Lead Application Security Engineer
Remote in Argentina, & 4 others
Security.Cloud& 9 others
Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobChoose an option
We are looking for a Lead Application Security Engineer to lead application vulnerability remediation across teams, starting with HackerOne findings and API and GraphQL issues. You will own the end-to-end workflow from intake and validation to remediation tracking and closure across Cybersecurity, Engineering, Product, and vendors.
Responsibilities
- Own the daily operational execution of the HackerOne program
- Run vulnerability intake, triage, validation, assignment, tracking, and closure end to end
- Lead weekly operating reviews with HackerOne and internal stakeholders
- Track remediation commitments and reinforce accountability for delivery
- Manage coordinated disclosure and related communications
- Reproduce and validate reported vulnerabilities, evaluating exploitability and business impact
- Use Postman, browser tooling, and security testing tools to verify findings
- Support vulnerability prioritization based on customer and business risk
- Coordinate remediation work across multiple engineering organizations
- Identify service ownership and route findings correctly while maintaining Jira and ServiceNow tracking
- Escalate critical items and drive resolution for overdue work
- Deliver executive-ready reporting and dashboards on backlog trends, SLA compliance, remediation progress, and risk reduction
- Present status and outcomes to cybersecurity and engineering leadership
- Leverage GenAI and workflow automation to enhance triage, remediation tracking, reporting, and service ownership identification
Requirements
- Proven background with 5+ years of experience in Software Engineering or Application Security
- Solid understanding of REST APIs, GraphQL, and Authentication & Authorization mechanisms
- Working knowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10
- Hands-on experience reproducing security findings
- Proficiency with Postman
- Practical experience using Jira and ServiceNow for tracking and workflow
- Strong stakeholder management skills across technical and non-technical teams
- English proficiency at B2 (Upper-Intermediate) level or higher
Nice to have
- Experience with HackerOne or other Bug Bounty programs
- Background in AppSec and penetration testing
- Full-stack software development experience
- Familiarity with Burp Suite
- Experience building or using GenAI automation
