Public Telegram Archive
Channels About
CY iT HR
@cyprusithr · supergroup · filtered by Lera
Lera 2026-07-30 10:12 UTC webpage
📎 Webpage (not supported)
Hey

International technology-driven financial company Salmon looking for: Application Security Lead
Location - remote (exlude Belarus and Russia)

What makes you a strong fit:
🏄🏽‍♂️7+ years in application security, with meaningful ownership over both technical work and process.
🏄🏽‍♂️Has built or substantially improved a secure SDLC in a fast-moving product org.
🏄🏽‍♂️Has run threat modeling on real product features and influenced design decisions as a result.
🏄🏽‍♂️Has owned vulnerability management end-to-end: triage, remediation tracking, SLA management, risk acceptance.
🏄🏽‍♂️Has done hands-on mobile security testing (iOS and/or Android) in a production context, not just UAT.
🏄🏽‍♂️Understands modern supply chain attack vectors like compromised packages (npm, PyPI), malicious IDE plugins, typosquatting, dependency confusion - and knows how to reduce exposure at the tooling and process level.
🏄🏽‍♂️Comfortable writing Python or Bash to automate repetitive security work.

**Technical skills:
**🏄SAST, DAST, SCA in CI/CD pipelines: knows how to tune for signal, not just coverage
🏄API security: authentication flows, token handling, common abuse patterns
🏄Mobile security: OWASP ASVS/MASVS applied in practice
🏄Supply chain: SBOM generation and dependency risk management
🏄Secrets management: detection, remediation, and structural prevention
🏄Working knowledge of AWS and containers sufficient to understand where application risks extend into infrastructure
🏄Southeast Asia's fintech moment starts here.

Сontact me
@Lera_Mes
or apply
https://careers.salmon.ph/open-roles?ashby_jid=51d03b6c-aad1-4d1f-9f68-c09cb2866a69
Lera 2026-07-30 10:14 UTC webpage
📎 Webpage (not supported)
#vacancy #appsec

Hey

International technology-driven financial company Salmon looking for: Application Security Lead
Location - remote (exlude Belarus and Russia)

What makes you a strong fit:
🏄🏽‍♂️7+ years in application security, with meaningful ownership over both technical work and process.
🏄🏽‍♂️Has built or substantially improved a secure SDLC in a fast-moving product org.
🏄🏽‍♂️Has run threat modeling on real product features and influenced design decisions as a result.
🏄🏽‍♂️Has owned vulnerability management end-to-end: triage, remediation tracking, SLA management, risk acceptance.
🏄🏽‍♂️Has done hands-on mobile security testing (iOS and/or Android) in a production context, not just UAT.
🏄🏽‍♂️Understands modern supply chain attack vectors like compromised packages (npm, PyPI), malicious IDE plugins, typosquatting, dependency confusion - and knows how to reduce exposure at the tooling and process level.
🏄🏽‍♂️Comfortable writing Python or Bash to automate repetitive security work.

**Technical skills:
**🏄SAST, DAST, SCA in CI/CD pipelines: knows how to tune for signal, not just coverage
🏄API security: authentication flows, token handling, common abuse patterns
🏄Mobile security: OWASP ASVS/MASVS applied in practice
🏄Supply chain: SBOM generation and dependency risk management
🏄Secrets management: detection, remediation, and structural prevention
🏄Working knowledge of AWS and containers sufficient to understand where application risks extend into infrastructure

Southeast Asia's fintech moment starts here.

Сontact me
@Lera_Mes
or apply
https://careers.salmon.ph/open-roles?ashby_jid=51d03b6c-aad1-4d1f-9f68-c09cb2866a69
2 messages on this day