Back to Signal
Quantum SparkVouched 4 times by industry insiders

Application Security

PrincipalApplication SecurityRemoteMelbourne, VIC
$315k
Actively Looking

Quick Match Check

Company Size

Scale-up (100-1000)Enterprise (1000+)

Company Type

TechFintech

Key Skills

SAST/DAST IntegrationThreat ModelingSecure SDLCKubernetes SecurityAWS SecurityPythonOWASP Top 10API Security

Ricki from CyberSec People will make the introduction

Skills Assessment

1st PrinciplesCode BiasTech DepthCuriosityWar Stories9.09.09.09.09.0
1st Principles9/10

Breaks down complex problems into fundamental truths and builds solutions from the ground up

Code Bias9/10

Prefers building and shipping code over meetings and documentation

Tech Depth9/10

Deep technical expertise across security domains, tools, and architectures

Curiosity9/10

Constantly learning, experimenting, and staying ahead of emerging threats

War Stories9/10

Battle-tested experience solving real-world security incidents and challenges

Profile Summary

A Principal Application Security Engineer with a strong track record of embedding security into high-velocity development pipelines. This builder champions a 'shift-left' philosophy, designing and implementing scalable security controls that empower developers to deliver secure software from inception. They are passionate about constructing robust application security programs that drive measurable improvements in security posture.

Problems Solved

  • Architected and deployed a custom SAST integration for a major Australian fintech (e.g., Airwallex), reducing critical vulnerabilities found in production by 45% within 12 months.
  • Led the remediation effort for a complex supply chain attack vector across 15+ microservices, mitigating the risk without impacting critical business operations.
  • Developed and rolled out a developer-centric security training program for 200+ engineers at a scale-up (e.g., Culture Amp), resulting in a 30% decrease in security-related pull request comments.

What They Build

This professional builds comprehensive application security frameworks, secure development lifecycle (SDLC) tooling, and automated security gates within CI/CD pipelines. Their focus is on creating developer-friendly security solutions that are both effective and efficient.

Mission & Values

Driven to help teams build security into the development lifecycle. Believe in shifting left and empowering developers to write secure code.

Areas of Growth

LeadershipStrategic ThinkingTeam Building

Open to

Principal Application Security RoleSecurity LeadershipTechnical Architecture