Security Engineer, Application Security
Reap Hong Kong, Hong Kong Island, Hong Kong S.A.R.
Information Technology & Services · 201-500 employees
About the role
You will own the secure SDLC by embedding security into the engineering process and building tooling to catch vulnerabilities in the CI/CD pipeline. Additionally, you will lead threat modelling sessions, manage penetration testing, and oversee the bug bounty program.
What they look for
Requirements
You should have hands-on experience improving application security programs within engineering organizations and proficiency in SAST/DAST/SCA tools. Strong skills in secure code review for languages like Python, Go, or Rust and knowledge of PCI DSS and threat modelling frameworks are required.
Benefits
Full description
About Reap
Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.
With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.
Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.
Founded in 2018
Security at Reap
Reap builds financial connectivity for a multi‑rail world-traditional finance, stablecoins, and real‑time payments. Security is foundational to that mission. We're looking for a pragmatic engineer who can turn regulation into robust systems, and complex threats into clear controls. You'll partner with Engineering, Risk, and Operations to keep value moving safely, globally, and 24/7.
Your Mission
During our acquisition by Payward/Kraken, their due diligence team found a race condition vulnerability in our product. We found it second. That is not the position we want to be in going forward.
As our Application Security Engineer, you will embed security inside the engineering process rather than bolting it on afterwards. You will own our secure SDLC, build the tooling that catches vulnerabilities in the pipeline before they ship, run threat modelling sessions with our engineering squads, and manage our bug bounty programme.
This is a builder role that works inside the engineering team, not above it.
What You Will Do
- Build and own the application security programme: secure coding standards, developer security training, security review gates in the engineering workflow, and the SAST/DAST/SCA tooling that enforces them in CI/CD.
- Lead threat modelling for new product features, API integrations, and significant architectural changes. Run STRIDE-based sessions with engineering squads who have not done this before.
- Do security-focused code reviews for the areas that matter: authentication, authorisation, payment flows, cryptographic operations, and external API integrations.
- Own our dependency and open source software security: scan, assess, and enforce our OSS usage policy.
- Run developer security education: OWASP Top 10, OWASP API Top 10, a security champions network, and practical sessions that engineers actually find useful.
- Manage penetration testing engagements end-to-end: scope, vendor, findings, and remediation verification.
- Own our responsible disclosure policy and manage our bug bounty programme once it launches.
Your Superpowers
- You have improved an application security programme inside an engineering organisation. You know
what the before and after looks like, and how to get engineering buy-in for both.
- Hands-on SAST/DAST/SCA pipeline experience. Semgrep, CodeQL, Checkmarx, SonarQube, or
equivalent. You have configured these in CI/CD, not just run them on demand.
- You can do threat modelling with engineers who have never done it. STRIDE or PASTA. You facilitate,
not lecture.
- Secure code review in at least two languages. JavaScript/TypeScript, Python, Go, or Rust. You can read code and find the vulnerability, not just run a scanner.
- Application penetration testing fundamentals. OWASP Top 10 and API Top 10 in practice. You know
how authentication and authorisation get broken.
- PCI DSS secure coding requirements. We handle payment card data. You know what that means for
development.
Nice to Have
- CSSLP, GWEB, or OSCP certification.
- Crypto or DeFi application security experience.
- Bug bounty programme management experience.
- Experience with smart contract interaction security or exchange API security.
Why You Will Love It Here
- You are building the application security function at a fast-moving fintech from scratch, with direct access to engineering leadership.
- The race condition finding gave us a very specific brief: find things like that before the acquirer does. You will have a clear mandate.
- We use AI tools extensively. GitHub Copilot, Claude Code, and others are part of how we build. You will help make sure we build securely with them.
- Flexible remote work, global team, and a company that is growing fast.
Benefits you'll enjoy
- A vibrant, inclusive work culture.
- Annual leave to relax and recharge, plus public holidays.
- Health insurance budget.
- Be part of a fast‑growing global team.
- Flexible remote work options.
- Home office equipment budget.
- Your own Corporate Reap Card-no more out‑of‑pocket spending.
About Reap
Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.
With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.
Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.
Founded in 2018 Coworkers 300+
Similar roles
-
Cybersecurity Control Officer
Inetum Porto, Portugal
-
SSE - Information Security Engineer
Arcesium LLC Gurugram, Haryana, India
-
Application Security Consultant, Google Cloud, Mandiant Consulting
Google Doha, Qatar
-
Staff Product Security Engineer
Affirm Canada · CA$181K–CA$241K/yr
-
Senior Security Engineer
ZeroNorth Copenhagen, Capital Region of Denmark, Denmark
-
Barlows UK Ltd - Apprentice Fire and Security Engineer - Bristol
Apprenticeships at Skills for Security Bristol, England, United Kingdom · £17K/yr