Skip To Main Content
backBack to Search

Lead Application Security Engineer

Remote in Argentina, & 4 others
Security.Cloud& 9 others
Looking for something else?

Find a vacancy that works for you. Send us your CV to receive a personalized offer.

Find me a job

We are looking for a Lead Application Security Engineer to lead application vulnerability remediation across teams, starting with HackerOne findings and API and GraphQL issues. You will own the end-to-end workflow from intake and validation to remediation tracking and closure across Cybersecurity, Engineering, Product, and vendors.

Responsibilities
  • Own the daily operational execution of the HackerOne program
  • Run vulnerability intake, triage, validation, assignment, tracking, and closure end to end
  • Lead weekly operating reviews with HackerOne and internal stakeholders
  • Track remediation commitments and reinforce accountability for delivery
  • Manage coordinated disclosure and related communications
  • Reproduce and validate reported vulnerabilities, evaluating exploitability and business impact
  • Use Postman, browser tooling, and security testing tools to verify findings
  • Support vulnerability prioritization based on customer and business risk
  • Coordinate remediation work across multiple engineering organizations
  • Identify service ownership and route findings correctly while maintaining Jira and ServiceNow tracking
  • Escalate critical items and drive resolution for overdue work
  • Deliver executive-ready reporting and dashboards on backlog trends, SLA compliance, remediation progress, and risk reduction
  • Present status and outcomes to cybersecurity and engineering leadership
  • Leverage GenAI and workflow automation to enhance triage, remediation tracking, reporting, and service ownership identification
Requirements
  • Proven background with 5+ years of experience in Software Engineering or Application Security
  • Solid understanding of REST APIs, GraphQL, and Authentication & Authorization mechanisms
  • Working knowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10
  • Hands-on experience reproducing security findings
  • Proficiency with Postman
  • Practical experience using Jira and ServiceNow for tracking and workflow
  • Strong stakeholder management skills across technical and non-technical teams
  • English proficiency at B2 (Upper-Intermediate) level or higher
Nice to have
  • Experience with HackerOne or other Bug Bounty programs
  • Background in AppSec and penetration testing
  • Full-stack software development experience
  • Familiarity with Burp Suite
  • Experience building or using GenAI automation