ONE, your work directly powers the digital economy. If you're eager to solve meaningful challenges and build with purpose, we’d love to hear from you.
About the RoleWe’re looking for an Senior Application Security Engineer to build and scale our product security function across the Group. As the first dedicated AppSec specialist, you’ll own security practices end to end — from Secure SDLC and CI/CD security gates to vulnerability management, security testing, and developer enablement. You’ll work closely with the Group CISO and security team to help build secure, scalable fintech products.
Key ResponsibilitiesSecure SDLC
- Roll out our Secure SDLC process to all products, one by one. The pilot is done; you scale it.
- Run security design reviews for critical changes (auth, payments, admin, crypto). Use lightweight threat modeling.
- Keep the security review process fast. Target: first response within 1 working day, async review within 3.
Security tooling in CI/CD
- Own SAST, SCA, secret scanning, and IaC scanning in GitLab CI (Semgrep, Trivy, gitleaks, Checkov).
- Write custom Semgrep rules based on real findings in our code.
- Make the pipelines stable and useful. Low noise, clear signal, blocking gates where it matters.
Vulnerability management
- Triage findings from pentests, scanners, and our attack surface monitoring. SLA: triage within 2 working days.
- Verify fixes with confirmation scans before closing.
- Re-test old pentest findings so they do not come back.
Product security testing
- Do hands-on security testing of our web apps and APIs: payment flows, back-office panels, partner integrations.
- Review source code for security issues (Go, PHP, JavaScript).
- Help dev teams design secure APIs: request signing, key rotation, replay protection, rate limiting.
Bug bounty
- Prepare and launch our private bug bounty program. Later, take it public.
- Own triage, researcher communication, and reward decisions.
People and compliance
- Train developers: short secure-coding sessions, based on our own findings.
- Support the Security Champions program in dev teams.
- Provide evidence for PCI DSS and DORA audits (secure development, payment page integrity, change control).
What you need to succeed in this role• 4+ years in application security and/or penetration testing
- Strong web and API security skills: OWASP Top 10 is your comfort zone, business logic flaws are your interest
- You can analyze source code and identify security flaws. Experience with Go, PHP, or JavaScript is required, with Go being a plus
- Hands-on experience adding security tools to CI/CD pipelines (any of: Semgrep, Trivy, gitleaks, or similar)
- Ability to write clear, actionable security reports and communicate findings effectively with development teams
- Strong prioritization skills - you understand risk impact and can distinguish critical issues from lower-priority findings
- B1+ level of English proficiency is required to work with technical documentation
Nice to have• Practical certificates: OSCP, OSWE, BSCP, or similar
- Experience running or managing a bug bounty program
- Experience with AI-assisted vulnerability triage and review
- Kubernetes and AWS security basics
- Mobile (Android) security testing
- Experience in fintech or another regulated industry (PCI DSS is a strong plus)
What we offer• Opportunity to shape the future of fintech solutions within a growing company
- Collaborative, horizontal team structure that values your expertise and ideas
- Continuous learning and development opportunities to enhance your skills and career growth
- Competitive salary and benefits package
* This position is offered within the COLIBRIX ONE. Employment will be under the appropriate legal entity based on the role and location.