
Applications Security Specialist
Posted Jul 25

Posted Jul 25
This is a fully remote position, open to applicants in Argentina.
• Perform secure code assessments for Go-based microservices, identifying vulnerabilities early in the development process.
• Execute security testing on APIs, web applications, and backend services prior to their deployment in production.
• Develop and enhance secure coding standards, guidelines, and reusable practices for engineering teams.
• Facilitate threat modeling sessions with engineering and product teams during the design phase of new features and services.
• Define and implement security gates within CI/CD pipelines, including SAST, DAST, SCA, and secrets scanning, with criteria for blocking high-severity issues.
• Oversee the entire DAST process: selecting tools, scheduling, managing escalation workflows, and tracking remediation efforts.
• Integrate container image scanning and infrastructure-as-code (IaC) security checks into deployment processes.
• Support hardening efforts across Kubernetes, ingress, and workloads.
• Contribute to the security observability initiative by defining and refining alerting rules for authentication anomalies and suspicious API activity.
• Promote secure development practices across engineering teams through guidance, training, and hands-on assistance.
• Develop and maintain security documentation, runbooks, and standards.
• Assess, prioritize, and monitor the remediation of security issues across the platform.
• Coordinate external penetration testing efforts and collaborate with vendors on scope, debriefings, and remediation strategies.
• Collaborate with product and business teams to understand risks from a product perspective.
• Ensure no high-severity findings remain unresolved for more than 30 days.
• 3–5 years of experience in application security, product security, or a related field.
• Practical experience with SAST/DAST tools (such as Snyk, Checkmarx, OWASP ZAP, Burp Suite, or similar).
• In-depth knowledge of the OWASP Top 10 for web and APIs, along with real-world exploitability assessments.
• Experience reviewing code in Go or comparable compiled languages.
• Familiarity with Kubernetes, containers, and cloud-native architectures.
• Excellent written and verbal communication skills, capable of articulating security risks to both technical and non-technical stakeholders.
• Self-motivated and comfortable working independently in a fast-paced setting.
• Proficiency in English, both written and spoken (required).
• Nice to have:
• Certifications such as OSCP, OSWE, CEH, or eWPT.
• Experience with Istio or service mesh security.
• Familiarity with compliance frameworks like ISO 27001, GDPR, or SOC 2.
• Experience in threat modeling (using STRIDE, PASTA, or similar methodologies).
• Background in fintech or regulated industries.
• Opportunity to join a high-impact, mission-focused fintech organization with a regional footprint.
• Collaboration with exceptional teams across Latin America.
• Equipment provided by R2.
• Training budget allocated for professional development.
• Career advancement opportunities within R2.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.