Transak

Application Security Engineer

Full-Time in Austria - Information Security - €120,000 – €140,000 / year

About the company:

Our mission is that "Any financial application can onboard any user, anywhere in the world, in 1 click." Transak provides onboarding to financial applications through authentication, KYC, risk checks, and fiat on/off ramps. This is a next generation of infrastructure for the next generation of financial applications that are built on blockchain and stablecoin rails. Our API and widget-based solutions are used by top partners like MetaMask, Coinbase, Ledger, and Trust Wallet to enable seamless onboarding of over 10 million users across over 450 active applications.

We have raised over $37M from top-tier investors including Consensys, Tether, and Animoca Brands.

About the Role:

Transak's product is its attack surface: a widget, a set of APIs and the flows that move customer funds and customer identity data, built on a Node.js and Python stack.

This is a founding role in a small security function, reporting to the CISO. You will own application and product security end to end and build the capability rather than operate an existing one - there is no established programme to inherit and no team to delegate to. Transak operates under MiCA and DORA in the EU with further regulated entities in MENA and the US, so what you build needs to be evidenced as well as effective.

What You'll Be Doing

As Transak's first dedicated application security hire, you will safeguard our applications and development lifecycle through proactive security integration and engineering excellence. Your responsibilities include:

  • Partner with engineering teams to embed security into the software development lifecycle, from design through to deployment.
  • Conduct security code reviews, threat modelling sessions and architecture reviews for the flows that move customer funds and customer identity data.
  • Select, implement and tune SAST, DAST and SCA solutions to identify vulnerabilities early in the development process.
  • Build and maintain application security testing automation within CI/CD pipelines, with severity-based gating that engineering can plan around.
  • Own the software supply chain: an SBOM per deployable service, dependency and provenance standards, and approved base images.
  • Build and run a consolidated vulnerability register - triage, prioritise by real exploitability, assign owners and drive remediation to verified closure.
  • Perform penetration testing and vulnerability assessments of web applications, APIs and mobile applications.
  • Own the external penetration testing programme, scoping engagements from the threat model and enforcing re-testing.
  • Develop secure coding standards, reusable security components and role-based training for engineering teams.
  • Create a security champions programme so that security scales beyond one person.
  • Run the bug bounty programme and coordinate with external security researchers.
  • Research emerging application and supply chain threats, and integrate defensive measures into the security architecture.
  • Evidence secure development and vulnerability management controls for DORA, MiCA, SOC 2 and ISO 27001.

What We're Looking For

Core Experience:

  • 5+ years as a security engineer, focused on application or product security.
  • Deep understanding of web and API security - OWASP Top 10, authentication and authorisation, session management.
  • Hands-on experience with security testing tools such as Burp Suite, OWASP ZAP, Snyk, Aikido etc.
  • Strong programming skills in a modern language, ideally JavaScript / Node.js or Python.
  • Experience integrating security tooling into CI/CD pipelines such as GitLab CI, Jenkins or GitHub Actions.
  • Practical software composition analysis and SBOM experience, with an understanding of modern supply chain attacks against npm and PyPI.
  • Vulnerability management ownership: a register, named owners, enforced SLAs and reported adherence.
  • Threat modelling applied to real business flows, and secure architecture patterns for APIs and distributed systems.
  • Solid understanding of cryptography, secrets management and identity and access management.
  • Excellent communication skills, able to translate security concepts for an engineering audience.
  • Comfortable building a capability from nothing rather than inheriting a mature programme.

Bonus:

  • Hands-on security testing of cryptocurrency or blockchain infrastructure and applications is a major bonus.
  • Fintech, payments or custody experience, particularly anything touching wallets or settlement.
  • Supply chain security depth: SBOM formats, build provenance, SLSA, and prioritisation using EPSS and the CISA KEV catalogue.
  • Knowledge of compliance frameworks such as DORA, MiCA, SOC 2, ISO 27001 or GDPR.
  • Managing an external penetration testing vendor or a bug bounty programme.
  • Certifications such as OSCP, OSWE, GWAPT or CSSLP.

Why join us

  • Equity options so you can share in the success of the company
  • A fast-moving, fun, and international company made up of skillful team players
  • Transparent, Open, and Collaborative work environment
  • A competitive compensation package and comprehensive benefits offering