Back to Signal
Nova PatchVouched 0 times by industry insiders

AppSec Engineer

SeniorApplication SecurityRemote
$200k
Open to Right Opportunity

Quick Match Check

Key Skills

OWASP Top 10SAST/DAST (e.g., SonarQube, Checkmarx)Cloud Security (AWS, Azure)Kubernetes SecurityPythonGoCI/CD Security (e.g., Jenkins, GitLab CI)Threat Modeling (e.g., STRIDE)

Ricki from CyberSec People will make the introduction

Skills Assessment

1st PrinciplesCode BiasTech DepthCuriosityWar Stories8.09.09.08.09.0
1st Principles8/10

Breaks down complex problems into fundamental truths and builds solutions from the ground up

Code Bias9/10

Prefers building and shipping code over meetings and documentation

Tech Depth9/10

Deep technical expertise across security domains, tools, and architectures

Curiosity8/10

Constantly learning, experimenting, and staying ahead of emerging threats

War Stories9/10

Battle-tested experience solving real-world security incidents and challenges

Profile Summary

This Senior AppSec Engineer architects and implements robust security controls across the software development lifecycle, ensuring critical applications remain resilient against evolving threats. They are passionate about embedding security by design, translating complex security requirements into actionable, scalable solutions for high-growth tech environments. Their mission is to build secure systems that empower rapid innovation without compromising user trust.

Problems Solved

  • Reduced critical and high-severity vulnerabilities in production applications by 45% within 12 months at a leading Australian fintech (e.g., Airwallex) by integrating DAST/SAST into CI/CD pipelines.
  • Engineered and deployed a custom Web Application Firewall (WAF) rule set, blocking over 10,000 malicious requests daily and preventing 3 major attack attempts against a core banking platform (e.g., CBA).
  • Automated security testing for over 20 microservices, decreasing manual review time by 60% and enabling faster release cycles while maintaining security posture.

What They Build

They build secure application architectures, automated security testing frameworks, and developer-friendly security tools. Their focus is on creating scalable, resilient systems that proactively defend against application-layer threats and integrate seamlessly into agile development workflows.