Himalayas logo
Palermo AdvisorsPA

Senior Application Security Engineer for a leading Series B Fintech

Palermo Advisors is a global talent advisory and headhunting firm that simplifies borderless hiring by connecting companies with world-class talent.

Palermo Advisors

Employee count: 11-50

Portugal only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Our client is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. They’ve raised nearly $400M in funding—including the largest Series A in fintech history—and just closed a successful Series B to fuel their next stage of hypergrowth.

We are seeking a skilled and driven Senior Application Security Engineer to join a growing European team. The company has members in UK, Portugal, Spain, the Netherlands, among other European countries. This role demands a proactive approach to secure software development and cloud-native defense. You will partner closely with engineering and development squads, and work alongside their Cloud Security and GRC team members to improve application and platform security posture.

This position is technically grounded, requiring direct engagement in application-layer matters and security reviews, while also contributing to cloud security automation, awareness initiatives, and secure engineering practices across the SDLC.

Key Responsibilities:

  • Collaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.
  • Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.
  • Design, implement, and oversee automated processes for securely updating application and code dependencies, proactively mitigating issues and ensuring timely vulnerability remediation.
  • Integrate security checks into CI/CD pipelines (SAST, DAST, SCA, IaC), working with tools like Semgrep, Snyk, Trivy, and Burp Suite.
  • Contribute to runtime security initiatives, such as container/Kubernetes hardening, RASP, and eBPF-based detection.
  • Build and maintain a security issues dashboard to track remediation status and metrics.
  • Provide real-time support in the event of cybersecurity incidents impacting applications or cloud infrastructure (exploited vuln, credential stuffing, web/API attacks).
  • Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub remediation automations, DLP monitoring, etc.).
  • Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to the architecture.
  • Collaborate with the GRC team to develop and deliver internal security awareness initiatives, phishing campaigns, and developer training (e.g., secure coding, API security).
  • Participate in the continuous improvement of AppSec maturity (e.g., aligning with OWASP SAMM, ISO 27001, or SOC 2 frameworks).

Required Qualifications:

  • Fluent English, including strong verbal and written skills.
  • Strong problem-solving and analytical mindset.
  • Excellent communication skills to convey security risks to technical and non-technical stakeholders.
  • 3–5+ years of experience in application security, penetration testing roles, and/or secure code development, including work with QA teams.
  • Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).
  • Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).
  • Proven expertise in performing code review or security assessments and writing clear reports.
  • Proficiency in at least one backend language (e.g., Go, Python, Node.js) and understanding of React / React Native front-ends.
  • Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2/OpenID Connect.
  • Experience securing CI/CD pipelines and integrating AppSec tooling into SDLC.
  • Solid knowledge of containerization and Kubernetes security fundamentals.
  • Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.
  • Comfortable with Agile development methodologies and working within cross-functional squads.
  • Software supply chain security (e.g., SBOM, artifact signing).

Preferred Qualifications:

  • Certifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.
  • AWS, GCP, or Azure Security Specialty certification.
  • Familiarity with bug bounty triage and vulnerability management platforms (e.g., DefectDojo).
  • Experience implementing RASP or eBPF runtime protection tools.
  • Exposure to LLM/AI security considerations and secure code generation practices.
  • Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior

Location requirements

Hiring timezones

Portugal +/- 0 hours

About Palermo Advisors

Learn more about Palermo Advisors and their company culture.

View company profile

At Palermo Advisors, we are at the forefront of revolutionizing talent acquisition through innovative and technology-driven solutions. Our firm is dedicated to simplifying the complexities of borderless hiring, connecting forward-thinking companies with exceptional, world-class talent from across the globe. We leverage a vast, meticulously cultivated network of professionals and deploy customized talent acquisition strategies that are designed to meet the unique and evolving needs of our clients. Whether an early-stage startup navigating the critical initial hires or a large, established corporation expanding into new territories or building out remote teams, our approach is engineered for precision and success. Our methodology is a departure from traditional recruitment, focusing on a proactive, targeted search to identify and engage the best candidates, many of whom are not actively seeking new opportunities. This ensures our clients are not just filling positions, but are building winning teams that drive innovation and long-term success.

Our commitment to technological advancement is matched by our dedication to providing unparalleled service and expertise. The leadership team at Palermo Advisors is comprised of seasoned experts with deep experience in innovation, finance, and global talent acquisition. This unique blend of skills allows us to offer more than just recruitment services; we act as strategic advisors to our clients, offering insights into market trends, talent landscapes, and effective team-building strategies. We have a proven track record, with over 1,500 successful placements, a testament to our ability to consistently match exceptional talent with the specific needs and cultures of our client organizations. By integrating advanced data security measures and a client-centric, conversational approach, we have streamlined the hiring process, making it faster, more efficient, and ultimately more effective. At Palermo Advisors, we are not just recruiters; we are architects of high-performing teams, dedicated to helping our clients achieve their most ambitious goals through the power of exceptional talent.

Employee benefits

Learn about the employee benefits and perks provided at Palermo Advisors.

View benefits

401k

We provide a 401k plan.

Life Insurance

We provide life insurance.

Dental Insurance

We provide dental benefits.

Healthcare Benefits

We provide full healthcare benefits.

View Palermo Advisors's employee benefits
Claim this profilePalermo Advisors logoPA

Palermo Advisors

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

3 remote jobs at Palermo Advisors

Explore the variety of open remote roles at Palermo Advisors, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Palermo Advisors

Remote companies like Palermo Advisors

Find your next opportunity by exploring profiles of companies that are similar to Palermo Advisors. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan