- Perform security reviews and code audits on internal services and applications, focused on common vulnerability classes (OWASP Top 10, injection, auth/session flaws, SSRF, insecure deserialization, etc.)
- Help integrate and tune SAST/DAST tools into CI/CD pipelines and triage their findings
- Support threat modeling for current features and services during design review
- Investigate and help remediate findings from pen tests or bug bounty reports
- Contribute to secure coding guidelines and help engineering teams fix root causes, not just symptoms
About Sugary :
We are a fintech in corporate and prepaid cards and run a voucher commerce gateway. Our engineering team comprises of hobbyist coders and ethical hackers so if you are super passionate with proven winnings then only we are a cultural fit !