Back to Signal
Dark HatchVouched 4 times by industry insiders

Application Security

PrincipalApplication SecurityRemoteMelbourne, VIC
$315k
Actively Looking

Quick Match Check

Company Size

Scale-up (100-1000)Enterprise (1000+)

Company Type

TechFintech

Key Skills

SAST/DAST/SCA Tools (e.g., Checkmarx, SonarQube, Snyk)Cloud Security (AWS, Azure)Container Security (Docker, Kubernetes)API SecuritySecure SDLC ImplementationThreat Modeling (STRIDE, DREAD)Python (for automation and tooling)DevSecOps Tooling (e.g., GitLab CI/CD, Jenkins)

Ricki from CyberSec People will make the introduction

Skills Assessment

1st PrinciplesCode BiasTech DepthCuriosityWar Stories9.09.09.09.09.0
1st Principles9/10

Breaks down complex problems into fundamental truths and builds solutions from the ground up

Code Bias9/10

Prefers building and shipping code over meetings and documentation

Tech Depth9/10

Deep technical expertise across security domains, tools, and architectures

Curiosity9/10

Constantly learning, experimenting, and staying ahead of emerging threats

War Stories9/10

Battle-tested experience solving real-world security incidents and challenges

Profile Summary

A Principal Application Security Engineer with over a decade of experience driving secure development practices within high-growth tech environments like Airwallex. They excel at designing and implementing scalable application security programs that empower development teams to build secure-by-design software. This individual is passionate about shifting left and embedding security controls directly into the SDLC.

Problems Solved

  • Architected and deployed a custom SAST pipeline across 500+ microservices, reducing critical vulnerabilities found in production by 45% within 12 months at a major fintech.
  • Led the integration of DAST into CI/CD for over 150 applications, resulting in a 70% decrease in high-severity web application findings reaching UAT.
  • Developed and delivered bespoke secure coding training for 300+ engineers, improving developer-fixed security defect rates by 55% and significantly reducing security team's manual review burden.

What They Build

They build robust application security frameworks, automated security testing tools, and developer-centric security pipelines. Their focus is on creating scalable solutions that integrate seamlessly into existing development workflows, fostering a culture of security ownership among engineering teams.

Mission & Values

Driven to help teams build security into the development lifecycle. Believe in shifting left and empowering developers to write secure code.

Areas of Growth

LeadershipStrategic ThinkingTeam Building

Open to

Principal Application Security RoleSecurity LeadershipTechnical Architecture