← WorkMundi · 1M+ jobs from around the world, liveSign inCreate free account

Security Engineer, Application Security

REAP Limited · Hong Kong SAR

🌐 Remote📅 12/08/2026
🔔 Alert me about jobs like this
No password, no sign-up. Just the email — and you can leave the list anytime.
🔓 Apply — free →
Opens this job on WorkMundi. The account is free and takes under a minute.

See the other 6,924 jobs in Hong Kong →

🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
Founded in 2018 Your Mission During our acquisition by Payward/Kraken, their due diligence team found a race condition vulnerability in our product. We found it second. That is not the position we want to be in going forward. As our Application Security Engineer, you will embed security inside the engineering process rather than bolting it on afterwards. You will own our secure SDLC, build the tooling that catches vulnerabilities in the pipeline before they ship, run threat modelling sessions with our engineering squads, and manage our bug bounty programme. This is a builder role that works inside the engineering team, not above it. What You Will Do • Build and own the application security programme: secure coding standards, developer security training, security review gates in the engineering workflow, and the SAST/DAST/SCA tooling that enforces them in CI/CD. • Lead threat modelling for new product features, API integrations, and significant architectural changes. Run STRIDE-based sessions with engineering squads who have not done this before. • Do security-focused code reviews for the areas that matter: authentication, authorisation, payment flows, cryptographic operations, and external API integrations. • Own our dependency and open source software security: scan, assess, and enforce our OSS usage policy. • Run developer security education: OWASP Top 10, OWASP API Top 10, a security champions network, and practical sessions that engineers actually find useful. • Manage penetration testing engagements end-to-end: scope, vendor, findings, and remediation verification. • Own our responsible disclosure policy and manage our bug bounty programme once it launches. Your Superpowers • You have improved an application security programme inside an engineering organisation. You know what the before and after looks like, and how to get engineering buy-in for both. • Hands-on SAST/DAST/SCA pipeline experience. Semgrep, CodeQL, Checkmarx, SonarQube, or equivalent. You have configured these in CI/CD, not just run them on demand. • You can do threat modelling with engineers who have never done it. STRIDE or PASTA. You facilitate, not lecture. • Secure code review in at least two languages. JavaScript/TypeScript, Python, Go, or Rust. You can read code and find the vulnerability, not just run a scanner. • Application penetration testing fundamentals. OWASP Top 10 and API Top 10 in practice. You know how authentication and authorisation get broken. • PCI DSS secure coding requirements. We handle payment card data. You know what that means for development. Nice to Have • CSSLP, GWEB, or OSCP certification. • Crypto or DeFi application security experience. • Bug bounty programme management experience. • Experience with smart contract interaction security or exchange API security. Why You Will Love It Here • You are building the application security function at a fast-moving fintech from scratch, with direct access to engineering leadership. • The race condition finding gave us a very specific brief: find things like that before the acquirer does. You will have a clear mandate. • We use AI tools extensively. GitHub Copilot, Claude Code, and others are part of how we build. You will help make sure we build securely with them. • Flexible remote work, global team, and a company that is growing fast. Benefits you'll enjoy A vibrant, inclusive work culture. Annual leave to relax and recharge, plus public holidays. Health insurance budget. Be part of a fast‑growing global team. Flexible remote work options. Home office equipment budget. Your own Corporate Reap Card-no more out‑of‑pocket spending.
Read the rest of the job →
For people searching Engineer

144,883 engineer jobs are open right now

Here's how to pick the right one and stand out in your application.

144.883Jobs
31.687IN
81%EN

That number is real. WorkMundi's database shows 144,883 open engineer roles across the world. India has the most with 31,687 jobs, followed by the United States with 30,084. If you just finished reading one job ad and felt paralyzed by choice, you're not alone—but this scale is actually an advantage. It means you can afford to be selective.

Start by geography and language. The majority of engineer ads—117,837 of them—have the job posting text written in English. Use that as one filter, but remember: the ad text language tells you nothing about whether the role actually requires you to speak English day-to-day. Read the job description carefully. Then check which countries have the volume you're targeting. Singapore, Poland, and Australia round out the top five after India and the US.

Next, learn who's hiring. Accenture has posted 2,801 engineer roles. andurilindustries, speechify, and jobgether are also actively recruiting. If you're applying to one of these names, research their hiring patterns and interview style before you apply. That homework pays off.

When you interview, expect the question every engineer hears: 'Tell me about a time you had to debug a problem that wasn't in your job description.' Have a specific story ready—not a general one. Name the tools, the deadline pressure, and what you learned. Hiring managers listen for whether you see problem-solving as part of the role itself, not a favour.

👁 21 have read this
0 comments
Want to comment?

Leave your e-mail to comment, react and follow the posts for your role. It is free.

Similar jobs

Job on WorkMundi — the world's largest job board. See more jobs from every continent, updated live.

📢
🎁

Before you apply, rehearse this interview.

Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card.

I want my training →