Skip to content

Open nowPosted 15 days ago

Application Security Engineer

transak-inc13 open roles

Where
Austria
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowApplication Security Engineertransak-inc · Austria
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on transak-inc's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.0%30 days
This job: posted 15 days ago

The posting

About the company:

Our mission is that "Any financial application can onboard any user, anywhere in the world, in 1 click." Transak provides onboarding to financial applications through authentication, KYC, risk checks, and fiat on/off ramps. This is a next generation of infrastructure for the next generation of financial applications that are built on blockchain and stablecoin rails. Our API and widget-based solutions are used by top partners like MetaMask, Coinbase, Ledger, and Trust Wallet to enable seamless onboarding of over 10 million users across over 450 active applications.

We have raised over $37M from top-tier investors including Consensys, Tether, and Animoca Brands.

About the Role:

Transak's product is its attack surface: a widget, a set of APIs and the flows that move customer funds and customer identity data, built on a Node.js and Python stack.

This is a founding role in a small security function, reporting to the CISO. You will own application and product security end to end and build the capability rather than operate an existing one - there is no established programme to inherit and no team to delegate to. Transak operates under MiCA and DORA in the EU with further regulated entities in MENA and the US, so what you build needs to be evidenced as well as effective.

What You'll Be Doing

As Transak's first dedicated application security hire, you will safeguard our applications and development lifecycle through proactive security integration and engineering excellence. Your responsibilities include:

  • Partner with engineering teams to embed security into the software development lifecycle, from design through to deployment.
  • Conduct security code reviews, threat modelling sessions and architecture reviews for the flows that move customer funds and customer identity data.
  • Select, implement and tune SAST, DAST and SCA solutions to identify vulnerabilities early in the development process.
  • Build and maintain application security testing automation within CI/CD pipelines, with severity-based gating that engineering can plan around.
  • Own the software supply chain: an SBOM per deployable service, dependency and provenance standards, and approved base images.
  • Build and run a consolidated vulnerability register - triage, prioritise by real exploitability, assign owners and drive remediation to verified closure.
  • Perform penetration testing and vulnerability assessments of web applications, APIs and mobile applications.
  • Own the external penetration testing programme, scoping engagements from the threat model and enforcing re-testing.
  • Develop secure coding standards, reusable security components and role-based training for engineering teams.
  • Create a security champions programme so that security scales beyond one person.
  • Run the bug bounty programme and coordinate with external security researchers.
  • Research emerging application and supply chain threats, and integrate defensive measures into the security architecture.
  • Evidence secure development and vulnerability management controls for DORA, MiCA, SOC 2 and ISO 27001.

What We're Looking For

Core Experience:

  • 5+ years as a security engineer, focused on application or product security.
  • Deep understanding of web and API security - OWASP Top 10, authentication and authorisation, session management.
  • Hands-on experience with security testing tools such as Burp Suite, OWASP ZAP, Snyk, Aikido etc.
  • Strong programming skills in a modern language, ideally JavaScript / Node.js or Python.
  • Experience integrating security tooling into CI/CD pipelines such as GitLab CI, Jenkins or GitHub Actions.
  • Practical software composition analysis and SBOM experience, with an understanding of modern supply chain attacks against npm and PyPI.
  • Vulnerability management ownership: a register, named owners, enforced SLAs and reported adherence.
  • Threat modelling applied to real business flows, and secure architecture patterns for APIs and distributed systems.
  • Solid understanding of cryptography, secrets management and identity and access management.
  • Excellent communication skills, able to translate security concepts for an engineering audience.
  • Comfortable building a capability from nothing rather than inheriting a mature programme.

Bonus:

  • Hands-on security testing of cryptocurrency or blockchain infrastructure and applications is a major bonus.
  • Fintech, payments or custody experience, particularly anything touching wallets or settlement.
  • Supply chain security depth: SBOM formats, build provenance, SLSA, and prioritisation using EPSS and the CISA KEV catalogue.
  • Knowledge of compliance frameworks such as DORA, MiCA, SOC 2, ISO 27001 or GDPR.
  • Managing an external penetration testing vendor or a bug bounty programme.
  • Certifications such as OSCP, OSWE, GWAPT or CSSLP.

Why join us

  • Equity options so you can share in the success of the company
  • A fast-moving, fun, and international company made up of skillful team players
  • Transparent, Open, and Collaborative work environment
  • A competitive compensation package and comprehensive benefits offering
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against transak-inc's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on transak-inc's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    transak-inc's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.