Application Security Engineer - Senior
Plata CardWe are looking for an Application Security Engineer to join our Information Security team. The Information Security team is responsible for protecting Plata’s products, systems, and data by embedding security throughout the technology lifecycle. We work closely with engineering teams to identify and mitigate security risks, strengthen application defenses, and ensure security is integrated into every stage of software development. As an Application Security Engineer , you will serve as a key link between development and security teams, designing, implementing, and maintaining robust application security controls. You’ll help embed security across the entire software development lifecycle — from design and development to testing and deployment — while continuously improving our application security practices. Challenges that await you: Collaborate with Dev & Ops teams. Guide secure coding practices, participate in code reviews, and embed security seamlessly into the SDLC Conduct security reviews & threat modeling. Analyze application architecture, define threat models, and drive proactive risk identification Integrate security tools. Deploy and manage SAST, DAST, IAST, RASP, and SCA tools within CI/CD pipelines to automate early detection and remediation Handle security incidents Implement “shifting left” strategies, enforce continuous testing, fast remediation, and embed security culture across teams Educate and train. Conduct workshops to elevate developer security awareness and promote adherence to OWASP, ASVS, and secure design standards What makes you a great fit: Proficient in programming languages (web/mobile) Strong understanding of web architectures (microservices) Deep knowledge of OWASP Top 10, threat modeling, and security testing frameworks Familiarity with security tools such as ZAP, Dependency-Track, Burp Strong analytical skills with precise and thorough attention to detail Your bonus skills: Security certifications (OSCP, OSWE, GWAPT, GCPN) Contributions to or experience with bug bounty or ethical-hacking programs SaaS or cloud-native environments experience Familiarity with Kubernetes or container security Our ways of working: Innovative Spirit: A commitment to creativity and groundbreaking solutions Honest Feedback: valuing open, transparent communication Supportive Team: a strong, collaborative community Celebrating Achievements: recognizing our wins together High-Tech Environment : a team full of smart and revolutionary people who date to challenge the status quo of incumbent finances Our benefits: Relocation support to Kazahstan, Cyprus, Serbia or Spain with full visa & permit support to the employee and family Flexible work from one of our offices or remote Healthcare Coverage Education Budget: Language lessons, professional training and certifications Wellness Budget: Mental health and fitness activity reimbursements Vacation policy: 20 days of annual leave and paid sick leave