JobVault never charges job seekers. Learn how to stay safe →
Back to all jobs
Technology
full time

Senior Application Security Engineer (all genders)

Distribusion TechnologiesRemote job

Salary

R60 000 – R70 000 per month

Job Type

full time

Posted

about 2 hours ago

Closing date

7 Nov 2026

Share:WhatsAppLinkedIn

Job Description

Distribusion Technologies, a frontrunner in the ground transportation technology sector, is seeking a seasoned Senior Application Security Engineer. This role operates remotely, offering a flexible working environment for the right candidate. Distribusion has established itself as the premier B2B marketplace for ground transportation, facilitating seamless online access from search to ticket purchase. Their innovative platform connects a vast network of bus, rail, and ferry operators across more than 70 countries with major online retailers, including prominent names like Google Maps and Booking.com. As one of the fastest-growing travel startups, backed by significant venture capital, Distribusion is poised for further expansion, especially following an $80 million Series C funding round.

About the Role

This is a critical position within Distribusion's engineering team, focused on embedding security into the core of their technology platform. The Senior Application Security Engineer will be instrumental in safeguarding the company's digital assets and ensuring the integrity of its B2B operations. The role demands a proactive and hands-on approach, collaborating closely with development and DevOps teams to identify, assess, and mitigate security vulnerabilities. The ideal candidate will not only possess deep technical expertise but also the ability to translate complex security concepts into actionable insights for both technical and non-technical stakeholders.

Key Responsibilities

The Senior Application Security Engineer will take ownership of several key security initiatives. A significant part of the role involves leading threat modeling sessions and conducting secure design reviews for high-risk changes, particularly those related to partner integrations and payment processing flows. You will be responsible for implementing, fine-tuning, and enforcing security gates within the GitLab CI/CD pipeline. This includes integrating and managing tools for Static Application Security Testing (SAST), Software Composition Analysis (SCA), secrets detection, and Dynamic Application Security Testing (DAST), all while striving to minimise any disruption to the development workflow.

Furthermore, you will serve as the primary technical point of contact for triaging, reproducing, and prioritising security findings that emerge from bug bounty programs, third-party penetration tests, and automated scanning tools. A hands-on approach is expected when working alongside the DevOps team to implement robust security measures on Google Cloud Platform (GCP). This includes enforcing organisational policies, establishing least-privilege IAM architectures, and configuring Cloud Armor for Web Application Firewall (WAF) and rate-limiting capabilities. Building a network of security champions across various engineering squads and leveraging automation, potentially including AI-assisted tooling, to scale code review processes will also be a key responsibility.

What They're Looking For

Candidates should bring a minimum of five years of experience in application security. Alternatively, three years of dedicated AppSec experience combined with a strong background in software engineering or web penetration testing will be considered. A proven track record of taking ownership and driving security initiatives to completion is essential.

Technical proficiency is paramount. The role requires the ability to read and write production-level code in languages such as Python, Go, TypeScript, or Ruby. A deep understanding of modern web frameworks, CI/CD pipelines, and containerisation technologies like Kubernetes is also necessary. Expertise in web and API security is critical, with specific knowledge of authentication and authorisation models (including OAuth2 and JWT), rate limiting strategies, tenant isolation techniques, and common web vulnerabilities such as Insecure Direct Object References (IDOR) and Cross-Site Scripting (XSS).

Strong foundational knowledge of cloud security, with a preference for GCP, is required. This includes an understanding of best practices for public exposure management, secrets hygiene, and effective WAF rule configuration. The ideal candidate will demonstrate a pragmatic approach to security, prioritising risks based on real-world impact and proposing practical trade-offs rather than insisting on unattainable perfection. Crucially, they must be adept at communicating complex security risks in a clear and concise manner to both engineering teams and leadership. Experience in securing high-volume, multi-tenant B2B APIs and familiarity with AI tooling for security triage and review would be considered advantageous.

In South Africa, roles like this, particularly those involving significant cloud security and application security expertise with a remote option, are highly sought after. Compensation can vary widely based on experience and the specific company's funding and stage, but senior-level security engineers in tech-focused companies often command competitive salaries, frequently ranging from R70,000 to R120,000+ per month. The growth path in application security typically leads to lead security architect, security management, or specialised consulting roles.

Requirements

  • You bring 5+ years in AppSec (or 3+ years plus a strong software engineering/web-pentesting background), with a track record of true ownership.
  • You read and write production code (Python, Go, TypeScript, Ruby, etc.) and deeply understand web frameworks, CI/CD, and Kubernetes.
  • You have deep knowledge of web and API security, specifically authentication/authorization models (OAuth2, JWT), rate limiting, tenant isolation, IDOR, and XSS.
  • You have strong cloud security fundamentals (GCP preferred), specifically regarding public exposure, secrets hygiene, and WAF rules.
  • You prioritize by real-world risk, propose trade-offs rather than demanding perfection, and communicate complex risks plainly to engineers and leadership.
  • Bonus Points: You have experience securing high-volume, multi-tenant B2B APIs and utilizing AI tooling to accelerate triage and review.

About the employer

D

Distribusion Technologies

Distribusion Technologies is a hiring organisation operating in Remote job within the technology sector. They are currently recruiting for the Senior Application Security Engineer (all genders) role advertised on this page. Visit the official application link for more about the company, its culture and the team you would be joining.

Interested in this role at Distribusion Technologies?

JobVault never charges job seekers to apply.

Apply Now

More Technology jobs

See all →

Get ready for your application

Free career guides written for South African job seekers.

Browse all career resources →