Senior Application Security Engineer
Fancy helping to shape the future of FinTech?
We have always been innovators. In 1996 we were the first company to share exchange rate information, free of charge on the internet. Today, we are a world leading online trading group.
Join us to:
- Help build the future of online trading
- Be part of a culture driven by integrity and global impact
- Become part of an award-winning company - check out our full list of awards here
We are only as good as our people. Luckily, our people are the best. Join us!
How do we work?
We are looking for a Senior Application Security Engineer to join our global Team and help us "push security left" across our entire product ecosystem. At OANDA, we believe security is everyone's responsibility, so we focus on developer education, continuous automation and building defense-in-depth rather than just checking compliance boxes.
You will work directly with cross-functional engineering teams in hands-on coding engagements to demonstrate secure design principles in action. Operating across a modern, multi-language stack and cloud environments, you’ll tackle security challenges at every layer. From automating DevSecOps pipelines to pioneering AI security tooling, we foster a high-energy environment focused on continuous growth and partnership.
In this role, you will:
Lead & Advocate: Provide technical leadership in application security, conduct threat modeling, lead design reviews, and establish secure coding practices.
Build & Remediate: Directly build security-critical components and fix vulnerabilities across multiple languages (JS, Go, Python, C++, Java).
Apply Defense-in-Depth: Touch every layer of our stack — from system hardening and Terraform (IaC) cloud security to reviewing C++ code and applying modern cryptography/secrets management (PKI, hashing).
Automate DevSecOps: Implement static code analysis, fuzzing, composition analysis, to make security proactive and effortless for developers.
Threat Modelling: Develop and lead on Threat Modelling exercises to identify risk, threats and vulnerabilities in the development phase of our applications
Pioneer AI Security: Identify and implement best practices for secure AI development and AI security tooling.
Secure Supply Chains: Work with dev teams to identify, track, and remediate third-party library vulnerabilities and supply-chain risks.
What skillset you need, to be successful in this role:
2 - 5 years of relevant technical experience, with 1-2+ years focused specifically on application security / security engineering.
Expert-level knowledge of web application vulnerabilities (OWASP Top 10), attack vectors and secure code review.
Strong ability to develop in and navigate security pitfalls in at least one primary programming language (e.g., Python, Go, Java, C#, or JavaScript/C++).
Hands-on experience with modern testing tools (SAST, DAST, IAST, SCA, penetration testing frameworks).
Working knowledge of cloud platforms (AWS, Azure, or GCP), networking, databases, and containerized/IaC environments.
Ability to simplify complex security challenges and drive proactive solutions with urgency, high energy, and teamwork.
Nice to have:
Experience in Fintech / Financial Services (or familiarity with financial security threat models & regulations).
Hands-on experience writing Terraform (Infrastructure as Code) and managing cloud secrets.
Exposure to AI development frameworks, AI tooling security, or LLM vulnerability vectors.
Knowledge of industry compliance standards & privacy regulations (SOC2, ISO27001, NIST, GDPR).
Active involvement in the wider cybersecurity community (conferences, open-source security projects).
___
At OANDA, to help us efficiently process applications, we use AI-driven tools to help source and rank candidates based on professional experience and skills. While these tools provide recommendations, our recruitment process remains human-centric: all final shortlisting and hiring decisions are made by OANDA team. You have the right to request a human review of your application.
OANDA Global Corporation is a diverse and global team with offices around the world. We value the unique skills and experiences each individual brings to OANDA. We are committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide an inclusive and accessible environment for everyone. Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment and selection process, please let us know. We will work with you to provide as seamless a recruitment experience as possible.
Learn more about our culture here.
Review OANDA Privacy Policy and learn more about how we treat your personal data and protect your privacy.