About the company
Luno is the crypto investment app you can rely on, enabling you to buy, store and explore crypto securely. Weāre committed to putting the power of cryptocurrency in everyone's hands sensibly and responsibly.Since 2013, weāve helped millions of people around the world invest safely in crypto. We do this by cutting through the hype and supporting customers at every step of the way. All products and cryptocurrencies on our platform must first meet stringent legal, risk and technical security standards. We donāt do memecoins.Transparency is key for us. Luno stores all crypto on a 1:1 basis and we have rigorous processes in place so you can be confident your investment is secure. Weāre available in more than 40 countries around the world and we work closely with respective regulators in all of these markets to be fully compliant, as we believe this is the best way to help everyone, everywhere, invest safely.
Job Summary
Your mission will be:
šSupport and consult with product and engineering teams in the area of application security, including threat modelling and AppSec reviews šAssist teams in reproducing, triaging, and addressing application security vulnerabilities. šSupport and assist in managing our bug bounty program. šAuthor, share and contribute to documentation on application security processes, tooling and other resources to ensure collaboration and transparency within your own team and throughout the greater organisation. šDesign and implement continuous application security testing mechanisms to aid in assessing our security posture and furthermore, drive down the number of vulnerabilities and threats in our environment. šInform, support and empower our software engineers to strive towards becoming more vigilant, aware and capable secure coding practitioners. This includes developing structured and unstructured engagements such as, targeted and general training, one-on-one and one-to-many coaching/information sharing sessions and general enquiry handling around application security.
A little about you:
šExperience in vulnerability management and enhancing and/or contributing to the security within application source code. šExperience in securing CI/CD pipelines on Cloud platforms. Ideally AWS with the AWS Developer Associate certification being advantageous šDeep understanding of security best practices on technologies mentioned above šTeam player, willing to pitch in wherever needed šKeen interest in application security and vulnerability management šUnderstanding of the Software Development Lifecycle