[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"job-application-security-engineer-pepperstone-en-cy":3},{"id":4,"slug":5,"title":6,"description":7,"company":8,"is_featured":11,"featured_until":7,"is_active":12,"deactivated_at":7,"is_enriched":12,"processed_job_posting_json":13,"processed_latitude":69,"processed_longitude":71,"processed_employment_types":73,"processed_working_hours":74,"processed_working_hours_labels":76,"processed_home_office":77,"processed_salary_min":66,"processed_salary_max":67,"processed_salary_currency":63,"processed_salary_source":78,"processed_benefits":79,"processed_benefits_labels":95,"processed_industry":96,"processed_skills":7,"processed_job_location":97,"processed_full_address_gmaps":99,"processed_street_gmaps":101,"processed_city_gmaps":103,"processed_postal_code_gmaps":105,"processed_country_gmaps":107,"processed_country_iso_code_gmaps":109,"full_description":16,"formatted_description":111,"processed_employment_types_labels":22,"processed_home_office_labels":20,"processed_industry_labels":24,"processed_it_skills":112,"processed_it_skills_labels":115,"processed_soft_skills":116,"processed_soft_skills_labels":117,"processed_job_expertise_skills":118,"processed_job_expertise_skills_labels":119,"processed_language_requirements":120,"processed_total_experience_years":127,"processed_professional_field":128,"processed_professional_field_labels":130,"processed_leadership_role":11,"processed_date_posted":19,"raw_job_url":131,"apply_url":7,"raw_hiringOrganization_logo_url":132,"translations":7,"canonical_industry_key":96,"canonical_industry_label":24,"max_cpc":133,"actual_cpc":7},41014,"application-security-engineer-pepperstone","Application Security Engineer",null,{"name":9,"slug":10,"logo_url":7},"Pepperstone","pepperstone",false,true,{"@context":14,"@type":15,"title":6,"description":16,"hiringOrganization":17,"datePosted":19,"jobLocationType":20,"employmentType":21,"industry":23,"skills":25,"baseSalary":61},"https:\u002F\u002Fschema.org\u002F","JobPosting","The Pepperstone story started in 2010. We know what it’s like to trade the world’s markets. Our team describes us as a place for the curious and the driven, and we like to do things a little differently; as a transformative global fintech we’re digital, nimble, connected, and united in our vision to create a better way to trade.\nWe thrive on progress – for our clients and for ourselves. Our organisational culture is ever-evolving, vibrant, diverse, global and results focused. You’ll find our \n700+ \nteam across \n12\n regions and \n9\n time zones.\nThe Role\nThe Application Security Engineer exists to embed security throughout the software development lifecycle at Pepperstone. You will partner with engineering and product teams to identify, assess, and remediate security vulnerabilities in our applications and APIs, ensuring that security is a first-class citizen in every release.\nYou will drive adoption of secure coding practices, conduct application security assessments, and help build a security-aware engineering culture across the organisation.\nThis \nposition reports to Head of Product Security, Limassol, Cyprus\n. Our team is made up of individuals from all walks of life, each bringing unique experiences and perspectives that enrich our work and culture. We truly value this diversity and are excited to welcome someone who is open-minded, adaptable, and enthusiastic about collaborating in a globally connected and inclusive environment.\nWhat You’ll Be Doing\nPerform application security assessments including threat modelling, secure code reviews, and penetration testing across web, mobile, and API surfaces.\nPartner with development teams to integrate security controls into CI\u002FCD pipelines using SAST, DAST, SCA, and secrets detection tooling.\nIdentify, triage, and track vulnerabilities through to remediation, working closely with engineering teams to provide actionable guidance.\nDefine and maintain application security standards, secure coding guidelines, and developer-facing security documentation.\nChampion security-by-design principles and provide hands-on guidance during the design and architecture phases of new features and products.\nLead and support bug bounty and responsible disclosure programmes, coordinating triage and remediation of externally reported issues.\nConduct security training and awareness sessions for software engineers, embedding secure development practices across teams.\nEvaluate third-party libraries, open-source components, and vendor integrations for security risk.\nCollaborate with the broader Security team on incident response activities related to application-layer vulnerabilities.\nAbout You\n8+ years of experience in information security, with at least 3 years specialising in application security or software security engineering.\nSolid understanding of common vulnerability classes including OWASP Top 10, business logic flaws, and API security risks.\nHands-on experience with security testing tools such as Burp Suite, OWASP ZAP, Semgrep, Checkmarx, Snyk, or equivalent.\nProficiency in at least one programming or scripting language (Python, JavaScript, Java, Go, or similar) to support code review and automation.\nExperience integrating security tooling into CI\u002FCD pipelines (GitHub Actions, Jenkins, GitLab CI, or similar).\nFamiliarity with cloud security principles across AWS, Azure, or GCP, particularly as they relate to application hosting and deployment.\nStrong communication skills with the ability to articulate security risk to both technical and non-technical stakeholders.\nRelevant certifications such as OSCP, GWEB, CEH, or equivalent are advantageous.\nExperience in a regulated financial services or fintech environment is a plus.\nFluency in English; Hungarian language skills are an advantage.\nAbility to live the Pepperstone values.\nCommitted to ongoing learning and development\nWhy you will enjoy working with us\nCompetitive salary structure including company bonus scheme\nFlexible and hybrid working\nRemote working option - work from anywhere for up to 4 weeks per year\n10 days of Company paid sick leave annually  \n21 days of paid vacation within the first year of employment, increasing to 25 days after one year \n3 paid volunteering days per year & Workplace Giving Program\nComprehensive medical insurance with coverage for your healthcare needs\nPension fund\nEmployee referral bonuses for referring top talent to the company \nOngoing personal development & learning opportunities\nPeriodic recognition and reward programs for outstanding performance and achievements\nFrequent events and celebrations\nGenuinely collaborative and friendly culture\nEmployee Assistance Program & Wellbeing Initiatives\nConvenient and cozy office located near the Limassol Municipal Garden\nMore about Pepperstone\nWe’re a regulated online Forex and CFD trading platform. With the scale of a global fintech and the agility of a start-up, we arm our clients with everything they need to take on the global markets with confidence. You will be part of a wider passionate and friendly team, and whilst things may not always go to plan, we learn quickly and move forward with impact. To learn even more visit  and \nWe understand it’s important to do due diligence on a prospective employer and see what our team is saying on . We respect our team members’ experiences and will never pay to remove a negative review.\nPepperstone is an equal-opportunity employer. We are passionate about building a diverse workplace and strongly encourage applications from any background.\n“We are a 2025 Circle Back Initiative Employer – we respond to every applicant”.\nWe will be reviewing applications as they come through, so if this is an opportunity that excites you, don't wait. Express your interest by clicking the apply button below as soon as possible.\nNote to external agencies: While we appreciate the efforts of external recruitment agencies, we prefer to engage directly with applicants for this opportunity.",{"@type":18,"name":9},"Organization","2026-06-19","HYBRID",[22],"PERMANENT",[24],"Financial Services",[26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60],"Burp Suite","OWASP ZAP","Semgrep","Checkmarx","Snyk","Python","JavaScript","Java","Go","GitHub Actions","Jenkins","GitLab CI","AWS","Azure","GCP","Communication","Collaboration","Adaptability","Open-mindedness","Enthusiasm","Application Security Assessments","Threat Modelling","Secure Code Reviews","Penetration Testing","CI\u002FCD Integration","Vulnerability Management","Security Standards Definition","Security-by-Design","Bug Bounty Program Management","Security Training","Third-party Security Evaluation","Incident Response","OWASP Top 10","API Security","Cloud Security",{"@type":62,"currency":63,"value":64},"MonetaryAmount","EUR",{"@type":65,"minValue":66,"maxValue":67,"unitText":68},"QuantitativeValue",80000,120000,"YEAR",[70],34.6824711,[72],33.0527214,"permanent",[75],"FULL_TIME",[75],"hybrid","estimated",[80,81,82,83,84,85,86,87,88,89,90,91,92,93,94],"Competitive salary structure including company bonus scheme","Flexible and hybrid working","Remote working option - work from anywhere for up to 4 weeks per year","10 days of Company paid sick leave annually","21 days of paid vacation within the first year of employment, increasing to 25 days after one year","3 paid volunteering days per year & Workplace Giving Program","Comprehensive medical insurance with coverage for your healthcare needs","Pension fund","Employee referral bonuses for referring top talent to the company","Ongoing personal development & learning opportunities","Periodic recognition and reward programs for outstanding performance and achievements","Frequent events and celebrations","Genuinely collaborative and friendly culture","Employee Assistance Program & Wellbeing Initiatives","Convenient and cozy office located near the Limassol Municipal Garden",[80,81,82,83,84,85,86,87,88,89,90,91,92,93,94],"financial services",[98],"pepperstone, limassol, cyprus",[100],"Myronos 3, Limasol 3035, Zypern",[102],"Myronos 3",[104],"Lemesos",[106],"3035",[108],"Zypern",[110],"CY","The Pepperstone story started in 2010. We know what it’s like to trade the world’s markets. Our team describes us as a place for the curious and the driven, and we like to do things a little differently; as a transformative global fintech we’re digital, nimble, connected, and united in our vision to create a better way to trade.\n\nWe thrive on progress – for our clients and for ourselves. Our organisational culture is ever-evolving, vibrant, diverse, global and results focused. You’ll find our 700+ team across 12 regions and 9 time zones.\n\n## The Role\n\nThe Application Security Engineer exists to embed security throughout the software development lifecycle at Pepperstone. You will partner with engineering and product teams to identify, assess, and remediate security vulnerabilities in our applications and APIs, ensuring that security is a first-class citizen in every release.\n\nYou will drive adoption of secure coding practices, conduct application security assessments, and help build a security-aware engineering culture across the organisation.\n\nThis position reports to Head of Product Security, Limassol, Cyprus. Our team is made up of individuals from all walks of life, each bringing unique experiences and perspectives that enrich our work and culture. We truly value this diversity and are excited to welcome someone who is open-minded, adaptable, and enthusiastic about collaborating in a globally connected and inclusive environment.\n\n## What You’ll Be Doing\n\n- Perform application security assessments including threat modelling, secure code reviews, and penetration testing across web, mobile, and API surfaces.\n- Partner with development teams to integrate security controls into CI\u002FCD pipelines using SAST, DAST, SCA, and secrets detection tooling.\n- Identify, triage, and track vulnerabilities through to remediation, working closely with engineering teams to provide actionable guidance.\n- Define and maintain application security standards, secure coding guidelines, and developer-facing security documentation.\n- Champion security-by-design principles and provide hands-on guidance during the design and architecture phases of new features and products.\n- Lead and support bug bounty and responsible disclosure programmes, coordinating triage and remediation of externally reported issues.\n- Conduct security training and awareness sessions for software engineers, embedding secure development practices across teams.\n- Evaluate third-party libraries, open-source components, and vendor integrations for security risk.\n- Collaborate with the broader Security team on incident response activities related to application-layer vulnerabilities.\n\n## About You\n\n- 8+ years of experience in information security, with at least 3 years specialising in application security or software security engineering.\n- Solid understanding of common vulnerability classes including OWASP Top 10, business logic flaws, and API security risks.\n- Hands-on experience with security testing tools such as Burp Suite, OWASP ZAP, Semgrep, Checkmarx, Snyk, or equivalent.\n- Proficiency in at least one programming or scripting language (Python, JavaScript, Java, Go, or similar) to support code review and automation.\n- Experience integrating security tooling into CI\u002FCD pipelines (GitHub Actions, Jenkins, GitLab CI, or similar).\n- Familiarity with cloud security principles across AWS, Azure, or GCP, particularly as they relate to application hosting and deployment.\n- Strong communication skills with the ability to articulate security risk to both technical and non-technical stakeholders.\n- Relevant certifications such as OSCP, GWEB, CEH, or equivalent are advantageous.\n- Experience in a regulated financial services or fintech environment is a plus.\n- Fluency in English; Hungarian language skills are an advantage.\n- Ability to live the Pepperstone values.\n- Committed to ongoing learning and development\n\n## Why you will enjoy working with us\n\n- Competitive salary structure including company bonus scheme\n- Flexible and hybrid working\n- Remote working option - work from anywhere for up to 4 weeks per year\n- 10 days of Company paid sick leave annually  \n- 21 days of paid vacation within the first year of employment, increasing to 25 days after one year \n- 3 paid volunteering days per year & Workplace Giving Program\n- Comprehensive medical insurance with coverage for your healthcare needs\n- Pension fund\n- Employee referral bonuses for referring top talent to the company \n- Ongoing personal development & learning opportunities\n- Periodic recognition and reward programs for outstanding performance and achievements\n- Frequent events and celebrations\n- Genuinely collaborative and friendly culture\n- Employee Assistance Program & Wellbeing Initiatives\n- Convenient and cozy office located near the Limassol Municipal Garden\n\n## More about Pepperstone\n\nWe’re a regulated online Forex and CFD trading platform. With the scale of a global fintech and the agility of a start-up, we arm our clients with everything they need to take on the global markets with confidence. You will be part of a wider passionate and friendly team, and whilst things may not always go to plan, we learn quickly and move forward with impact. To learn even more visit  and \n\nWe understand it’s important to do due diligence on a prospective employer and see what our team is saying on . We respect our team members’ experiences and will never pay to remove a negative review.\n\nPepperstone is an equal-opportunity employer. We are passionate about building a diverse workplace and strongly encourage applications from any background.\n\n“We are a 2025 Circle Back Initiative Employer – we respond to every applicant”.\n\nWe will be reviewing applications as they come through, so if this is an opportunity that excites you, don't wait. Express your interest by clicking the apply button below as soon as possible.\n\nNote to external agencies: While we appreciate the efforts of external recruitment agencies, we prefer to engage directly with applicants for this opportunity.",{"go":113,"aws":114,"gcp":114,"java":113,"snyk":113,"azure":114,"python":113,"jenkins":113,"semgrep":113,"checkmarx":113,"gitlab ci":113,"owasp zap":113,"burp suite":113,"javascript":113,"github actions":113},4,3,[26,27,28,29,30,31,32,33,34,35,36,37,38,39,40],{"communication":113,"collaboration":113,"adaptability":114,"open-mindedness":114,"enthusiasm":114},[41,42,43,44,45],{"api security":113,"owasp top 10":113,"cloud security":114,"threat modelling":113,"ci\u002Fcd integration":113,"incident response":114,"security training":113,"security-by-design":113,"penetration testing":113,"secure code reviews":113,"vulnerability management":113,"bug bounty program management":113,"security standards definition":113,"third-party security evaluation":113,"application security assessments":113},[46,47,48,49,50,51,52,53,54,55,56,57,58,59,60],{"detected_language_jobad":121,"required":122},"en",[123],[124],{"language":125,"level":126},"ENGLISH","C2",8,[129],"Information and Communications Technology Professionals",[129],"https:\u002F\u002Fapply.workable.com\u002Fpepperstone\u002Fj\u002F9e86cb0db3\u002F","https:\u002F\u002Fworkablehr.s3.amazonaws.com\u002Fuploads\u002Faccount\u002Flogo\u002F564195\u002Flogo",1]