About the job
Join Verto as a Product Security Engineer
At Verto, we are dedicated to transforming global finance and empowering businesses in Emerging Markets to thrive on the world stage. Founded by visionary British-Nigerian entrepreneurs, Ola Oyetayo and Anthony Oduu, our African roots afford us a deep understanding of the unique challenges businesses encounter with cross-border payments. From illiquid currencies to exorbitant fees and sluggish transactions, we tackle these issues head-on, focusing on Africa as a pivotal area of impact.
Initially designed as a foreign exchange solution for the Nigerian Naira, our platform has matured into a leading service, facilitating seamless transactions worth billions of dollars for thousands of businesses annually. We believe that success in business should not be dictated by geography. Our mission is to provide equal access to streamlined payment and liquidity solutions that are commonplace in developed markets.
Supported by premier investors such as Y-Combinator, Quona, and MEVP, Verto has earned accolades including the Milken-Motsepe Prize and recognition on CNBC's list of the fastest growing UK companies, as well as the Deloitte Fast 50 and Sifted’s fastest-growing UK tech firms. We are committed to creating a future where cross-border payments are seamless and efficient.
Become part of our journey to reshape global finance!
Role Overview
As a Product Security Engineer, you will play a vital role in enhancing Verto's application security through comprehensive penetration testing of Web, API, and mobile platforms. You will also be responsible for integrating security automation into our development workflows, thereby significantly reducing vulnerabilities and cultivating a security-first culture. We are looking for a dedicated Security Engineer (DevSecOps + Pentesting) who is enthusiastic about modern application security and testing.
Key Responsibilities
Perform detailed penetration testing on Web, API, and Mobile (iOS & Android) applications.
Conduct secure code reviews and provide actionable remediation guidance, particularly for Node.js applications.
Automate security testing processes and integrate security tools into CI/CD pipelines.
Write scripts to automate routine security tasks.
Develop and implement industry-standard security best practices (e.g., OWASP Top 10, SANS 25).
Continuously monitor and enhance AWS cloud security configurations.

