Skip to main content
Back to jobs

AppSec Engineer

External
addi logoAddi · Colombia
Full-timeRemote5mo ago
Application SecurityCI/CDOWASPThreat Modeling
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

This is where you come in. Below, you'll find what this role is all about-the impact you'll drive, the challenges you'll tackle, and what it takes to thrive at Addi. If you're ready to be part of something big, keep reading. What's the mission you'll drive Design, implement, and operate the Secure Software Development Lifecycle (SSDLC) end to end, embedding security requirements, threat modeling, testing, and vulnerability management into the development process to reduce application risk at scale.

Responsibilities

  • Own the end-to-end application vulnerability management lifecycle across code, dependencies, APIs, and mobile applications, ensuring ≥70% of critical vulnerabilities are remediated within SLAs by the end of Q2 2026, with continuous quarter-over-quarter reduction in open critical findings.
  • Plan and manage application security assessments, penetration tests, and adversarial exercises for critical applications, ensuring 100% of high-risk findings are tracked and remediated within SLAs, and demonstrating year-over-year reduction in recurring high-risk issues.

Requirements

  • Hands-on Expertise in Application Security Testing & Tooling
  • Experienced in using and maintaining application security tools such as Burp Suite, MobSF, trufflehog, Nuclei, and manual code review, including SAST, DAST, and mobile testing solutions.
  • Tunes tools to reduce false positives and ensures findings are actionable and developer-friendly.
  • Integrates automated security testing seamlessly into CI/CD pipelines and developer workflows.
  • Demonstrated Ability to Lead Threat Modeling & Secure Design
  • Conducts structured threat modeling sessions using frameworks such as DREAD, PASTA, and STRIDE to identify and assess design-level risks.
  • Translates threat model outputs into clear, prioritized security requirements and architectural controls.
  • Applies deep understanding of common threat patterns, including OWASP Top 10, API security, mobile, web, and AI-related risks.
  • Strong Capability in Vulnerability Management & Remediation Support
  • Manages application vulnerabilities end to end, from identification through remediation verification and closure.
  • Prioritizes vulnerabilities based on technical severity, exploitability, and business impact.
  • Partners closely with engineering teams to guide remediation efforts and reduce recurring issues.
  • Track Record of De

Benefits

Vision insurance

Additional Information

About Addi We are a leading financial platform, building the future of payments, shopping, and banking-a world where consumers and merchants can transact effortlessly, grow together and where we create abundance and generate pride in them. Today, we serve over 2 million customers and partner with more than 20,000 merchants, making Addi Colombia's fastest-growing marketplace. We provide banking solutions (deposits, payments, unsecured credit) and commerce services (e-commerce, marketing) using state-of-the-art technology, bridging the financial gap for millions and redefining how people experience financial freedom. As the country's leading Buy Now, Pay Later provider, we have secured regulatory approval to operate as a bank, unlocking even greater opportunities for our customers. In the past year, we have also achieved profitability, reinforcing the strength of our business model and our ability to scale sustainably. Our mission has earned the trust of world-class investors, including Andreessen Horowitz, Architect Capital, GIC, Goldman Sachs, Greycroft, Monashees, Notable Capital, Quona Capital, Union Square Ventures, Victory Park Capital, and more, who back our vision for the future. With their support, we are not just growing-we are transforming Latin America's financial ecosystem and shaping the next generation to shop, pay, and bank in Colombia. But what truly sets us apart is how we build. We are a conscious company, driven by deep experience in scaling technology, services and products, and we live by our values every day.


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at addi? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect