Senior Application Security Engineer
Colibrix One
| Company | Colibrix One |
| Category | Engineering |
| Location | Limassol |
| Remote | Hybrid |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 4 Aug 2026 |
| Last verified | 4 Aug 2026 |
| Source | Employer ATS (workable) |
Description
Join COLIBRIX ONE – Innovating the Future of Payments At COLIBRIX ONE* , we’re building advanced, AI-powered payment technologies that support Payment Service Providers (PSPs), Electronic Money Institutions (EMIs), and neobanks across the EU and the UK. As a fully licensed Electronic Money Institution (FCA Reference No. 927920) and holder of a Financial Institution Licence issued by the MFSA, as well as a principal member of both VISA and Mastercard, we provide comprehensive, real-world financial solutions that include: Global card processing Digital wallet infrastructure Cross-border merchant accounts Alternative payment methods (APMs) Corporate accounts for legal entities We’re a fast-growing team with a passion for innovation, security, and scalability. Our culture values curiosity, collaboration, and impact - and we’re looking for talented professionals who are ready to shape the future of fintech. At COLIBRIX ONE, your work directly powers the digital economy. If you're eager to solve meaningful challenges and build with purpose, we’d love to hear from you. About the Role We’re looking for an Senior Application Security Engineer to build and scale our product security function across the Group. As the first dedicated AppSec specialist, you’ll own security practices end to end — from Secure SDLC and CI/CD security gates to vulnerability management, security testing, and developer enablement. You’ll work closely with the Group CISO and security team to help build secure, scalable fintech products. Key Responsibilities Secure SDLC Roll out our Secure SDLC process to all products, one by one. The pilot is done; you scale it. Run security design reviews for critical changes (auth, payments, admin, crypto). Use lightweight threat modeling. Keep the security review process fast. Target: first response within 1 working day, async review within 3. Security tooling in CI/CD Own SAST, SCA, secret scanning, and IaC scanning in GitLab CI (Semgrep, Trivy, gitleaks, Checkov). Write custom Semgrep rules based on real findings in our code. Make the pipelines stable and useful. Low noise, clear signal, blocking gates where it matters. Vulnerability management Triage findings from pentests, scanners, and our attack surface monitoring. SLA: triage within 2 working days. Verify fixes with confirmation scans before closing. Re-test old pentest findings so they do not come back. Product security testing Do hands-on security testing of our web apps and APIs: payment flows, back-office panels, partner integrations. Review source code for security issues (Go, PHP, JavaScript). Help dev teams design secure APIs: request signing, key rotation, replay protection, rate limiting. Bug bounty Prepare and launch our private bug bounty program. Later, take it public. Own triage, researcher communication, and reward decisions. People and compliance Train developers: short secure-coding sessions, based on our own findings. Support the Security Champions program in dev teams. Provide evidence for PCI DSS and DORA audits (secure development, payment page integrity, change control). What you need to succeed in this role 4+ years in application security and/or penetration testing Strong web and API security skills: OWASP Top 10 is your comfort zone, business logic flaws are your interest You can analyze source code and identify security flaws. Experience with Go, PHP, or JavaScript is required, with Go being a plus Hands-on experience adding security tools to CI/CD pipelines (any of: Semgrep, Trivy, gitleaks, or similar) Ability to write clear, actionable security reports and communicate findings effectively with development teams Strong prioritization skills - you understand risk impact and can distinguish critical issues from lower-priority findings B1+ level of English proficiency is required to work with technical documentation Nice to have Practical cert