Description

Role Purpose

An established or growing technology team operating in the financial services sector is seeking an Application Security Engineer to improve the security of web applications, backend services, APIs, and customer-facing digital products.

The position concentrates on identifying and preventing software vulnerabilities before they reach production. You will collaborate directly with software developers, architects, quality assurance specialists, and infrastructure engineers to assess application risks, improve secure coding practices, and strengthen the protection of sensitive financial and personal information.

The successful applicant will combine practical security testing skills with an understanding of application architecture and the realities of delivering reliable software in a regulated industry.

Primary Responsibilities

Application Security Assessment

  • Conduct application security reviews, vulnerability assessments, and targeted penetration tests within authorised environments.
  • Identify risks involving broken access controls, injection vulnerabilities, insecure authentication, session management weaknesses, and sensitive data exposure.
  • Assess REST APIs and other service interfaces for authorisation flaws, excessive data exposure, and insecure integration patterns.
  • Perform threat modelling for new features, payment workflows, account-management functions, and external service integrations.
  • Evaluate third-party libraries and dependencies for known vulnerabilities and assess their potential impact on production systems.

Secure Development Enablement

  • Work with developers to integrate secure coding principles into design, implementation, testing, and code review.
  • Provide clear remediation guidance, proof-of-concept demonstrations where appropriate, and practical recommendations for preventing recurring vulnerabilities.
  • Help establish security acceptance criteria for new applications and major feature releases.
  • Develop reusable security test cases and support automated application security testing.
  • Contribute to secure coding guidelines, developer training, and internal security knowledge-sharing sessions.

Risk Management and Assurance

  • Maintain application security findings, prioritise remediation according to exploitability and business impact, and track issues through closure.
  • Support evidence collection for security assessments, audits, and internal control reviews.
  • Work with relevant stakeholders to align application security practices with GDPR obligations, organisational policies, and applicable industry standards.
  • Review security implications of changes to authentication systems, payment integrations, customer data flows, and external APIs.
  • Contribute to incident investigations involving suspected application vulnerabilities or software exploitation.

Candidate Profile

  • Degree in computer science, software engineering, cybersecurity, or equivalent professional experience.
  • Experience in application security, penetration testing, secure software development, or product security engineering.
  • Strong understanding of web application architecture, HTTP, REST APIs, authentication, authorisation, and session security.
  • Familiarity with the OWASP Top 10 and OWASP API Security Top 10.
  • Practical experience with tools such as Burp Suite, OWASP ZAP, Semgrep, Snyk, or comparable security testing platforms.
  • Ability to read and assess application code in languages such as Java, Python, JavaScript/TypeScript, Go, or C#.
  • Understanding of SQL and NoSQL databases, cloud application security, encryption, and secrets management.
  • Strong technical writing skills and the ability to communicate vulnerabilities to both technical and non-technical stakeholders.

Additional Advantages

Relevant certifications such as CSSLP, GWAPT, OSCP, or comparable application security credentials are welcome but not mandatory. Experience with digital banking, payment gateways, financial APIs, identity verification, or other sensitive-data platforms would be advantageous.

Why This Role Matters

Application vulnerabilities can expose customer records, disrupt transactions, undermine platform availability, and create significant operational and regulatory risks. This role will help reduce those risks by strengthening software quality at the design and development stages.

You will have the opportunity to influence engineering practices, improve the security of digital products, and help establish a consistent approach to application risk management across the development lifecycle.

Ideal Candidate: A detail-oriented security engineer with a developer’s understanding of software systems, an investigator’s approach to vulnerability analysis, and the communication skills required to turn technical findings into effective remediation.

Are you interested in this position?

Apply by clicking on the “Apply Now” Button below!

#JobsHubEstonia #GlobalRecrument
#CareerOpportunities #HiringNow
#JobSeekersNetwork #EstoniaJobs
#RecruitmentServices #EmploymentPortal.