Senior Application Security Engineer
Remote in Argentina, & 4 others
Security.Cloud& 9 others
Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobChoose an option
We are seeking a Senior Application Security Engineer to own and drive application security vulnerability remediation programs, with an initial focus on HackerOne bug bounty findings, API security vulnerabilities, GraphQL authorization issues, and cross-functional remediation tracking. This role serves as the operational owner of the vulnerability remediation lifecycle, coordinating across Cybersecurity, Engineering, Product, and external vendors to ensure timely identification, validation, assignment, remediation, and closure of security findings.
Responsibilities
- Own day-to-day management of the HackerOne program
- Manage vulnerability intake, triage, validation, routing, tracking, and closure
- Coordinate weekly operating reviews with HackerOne and internal stakeholders
- Track remediation commitments and drive accountability
- Manage disclosure and communication processes
- Reproduce and validate reported vulnerabilities, assessing exploitability and business impact
- Utilize Postman, browser tooling, and security testing tools to validate findings
- Support vulnerability prioritization based on customer and business risk
- Coordinate remediation efforts across multiple engineering organizations
- Identify service ownership and route findings appropriately, maintaining Jira and ServiceNow tracking
- Escalate critical and overdue items
- Produce executive-level reporting and dashboards, tracking backlog trends, SLA compliance, remediation progress, and risk reduction
- Present status updates to cybersecurity and engineering leadership
- Leverage GenAI and workflow automation to improve triage, remediation tracking, reporting, and service ownership identification
Requirements
- 3+ years of experience in Software Engineering or Application Security
- Understanding of REST APIs, GraphQL, and Authentication & Authorization mechanisms
- Knowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10
- Experience reproducing security findings
- Proficiency in Postman
- Experience with Jira and ServiceNow
- Strong stakeholder management skills
- English proficiency at B2 level or higher
Nice to have
- Background in HackerOne or Bug Bounty programs
- Experience in AppSec and penetration testing
- Full-stack software development background
- Familiarity with Burp Suite
- Experience with GenAI automation
