Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
Reap logo

Security Engineer, Application Security

Reap
Posted 5 hours ago
🌍Hong Kong, Singapore🏢Hybrid📁Engineering & Development
Is this job info correct?

Security Engineer, Application Security Join Reap as an Application Security Engineer — embed security in development, lead threat modelling, and build tools that protect global payments before vulnerabilities ship. About Reap Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement. With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments. Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia. Founded in 2018 Security at Reap Reap builds financial connectivity for a multi‑rail world-traditional finance, stablecoins, and real‑time payments. Security is foundational to that mission. We're looking for a pragmatic engineer who can turn regulation into robust systems, and complex threats into clear controls. You'll partner with Engineering, Risk, and Operations to keep value moving safely, globally, and 24/7. Your Mission During our acquisition by Payward/Kraken, their due diligence team found a race condition vulnerability in our product. We found it second. That is not the position we want to be in going forward. As our Application Security Engineer, you will embed security inside the engineering process rather than bolting it on afterwards. You will own our secure SDLC, build the tooling that catches vulnerabilities in the pipeline before they ship, run threat modelling sessions with our engineering squads, and manage our bug bounty programme. This is a builder role that works inside the engineering team, not above it. What You Will Do • Build and own the application security programme: secure coding standards, developer security training, security review gates in the engineering workflow, and the SAST/DAST/SCA tooling that enforces them in CI/CD. • Lead threat modelling for new product features, API integrations, and significant architectural changes. Run STRIDE-based sessions with engineering squads who have not done this before. • Do security-focused code reviews for the areas that matter: authentication, authorisation, payment flows, cryptographic operations, and external API integrations. • Own our dependency and open source software security: scan, assess, and enforce our OSS usage policy. • Run developer security education: OWASP Top 10, OWASP API Top 10, a security champions network, and practical sessions that engineers actually find useful. • Manage penetration testing engagements end-to-end: scope, vendor, findings, and remediation verification. • Own our responsible disclosure policy and manage our bug bounty programme once it launches. Your Superpowers • You have improved an application security programme inside an engineering organisation. You know what the before and after looks like, and how to get engineering buy-in for both. • Hands-on SAST/DAST/SCA pipeline experience. Semgrep, CodeQL, Checkmarx, SonarQube, or equivalent. You have configured these in CI/CD, not just run them on demand. • You can do threat modelling with engineers who have never done it. STRIDE or PASTA. You facilitate, not lecture. • Secure code review in at least two languages. JavaScript/TypeScript, Python, Go, or Rust. You can read code and find the vulnerability, not just run a scanner. • Application penetration testing fundamentals. OWASP Top 10 and API Top 10 in practice. You know how authentication and authorisation get broken. • PCI DSS secure coding requirements. We handle payment card data. You know what that means for development. Nice to Have • CSSLP, GWEB, or OSCP certification. • Crypto or DeFi application security experience. • Bug bounty programme management experience. • Experience with smart contract interaction security or exchange API security. Why You Will Love It Here • You are building the application security function at a fast-moving fintech from scratch, with direct access to engineering leadership. • The race condition finding gave us a very specific brief: find things like that before the acquirer does. You will have a clear mandate. • We use AI tools extensively. GitHub Copilot, Claude Code, and others are part of how we build. You will help make sure we build securely with them. • Flexible remote work, global team, and a company that is growing fast. Benefits you'll enjoy A vibrant, inclusive work culture. Annual leave to relax and recharge, plus public holidays. Health insurance budget. Be part of a fast‑growing global team. Flexible remote work options. Home office equipment budget. Your own Corporate Reap Card-no more out‑of‑pocket spending. About Reap Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement. With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments. Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia. Founded in 2018 Coworkers 300+ Department IT & Security Locations Hong Kong, Singapore Remote status Hybrid About Reap Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement. With stablecoin-enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross-border payments. Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.

Similar jobs

Similar jobs

InnoEdge Labs Pte. Ltd. logo

Application Security Researcher (Senior/ Lead/ Principal)

InnoEdge Labs Pte. Ltd.

🇸🇬SingaporeMay 28, 2026, 7:13 AM UTC
Binance logo

Pioneer Talent Program - AI-powered Productivity Platform Engineer

Binance

🌍Hong Kong, Taiwan3 hours ago
Reap logo

Security Engineer, Detection and Security Operations

Reap

🌍Hong Kong, Singapore5 hours ago
Reap logo

Data Access Control Analyst

Reap

🌍Hong Kong, Singapore5 hours ago
1 Stopasia logo

Hong Kong native, Telephone testing

1 Stopasia

🇭🇰Hong Kong13 hours ago
Comm It logo

Tier-2 IT Support Engineer

Comm It

🇸🇬Singapore15 hours ago