Logo for additiv

Senior Cloud Application Security Engineer

Role overview

Qualifications

  • At least 5 years of relevant application security, cloud security, vulnerability management or security engineering experience
  • Hands-on experience in application/API security testing, vulnerability triage and remediation validation
  • Practical knowledge of Azure security, especially Defender for Cloud and Sentinel
  • Understanding of web/API risks, secure development, authentication, authorisation, access control

Responsibilities

  • Provide production-focused security oversight for applications, APIs and microservices
  • Review Defender for Cloud and Sentinel alerts, recommendations and security findings
  • Investigate suspicious activity and potential attack paths; assess exposure, exploitability and business risk
  • Support application/API threat modelling, design reviews and secure development

Key facts

Hard skills

Other skills

  • Communication
  • Investigation
  • Collaboration
  • Problem Solving

About the company

additiv logo

additiv

Financial Services

additiv empowers the world's leading financial institutions and brands to create new business models and transform existing ones. additiv's API-first cloud platform is one of the world's most powerful solutions for wealth management, banking, credit, and insurance. The technology, together with the global ecosystem of regulated financial services providers, opens up new opportunities for banks, insurance companies, asset managers, IFAs and consumer brands to quickly and flexibly offer their own and third-party financial solutions through existing or new customer channels. Headquartered in Switzerland, with regional offices in Singapore, UAE, Germany, and the UK, and more than 250 employees, additiv serves over 400 financial institutions (banks, insurers, asset managers, pension providers, IFAs, etc.) and brands worldwide.

Company details

Company typeSME
IndustryFinancial Services
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About this role

We are seeking a senior Cloud Application Security Engineer to strengthen application and API security across the production estate. The role investigates monitoring and assessment findings and coordinates remediation with CloudOps and development teams. The engineer will work with the existing security team.


Your responsibilities

  • Provide production-focused security oversight for applications, APIs and microservices
  • Review Defender for Cloud and Sentinel alerts, recommendations and security findings
  • Operate and improve continuous vulnerability assessment and VAPT, including the AI-enabled security-validation platform when selected
  • Correlate findings and telemetry from Defender for Cloud, Sentinel, Azure Front Door/WAF, API Management, AKS, OpenTelemetry, Azure Monitor and Grafana
  • Investigate suspicious activity and potential attack paths; assess exposure, exploitability and business risk
  • Support application/API threat modelling, design reviews and secure development; assess authentication, authorisation, access controls, secrets, dependencies, containers and supply-chain risks
  • Validate findings, filter false positives, prioritise remediation, coordinate fixes with CloudOps and development teams, and retest through closure
  • Tune assessment and detection configurations; support incident investigations, evidence collection, post-incident reviews and security reporting

Your qualifications, skills and experience

  • At least 5 years of relevant application security, cloud security, vulnerability management or security engineering experience, with senior-level ownership of investigations or remediation
  • Hands-on experience in application/API security testing, vulnerability triage and remediation validation
  • Practical knowledge of Azure security, especially Defender for Cloud and Sentinel; familiarity with KQL, Azure Monitor, Log Analytics and OpenTelemetry is an advantage
  • Understanding of web/API risks, secure development, authentication, authorisation, access control, containers, AKS/Kubernetes and software supply chains
  • Experience with DAST, API scanning, vulnerability assessment or continuous VAPT
  • Experience with .NET, ASP.NET (MVC, Web API), Web Services, and SQL DBs
  • Clear communicator in English, able to explain findings to developers, CloudOps, security colleagues and management
  • Investigative, evidence-led and collaborative; prioritises risk pragmatically and follows remediation through validation
  • Careful to test production systems only within approved scope and change controls.
  • Focused on improving production defence

Location

 Work from our office in: Bucharest/ Dubai/ Sarajevo


We offer you

  • An open-minded, international and fast-paced environment where decisions are made quickly, ideas are welcomed and people are encouraged to make a real impact

  • A meritocratic culture built on ownership, performance and continuous feedback, where ambition is recognized and contribution matters

  • The opportunity to influence decisions, challenge the status quo and shape better ways of working, while collaborating across teams and functions

  • A strong commitment to continuous learning and professional development, with support to grow your expertise, capabilities and career

  • A values-driven culture where we Care by building trust and lasting relationships, Commit by taking ownership and delivering on our goals, Collaborate by bringing the right people and expertise together, and Challenge ourselves to raise the bar and achieve stronger outcomes


How to apply

If you are passionate about joining a growing and motivated team of financial services enthusiasts and want to contribute to the growth of a leading international FinTech company, please click below to apply.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Application Security Engineer Related jobs

Other jobs at additiv

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.