
Application Security Specialist
Posted 13 hours ago

Posted 13 hours ago
This is a fully remote position, open to applicants in Colombia.
• Act as the security partner for Product, maintaining a comprehensive view of applications, components, data, dependencies, attack surfaces, and prioritized risks.
• Integrate security from the design phase through threat modeling, architecture reviews, and abuse scenarios for functionalities, APIs, payment flows, and high-risk changes.
• Design, implement, and operate AI-assisted AppSec capabilities to review changes, prioritize findings, generate tests, and suggest corrections with business context.
• Continuously assess the accuracy, coverage, latency, cost, and security of AI-assisted AppSec capabilities.
• Define guardrails for assistants and development agents, including approved tools and models, code and data handling, secret protection, permissions, execution isolation, and traceability.
• Extend the secure SDLC to both formal and informal development, including vibe coding, prototypes, scripts, automations, and internal tools.
• Integrate and fine-tune controls such as SAST, SCA, secret detection, IaC and container security, DAST, API testing, and manual analysis.
• Apply gates based on risk to provide useful signals without turning Security into a bottleneck.
• Conduct code reviews and security assessments on authentication, authorization, business logic, transactional integrity, data handling, integrations, and cloud configurations.
• Strengthen the software supply chain through component inventory, dependency controls, versioning, provenance, artifacts, and fixes.
• Define and maintain secure standards and patterns based on OWASP ASVS, OWASP Top 10, OWASP API Security, OWASP GenAI, NIST SSDF, and PCI DSS.
• Collaborate with Offensive Security and squads to validate exploitability, prioritize risk, agree on remediation plans, and verify closure of findings.
• Drive the Security Champions program and create guides, hands-on labs, or other means to adopt best practices.
• Measure coverage, risk, remediation time, recurrence, signal quality, and process friction.
• Communicate trends, decisions, and investment needs.
• Participate in incidents related to applications or AI-generated software and convert learnings into new controls.
• Over 4 years of experience in Application Security, Product Security, secure code review, or software development focused on security.
• Hands-on experience building or operating AI or LLM automations for code analysis, testing, triage, or remediation.
• Mastery of application and API vulnerabilities, including authorization, authentication, business logic, injections, SSRF, secret management, data integrity, and configuration failures.
• Experience applying threat modeling, architecture reviews, secure code review, and vulnerability management from discovery to verified correction.
• Experience integrating and fine-tuning SAST, SCA, secret detection, IaC or container analysis, DAST, and API testing in CI/CD.
• Ability to program and automate in at least one relevant production language, such as Python, Java, Go, JavaScript, TypeScript, Ruby, or Kotlin.
• Practical knowledge of AI-assisted development and risks such as prompt injection, excessive permission usage, secret or code exposure, nonexistent or malicious dependencies, untrusted instructions, and unvalidated agent actions.
• Experience with cloud architectures, preferably AWS, CI/CD, APIs, microservices, containers, serverless, and infrastructure as code.
• Critical thinking to differentiate exploitability and real risk from noise and choose proportional controls.
• Clear communication, ability to influence without formal authority, and capacity to build agreements with Engineering, Product, Platform, Data, AI, Offensive Security, and other areas.
• A plus: experience in fintech, payments, digital banking, or systems that process sensitive data and transactions.
• A plus: knowledge of PCI DSS 4.0.1, OWASP ASVS 5.0, OWASP AISVS, OWASP Top 10 for Agentic Applications, NIST SSDF, or equivalent frameworks.
• A plus: experience securing agents, applications with LLM, MCP integrations, or machine learning pipelines.
• A plus: experience with Security Champions programs, bug bounty initiatives, pentesting, or developing reusable secure patterns.
• A plus: advanced English proficiency.
• A plus: certifications such as OSWE, GWEB, CSSLP, AWS Certified Security, or equivalents.
• Permanent employment contract.
• Full-time remote work.
• Health insurance coverage.
• Company shares from an early-stage venture with high return potential.
• Competitive salary.
• Financial support for education.
• World-class technologies and processes.
• Additional days off beyond vacation.
• Visual health bonus.
• Emotional wellness support.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.