Über die Stelle
The role focuses on strengthening application security across the software development lifecycle, product features, mobile applications, APIs, and supply-chain risks. It combines hands-on technical security work with ownership of security processes.
About the company
Salmon is an international technology-driven financial company.
Work format
- Remote work
- Candidates from Belarus and Russia are not eligible
What makes you a strong fit
- 7+ years of experience in application security with meaningful ownership of technical work and processes
- Experience building or substantially improving a secure SDLC in a fast-moving product organization
- Experience conducting threat modeling for real product features and influencing design decisions based on the results
- End-to-end ownership of vulnerability management, including triage, remediation tracking, SLA management, and risk acceptance
- Hands-on mobile security testing experience with iOS and/or Android in a production context, not only UAT
- Understanding of modern supply-chain attack vectors, including compromised npm and PyPI packages, malicious IDE plugins, typosquatting, and dependency confusion
- Ability to reduce supply-chain exposure through tooling and processes
- Ability to write Python or Bash scripts to automate repetitive security work
Technical skills
- SAST, DAST, and SCA in CI/CD pipelines, with the ability to tune for signal rather than just coverage
- API security, including authentication flows, token handling, and common abuse patterns
- Mobile security with practical application of OWASP ASVS and MASVS
- Supply-chain security, including SBOM generation and dependency risk management
- Secrets management, including detection, remediation, and structural prevention
How to apply
Send your application and resume via Telegram to @Lera_Mes.