> Markdown version of [/jobs/ext/2723532-security-engineer](https://www.wearedevelopers.com/jobs/ext/2723532-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Transak's Product - **Location:** Austria - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Software System Penetration Testing, User Authentication, Burp Suite, Code Review, Cyber Security, Computer Programming, Distributed Systems, Github, Identity and Access Management, Mobile Application Software, Information Systems Security Architecture Professional, Python (Programming Language), Key Management, Node.Js, Open Web Application Security, Blockchain, Session Management, Software Engineering, Software Vulnerability Management, Web Applications, Sonatype, Software Security, GWAPT, Gitlab-ci, Jenkins, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/application-security-engineer-transak-9925093 ## About the Role * 5+ years as a security engineer, focused on application or product security. * Deep understanding of web and API security - OWASP Top 10, authentication and authorisation, session management. * Hands-on experience with security testing tools such as Burp Suite, OWASP ZAP, Snyk, Aikido etc. * Strong programming skills in a modern language, ideally JavaScript / Node.js or Python. * Experience integrating security tooling into CI/CD pipelines such as GitLab CI, Jenkins or GitHub Actions. * Practical software composition analysis and SBOM experience, with an understanding of modern supply chain attacks against npm and PyPI. * Vulnerability management ownership: a register, named owners, enforced SLAs and reported adherence. * Threat modelling applied to real business flows, and secure architecture patterns for APIs and distributed systems. * Solid understanding of cryptography, secrets management and identity and access management. * Excellent communication skills, able to translate security concepts for an engineering audience. * Comfortable building a capability from nothing rather than inheriting a mature programme. Bonus: * Hands-on security testing of cryptocurrency or blockchain infrastructure and applications is a major bonus. * Fintech, payments or custody experience, particularly anything touching wallets or settlement. * Supply chain security depth: SBOM formats, build provenance, SLSA, and prioritisation using EPSS and the CISA KEV catalogue. * Knowledge of compliance frameworks such as DORA, MiCA, SOC 2, ISO 27001 or GDPR. * Managing an external penetration testing vendor or a bug bounty programme. * Certifications such as OSCP, OSWE, GWAPT or CSSLP. ## Description Transak's product is its attack surface: a widget, a set of APIs and the flows that move customer funds and customer identity data, built on a Node.js and Python stack. This is a founding role in a small security function, reporting to the CISO. You will own application and product security end to end and build the capability rather than operate an existing one - there is no established programme to inherit and no team to delegate to. Transak operates under MiCA and DORA in the EU with further regulated entities in MENA and the US, so what you build needs to be evidenced as well as effective. What You'll Be Doing As Transak's first dedicated application security hire, you will safeguard our applications and development lifecycle through proactive security integration and engineering excellence. Your responsibilities include: * Partner with engineering teams to embed security into the software development lifecycle, from design through to deployment. * Conduct security code reviews, threat modelling sessions and architecture reviews for the flows that move customer funds and customer identity data. * Select, implement and tune SAST, DAST and SCA solutions to identify vulnerabilities early in the development process. * Build and maintain application security testing automation within CI/CD pipelines, with severity-based gating that engineering can plan around. * Own the software supply chain: an SBOM per deployable service, dependency and provenance standards, and approved base images. * Build and run a consolidated vulnerability register - triage, prioritise by real exploitability, assign owners and drive remediation to verified closure. * Perform penetration testing and vulnerability assessments of web applications, APIs and mobile applications. * Own the external penetration testing programme, scoping engagements from the threat model and enforcing re-testing. * Develop secure coding standards, reusable security components and role-based training for engineering teams. * Create a security champions programme so that security scales beyond one person. * Run the bug bounty programme and coordinate with external security researchers. * Research emerging application and supply chain threats, and integrate defensive measures into the security architecture. * Evidence secure development and vulnerability management controls for DORA, MiCA, SOC 2 and ISO 27001. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Ultimate Software Engineer Career Path Guide for 2023](https://www.wearedevelopers.com/magazine/146-the-ultimate-software-engineer-career-path-guide-for-2023) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Software Developer Salary in Austria [2023]](https://www.wearedevelopers.com/magazine/213-software-developer-salary-in-austria-2023) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)