Reap

Security Engineer, Application Security

Reap  •  Singapore, SG (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

About Reap

Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.

With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.

Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.

Founded in 2018

Security at Reap

Reap builds financial connectivity for a multi‑rail world-traditional finance, stablecoins, and real‑time payments. Security is foundational to that mission. We're looking for a pragmatic engineer who can turn regulation into robust systems, and complex threats into clear controls. You'll partner with Engineering, Risk, and Operations to keep value moving safely, globally, and 24/7.

Your Mission

During our acquisition by Payward/Kraken, their due diligence team found a race condition vulnerability in our product. We found it second. That is not the position we want to be in going forward.

As our Application Security Engineer, you will embed security inside the engineering process rather than bolting it on afterwards. You will own our secure SDLC, build the tooling that catches vulnerabilities in the pipeline before they ship, run threat modelling sessions with our engineering squads, and manage our bug bounty programme.

This is a builder role that works inside the engineering team, not above it.

What You Will Do

• Build and own the application security programme: secure coding standards, developer security training, security review gates in the engineering workflow, and the SAST/DAST/SCA tooling that enforces them in CI/CD.

• Lead threat modelling for new product features, API integrations, and significant architectural changes. Run STRIDE-based sessions with engineering squads who have not done this before.

• Do security-focused code reviews for the areas that matter: authentication, authorisation, payment flows, cryptographic operations, and external API integrations.

• Own our dependency and open source software security: scan, assess, and enforce our OSS usage policy.

• Run developer security education: OWASP Top 10, OWASP API Top 10, a security champions network, and practical sessions that engineers actually find useful.

• Manage penetration testing engagements end-to-end: scope, vendor, findings, and remediation verification.

• Own our responsible disclosure policy and manage our bug bounty programme once it launches.

Your Superpowers

• You have improved an application security programme inside an engineering organisation. You know

what the before and after looks like, and how to get engineering buy-in for both.

• Hands-on SAST/DAST/SCA pipeline experience. Semgrep, CodeQL, Checkmarx, SonarQube, or

equivalent. You have configured these in CI/CD, not just run them on demand.

• You can do threat modelling with engineers who have never done it. STRIDE or PASTA. You facilitate,

not lecture.

• Secure code review in at least two languages. JavaScript/TypeScript, Python, Go, or Rust. You can read code and find the vulnerability, not just run a scanner.

• Application penetration testing fundamentals. OWASP Top 10 and API Top 10 in practice. You know

how authentication and authorisation get broken.

• PCI DSS secure coding requirements. We handle payment card data. You know what that means for

development.

Nice to Have

• CSSLP, GWEB, or OSCP certification.

• Crypto or DeFi application security experience.

• Bug bounty programme management experience.

• Experience with smart contract interaction security or exchange API security.

Why You Will Love It Here

• You are building the application security function at a fast-moving fintech from scratch, with direct access to engineering leadership.

• The race condition finding gave us a very specific brief: find things like that before the acquirer does. You will have a clear mandate.

• We use AI tools extensively. GitHub Copilot, Claude Code, and others are part of how we build. You will help make sure we build securely with them.

• Flexible remote work, global team, and a company that is growing fast.

Benefits you'll enjoy

  • A vibrant, inclusive work culture.

  • Annual leave to relax and recharge, plus public holidays.

  • Health insurance budget.

  • Be part of a fast‑growing global team.

  • Flexible remote work options.

  • Home office equipment budget.

  • Your own Corporate Reap Card-no more out‑of‑pocket spending.

About Reap

Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.

With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.

Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.

Founded in 2018 Coworkers 300+

Reap

About Reap

Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.

With stablecoin-enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross-border payments.

Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia. Founded in 2018 in Hong Kong, we have since expanded to a team of over 100 across the globe.

Industry
Unknown
Company Size
201-500 employees
Headquarters
Global, HK
Year Founded
2018
Social Media