Senior Application Security Engineer

Summary

Senior Application Security Engineer embeds secure-by-design practices into cloud infrastructure and microservices, automating threat modeling and supply chain security while guiding engineering teams in a high-scale AWS environment.

About the Role

Are you a cybersecurity champion who thrives on embedding "secure by design" principles into cutting-edge cloud infrastructure and microservices? We are looking for a Senior Application Security Engineer to act as a trusted advisor, driving the evolution of secure product engineering from legacy data centers to AWS. If you want to own threat modeling automation, champion supply chain security, and influence engineering roadmaps in a high-scale environment, this is your next big move.

About the Client

Our partner is a tech company building product engineering across Fintech, iGaming, and Marketing. They turn innovative ideas into high-performing engines and launch them at scale. As their exclusive recruitment partner, Lionhires manages their full-cycle talent acquisition, connecting top-tier tech talent with this fast-growing ecosystem.

What You Will Do

  • Design and implement robust security architecture spanning from cloud infrastructure down to the application layer, ensuring "secure by design" principles are met.

  • Collaborate closely with product managers, architects, and developers to build and scale the security controls platform ecosystem.

  • Validate and proof security implementations within infrastructure, application deployment manifests, and automated CI/CD pipelines.

  • Define critical policies, controls, and capabilities to protect global products and environments.

  • Build and automate declarative threat modeling to proactively identify and mitigate application risks.

  • Oversee the product security strategy for migrating legacy data center workloads to the public cloud (AWS).

  • Serve as a trusted cybersecurity advisor to engineering and product teams, participating actively in planning cycles and technical committees.

What You Bring

  • Microservices Security: Proven experience analyzing and securing applications developed using JavaScript and TypeScript.

  • DevSecOps Core: Hands-on experience integrating security scanning/tooling into CI/CD pipelines (GitLab, Jenkins) and utilizing Infrastructure-as-Code models (Terraform, Helm, or CloudFormation).

  • Scripting Skills: Strong development experience in Python and Shell scripting.

  • Modern Infrastructure: Deep familiarity with Docker and service mesh technologies (such as ISTIO).

  • Security Assessments: Strong background in architecture/security reviews, threat modeling, and application risk mitigation within an Agile framework.

  • Software Integrity: A rock-solid understanding of supply chain security, software integrity, and secure software delivery.

  • Compliance & Privacy: Familiarity with industry regulations and frameworks (PCI-DSS, ISO 27001, NIST) and privacy laws like GDPR.

  • Bonus Points: In-depth experience architecting secure services on Kubernetes/AWS and holding industry certifications (e.g., CISSP, CISM, CCSK, CCSP, CEH).

What's in It for You

  • Career Growth: Limitless opportunities to advance in an international, highly dynamic tech environment.

  • Health & Wellness: Comprehensive medical insurance for you and your partner, plus a dedicated sports package to support a healthy lifestyle.

  • Work-Life Balance: 20 working days of paid annual vacation and 6 paid sick leaves.

  • Continuous Learning: Partial compensation for language courses to help you level up your skills.

  • Celebrations & Perks: Special gifts for life milestones (birthdays, weddings, newborns) alongside fully stocked office snacks and refreshments.

  • Premium Workspace: A modern, comfortable office with top-tier facilities in a prime location.

  • Vibrant Culture: Exciting corporate events, team-building activities, and unforgettable international company parties.