Distribusion Technologies is a leading global ground transportation marketplace, connecting bus, rail, and ferry operators with major online retailers. We are seeking a Senior Application Security Engineer to build our AppSec practice from the ground up in a greenfield environment, directly impacting our secure development lifecycle and protecting high-traffic partner-facing APIs.
Key responsibilities
- Lead threat modeling and secure design reviews for high-risk changes, partner integrations, and payment flows.
- Implement and enforce security gates in GitLab CI/CD, including SAST, SCA, and DAST, while minimizing developer friction.
- Act as the primary technical owner for triaging and prioritizing findings from bug bounties, pentests, and automated scanners.
- Collaborate with the DevOps team to implement GCP organizational policies, IAM least-privilege architectures, and WAF configurations.
- Establish a security-champions network across engineering squads to scale code reviews effectively.
Requirements
- 5+ years of experience in Application Security or a strong background in software engineering and web pentesting.
- Proficiency in reading and writing production code in languages such as Python, Go, TypeScript, or Ruby.
- Deep knowledge of web and API security, including OAuth2, JWT, tenant isolation, and common vulnerabilities like IDOR and XSS.
- Strong cloud security fundamentals, specifically within GCP environments, focusing on secrets hygiene and public exposure.
- Ability to prioritize real-world risks and communicate complex security concepts clearly to engineering teams and leadership.
What we offer
- The opportunity to join a fast-paced, high-growth travel tech company with a flat organizational structure.
- Full ownership and responsibility over the security architecture of a global B2B platform.
- Collaboration with an international, talented team of professionals in a mission-driven environment.
- A fully remote work environment with the flexibility to contribute to our global expansion.