Senior Application Security Engineer

Unlimit · Fintech

Job description

Position:
Senior Application Security Engineer

Company:
Unlimit

Location:
(Country, city) Belgrade

Employment type:
Full-Time

Work Arrangement:
On-site

Short Summary:
As a Senior Application Security Engineer, you’ll be a hands-on technical expert responsible for improving the security of Unlimit’s applications, APIs, and development processes.

Responsibilities:
- Drive secure software development practices across the organisation.
- Perform application security assessments, secure design reviews, and threat modelling for new and existing products.
- Conduct manual source code reviews for business-critical applications and support remediation of complex security issues.
- Integrate and optimise security testing throughout the SDLC, including SAST, DAST, Software Composition Analysis (SCA), API security testing, and Infrastructure as Code (IaC) security.
- Build and improve automated application security workflows within GitLab CI/CD pipelines.
- Own and continuously improve Application Security Posture Management (ASPM) capabilities.
- Partner closely with software engineering teams to identify vulnerabilities early and implement practical, scalable security controls.
- Support penetration testing activities by coordinating external assessments, validating findings, and driving remediation.
- Contribute to the development of internal AI-powered and agentic application security workflows, including automated security reviews, code analysis, and vulnerability triage.
- Research emerging attack techniques and translate them into practical improvements across secure development and security testing.
- Develop security guidance, reusable patterns, and engineering standards that enable developers to build secure software at scale.

Requirement:
- 5+ years of experience in Application Security, Software Security, DevSecOps, or Software Engineering with a strong security focus.
- Previous experience in fintech is preferred; experience in cryptocurrency is a strong plus.
- Strong software development background with hands-on experience across modern application architectures.
- Experience performing threat modelling, secure design reviews, and manual code reviews.
- Strong understanding of Secure SDLC principles and practical application security engineering.
- Experience implementing and maintaining automated security testing within CI/CD pipelines.
- Hands-on experience with SAST, DAST, SCA, API security testing, ASPM, and modern application security tooling.
- Practical understanding of modern attack techniques, exploitation methods, and secure coding practices.
- Experience collaborating directly with engineering teams to remediate vulnerabilities and improve application resilience.
- Strong scripting or programming skills in one or more of the following: Java, Go, Python, Node.js, PHP, or Dart (Flutter).
- Experience working with GitLab-based development workflows.
- A pragmatic, engineering-first mindset with a passion for automation and AI-assisted security.

Benefits:
- Unlimit is an equal opportunity employer. We believe passionately that employing a diverse workforce is central to our success.
- We welcome applications from all members of society irrespective of age, sex, disability, sexual orientation, race, religion or belief.

Skills

  • ci/cd
  • dart
  • dast
  • devsecops
  • golang
  • java
  • node_js
  • php
  • python
  • sast

Languages

EN

Apply

Open this job in our interactive board to apply, save it, or sign up for matched alerts on similar roles.

View & apply
Senior Application Security Engineer — Unlimit | RVC