Bottomline
Business Payments and Cash Management
ApplicationSecurityEngineer
Neural analysis suggests this role is
optimal for Mid candidates.
“Application Security Engineer at Bottomline. Skills: Application Security, Penetration Testing, SAST, DAST. Orchestrate application penetration testing. Support application security scanning tools”
What You'll Achieve.
strengthening the organisation’s application security posture; identifying vulnerabilities; analysing security patterns; contributing to continuous improvement; proactively identify and reduce risk exposure
Industry & Context.
problem-solving skills; analytical; analyse vulnerabilities
What They're Looking For.
Must Have
Application Security, Penetration Testing, Secure Code Scanning, penetration testing techniques, application security scanning platforms, SAST, SCA, DAST, common vulnerability patterns, OWASP Top 10, modern environments, APIs, microservices, CI/CD pipelines, analytical skills, problem-solving skills, communication skills
Nice to Have
Veracode, Burp Suite, OWASP ZAP, risk-based management models, threat exposure management models, secure coding practices, OSCP, OSWE, GWAPT, GPEN, CEH, CSSLP, CISSP, CISM
What You'll Do.
Orchestrate application penetration testing
Support application security scanning tools
Analyse vulnerabilities
Support prioritisation
Provide guidance for remediation
Contribute to improving coverage
Support multiple projects
How You'll Work.
Team & Collaboration
Work closely with Product; Work closely with Engineering; Work closely with Security teams; Work with development teams
Communication Scope
communicate complex security risks clearly; communicate effectively
Full Job Description
Why Choose Bottomline? Are you ready to transform the way businesses pay and get paid? Bottomline is a global leader in business payments and cash management, with over 35 years of experience and moving more than $16 trillion in payments annually. We're looking for passionate individuals to join our team and help drive impactful results for our customers. If you're dedicated to delighting customers and promoting growth and innovation - we want you on our team! As an Application Security Engineer, you will play a critical role in strengthening the organisation’s application security posture by supporting our penetration testing and application code scanning programmes. This role is responsible for identifying vulnerabilities, analysing security patterns and behaviours, and contributing to the continuous improvement of secure development practices across the software lifecycle. You will work closely with Product, Engineering, and Security teams to proactively identify and reduce risk exposure, supporting our threat exposure management approach across all applications. The role requires strong technical expertise combined with the ability to communicate complex security risks clearly and effectively to both technical and non-technical stakeholders. Essential Functions and Responsibilities: Orchestrate application penetration testing across web, API, and service-based architectures Support application security scanning tools (SAST, SCA, DAST) and CI/CD pipeline integration Analyse vulnerabilities to identify patterns, behaviours, and root causes, not just individual findings Support prioritisation and provide guidance for remediation based on risk and threat exposure Contribute to improving coverage, consistency, and reliability of application security testing Support multiple projects and initiatives in parallel Required Experience & Qualifications 3+ years’ experience in Application Security, Penetration Testing, or Secure Code Scanning Hands-on experience with penetr
Applying for this Application Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Greenhouse
- Create a Greenhouse profile before applying — it saves time across multiple applications.
- Upload your resume as a PDF; the parser handles it better than Word.
- Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
- Enable email notifications to track application status in real time.
ANONYMOUS · UNFILTERED
What do employees actually say about Bottomline?
Real rants from real employees. Read before you apply.