Description
Job Summary:
The DevSecOps Engineer (Application Security) will integrate security into the SDLC, promote a shift-left culture, and lead vulnerability management.
Key Highlights:
1. Integrate security into the software development lifecycle
2. Promote secure coding practices
3. Participate in threat modeling and purple team exercises
Hello! We are Cashea, and our mission is to restore Venezuelans' access to credit through a **BNPL** (buy now, pay later) business model.
Since our launch in 2022, we have dedicated ourselves to advancing **financial inclusion**. Today, we serve over 9 million active users — both consumers and merchants — and have become a trusted brand in Venezuela, winning the hearts and minds of people.
#### **Role Summary**
The DevSecOps Engineer (Application Security) is responsible for integrating security across the entire software development lifecycle (SDLC), promoting a shift\-left culture alongside engineering teams. They design and implement secure pipelines, integrate SAST, SCA, and DAST tools, lead vulnerability management initiatives, and collaborate on threat modeling for the company’s applications and services, adopting a purple team mindset focused on continuous collaboration between defensive and offensive efforts.
#### **Responsibilities**
* Design, implement, and maintain integration of SAST, SCA, and DAST tools into CI/CD pipelines.
* Define and standardize the security SDLC, including controls at design, development, testing, and deployment stages (security gates).
* Configure and maintain GitHub Actions workflows to automate security checks, code quality assessments, and compliance verification.
* Collaborate with development teams to identify, prioritize, and remediate vulnerabilities promptly, leading vulnerability management projects.
* Promote *secure coding* practices, secure code reviews, and the use of secure design patterns.
* Participate in threat modeling activities for new features, APIs, and services.
* Develop scripts and automations (in Python or another language) to orchestrate security tools, generate reports, and build dashboards.
* Support teams in adopting containers and orchestrators (Docker, Kubernetes) with a focus on security best practices.
* Collaborate with infrastructure and cloud teams to apply *hardening* and security controls in GCP and AWS.
* Participate in *purple team* exercises alongside the offensive team to continuously improve controls and threat detection.
#### **Requirements**
* Prior experience in application security and/or DevSecOps.
* Experience with GitHub and GitHub Actions (pipeline configuration, secrets management, branch protections).
* Practical knowledge and hands-on experience with SAST, SCA, and DAST tools.
* Solid understanding of CI/CD and how to integrate security controls without impeding development velocity.
* Strong familiarity with OWASP (Top 10, OWASP ASVS, and related guidelines).
* Experience working with Docker and Kubernetes (deployment, basic configuration, security best practices).
* Proficiency in Python or at least one programming language used by the company.
* Knowledge of cloud security services and controls (ideally GCP and AWS).
* Ability to communicate technical risks to non-technical audiences and coordinate across multiple teams.
#### **We Value**
* Experience in fintech or regulated industries.
* Experience designing and improving vulnerability management processes (SLAs, metrics, dashboards, reporting).
* Experience with Infrastructure as Code (Terraform, CloudFormation, etc.) and security-as-code concepts.
* Prior experience conducting threat modeling for APIs, microservices, and distributed architectures.
* Relevant certifications (e.g., AWS/GCP Security, CSSLP, DevSecOps, or others) — not mandatory.
* A purple team mindset and collaborative attitude toward development, operations, and offensive teams.
#### **Why You’ll Love Working at Cashea**
At Cashea, our work culture is built on trust and purpose. If you want to know why we’re the ideal place for you, here are our core values:
* **We don’t operate on autopilot.** Everything we do and share — internally and externally — is intentional. We’re passionate about creating ideas with full awareness of their impact on our users.
* Your creativity and curiosity are your most valuable assets.
* **Your voice matters.** We listen and create space for ideas and feedback. Everyone belongs here; what matters to you matters to us.
* **We value transparency.** Clarity keeps us connected and grounded.
* Last but not least, **we focus on real impact.** Everything we do is aimed at making a difference.
Do you identify with this? **Apply now — we’d love to meet you!**