PB✓
PBridge
Full-timeRemote, Nigeria

Senior Application Security Engineer

at Moniepoint

Moniepoint Inc., Africa's all-in-one financial platform serving 20 million businesses and individuals, is seeking a Senior Application Security Engineer to champion secure innovation by embedding security into the software development lifecycle. You will partner with engineering teams to safeguard customer trust while building cutting-edge services through threat modeling, code review, security automation, and developer mentorship.

Job Description

Responsibilities

  • Define and execute security strategy for product teams, aligning with business objectives
  • Lead threat modeling, security architecture reviews, and design guidance for diverse software projects
  • Mentor engineers technically and professionally, fostering a culture of security excellence
  • Conduct adversarial security analysis using automated tools and manual techniques (e.g., custom exploit development)
  • Perform manual/automated secure code reviews across Java, Python, JavaScript, and cloud-native stacks
  • Develop security automation tools to scale vulnerability detection (SAST/DAST/IAST enhancements)
  • Identify complex risks through offensive security research; advocate for cutting-edge mitigation technologies
  • Solve novel security problems lacking predefined solutions (e.g., zero-day vulnerabilities, emergent attack vectors)
  • Maintain and evolve threat models for critical applications and microservices architectures
  • Partner with the engineering team to embed security controls into CI/CD pipelines and development practices
  • Design/deliver security training programs tailored to development teams and business stakeholders
  • Lead incident response for application security events and drive root-cause analysis

Requirements

  • 5+ years in application security, including 2+ years in a senior/lead role
  • Expertise in threat modeling (e.g., STRIDE, PASTA), penetration testing, and secure SDLC implementation
  • Proficiency in code review for Java/Python/JavaScript and cloud platforms (AWS/Azure/GCP)
  • Hands-on experience building security tools (e.g., scanners, CI plugins) with Python/Go
  • Proven track record in security architecture design and risk-based decision-making
  • Ability to define team strategy, mentor engineers, and influence stakeholders
  • Aptitude for researching/implementing novel solutions to ambiguous security challenges
  • Mastery of application security frameworks (OWASP, NIST) and exploit techniques
  • Translate technical risks to business impact for executives and engineers alike
  • Drive implementation of security controls
  • OSCP, OSCE, GXPN, or similar offensive security certifications (preferred)
  • Contributions to security tooling/open-source projects (preferred)
  • Experience with container security (Kubernetes, Docker), serverless, or infrastructure-as-code (preferred)

Benefits

  • Culture prioritizing people first and the well-being of every team member
  • Company where all opinions carry weight and all voices are heard
  • Learning and development-focused environment with emphasis on knowledge sharing, training, and regular internal technical talks
  • Attractive salary
  • Pension
  • Health insurance
  • Employee Stock Options
  • Annual bonus

Skills

JavaPythonJavaScriptAWSAzureGCPGoKubernetesDockerSTRIDEPASTAOWASPNISTSASTDASTIASTCI/CD

Ready to apply for this role?

PBridge connects skilled professionals with top employers worldwide.