Moniepoint Inc.
Banking, Finance & Insurance
Application Security Engineer
Share this role
About this role
Moniepoint Inc., Africa's leading all-in-one financial technology platform, is recruiting a highly skilled and analytical Application Security Engineer. Moniepoint powers the financial operations of over 20 million businesses and individuals monthly, handling over $250 billion in digital payment transaction value annually. As Nigeria’s largest merchant acquirer driving the majority of point-of-sale (POS) systems across the continent, maintaining an unyielding security infrastructure is paramount.
Operating in a fully remote framework within Nigeria, the Application Security Engineer will serve as a core technical gatekeeper across product clusters and development pipelines. You will embed secure-by-design architectures into product life cycles, architect robust DevSecOps guardrails, and collaborate directly with engineering teams to minimize vulnerabilities before code ever hits production. This mid-to-senior placement is designed for a software-engineer-turned-security-specialist ready to deploy highly resilient systems at an ecosystem scale.
Key Responsibilities-
Security Advocacy: Act as a central Security Champion across product cells, actively influencing design patterns and architectural decisions to prioritize systems protection from inception.
-
Threat Modeling & Architecture: Design comprehensive Secure-by-Design solutions, integrating threat modeling methodologies and rigorous security requirements directly into pre-development reviews.
-
CI/CD Pipeline Automation: Automate, promote, and enforce secure coding standards using CI/CD integrations, structural peer reviews, and technical development workshops.
-
Vulnerability Infrastructure Lifecycle: Spearhead the company's Vulnerability Management framework, overseeing automated identification, risk-based triaging, and systematic remediation tracking.
-
Security Baseline Management: Develop and maintain global internal security packages, including secure configuration baselines, hardcoded-safe code templates, and security scanning orchestration.
-
Penetration Testing: Conduct both hands-on and automated penetration testing engagements across staging, sandbox, and active production environments to expose edge-case application flaws.
-
Cross-Team Mentorship: Facilitate technical knowledge-sharing sessions, post-mortem feedback loops, and security briefings to continuously upgrade the engineering team's maturity model.
-
Core Experience: 3 to 5 years of dedicated, hands-on experience in Application Security (AppSec), DevSecOps, or highly similar technical ecosystems.
-
Engineering Foundation: A solid background as a Software Engineer with a specialized shift into cybersecurity. Having at least 2 years of direct operational experience inside a core engineering team is a major plus.
-
SDLC First Principles: Deep conceptual and operational understanding of the Secure Software Development Lifecycle (SSDLC) and secure-by-design engineering frameworks.
-
Technical Software Stack: High capability reading and auditing code blocks across Java, Python, and JavaScript, alongside a strong operational comfort level with core cloud fabrics (AWS, GCP, or Azure).
-
Security Tooling Matrix: Expert proficiency deploying and tuning security scanning technologies, including SAST, DAST, and SCA tools, alongside incident remediation workflows.
-
Offensive Engagements: Proven experience with infrastructure pentesting or red-team operations, showing a clear history of identifying and neutralizing complex application-level exploits.
-
Certifications & Extras (Plus): Possession of offensive security badges such as OSCP, OSCE, GXPN, or related credentials is a strong advantage. Practical experience handling container security and contributing to open-source security tools is highly valued.
-
Compensation: Attractive base salary alongside annual performance bonuses and corporate Employee Stock Options (ESOP).
-
Perks & Protection: Full health insurance layout, comprehensive pension plan matching, and corporate wellness coverage.
-
Workplace Culture: A human-first, remote workspace prioritizing continuous internal training, regular engineering tech talks, and open-knowledge ecosystems.
-
Hiring Pipeline: Expect a 4-stage review process consisting of a Recruiter screening call, a technical take-home assessment, a deep-dive Technical Lead interview, and a final Executive behavioural session.
This role accepts applications on an external page.