About this role
Join our highly skilled team — breaking new ground and shaping the future of retail. We dare to dream big, we have the courage to keep raising the bar, and we're committed to being a force for good in retail—helping both established and fast-growing brands meet the ever-changing expectations of their customers.
Sitoo is a fast-growing technology company exploring how far we can take innovation to deliver the world's best Unified Commerce Platform and Point of Sale. Our technology is used in more than 20 countries—a number that keeps growing thanks to our incredible team. And we have no intention of slowing down. Are you the Application Security Engineer we're looking for?
Your mission at Sitoo
As a Application Security Engineer at Sitoo, you will work closely with our CISO, Senior Security Engineer, and engineering teams to support the secure development side of our platform. You will play a vital, hands-on role in securing our application code, repositories, and dependencies. You will take direct ownership of our application-level vulnerability backlog across our GitHub repositories, ensuring code fixes are triaged, released, and compliant with our SOC 2 SLA targets. By pairing a passion for security with an eagerness to learn, you will help triage findings, maintain CI/CD security gates, and empower our developers to safely leverage AI-assisted coding tools.
What you will do
- Actively track, prioritize, and remediate application and dependency vulnerabilities (Dependabot, Aikido) across ~184 active GitHub repositories to hit strict SOC 2 SLA targets.
- Assist development teams with code-level security updates across npm, pnpm, Go, Ruby, Python, Dockerfiles, and GitHub Actions.
- Help investigate and resolve breaking dependency upgrades, CI failures, and build issues caused by security updates.
- Track merged security fixes through the release lifecycle to ensure they are successfully deployed and validated in production.
- Contribute to improving repository-level security workflows, automated scanning, and CI/CD security gates.
- Learn, help define, and monitor security guardrails for the safe use of AI-assisted development tools in product engineering.
- Collaborate closely with our Senior Cloud & Infrastructure Security Engineer to escalate complex code or architectural risks while continuously growing your technical security expertise.
What you'll bring to the table
- Foundational knowledge of application security concepts, secure coding practices, and common vulnerabilities (OWASP Top 10).
- Familiarity with at least one programming language (such as Python, Go, Ruby, or JavaScript/TypeScript) and a hands-on drive to test PRs, update libraries, and fix build breakages.
- Basic understanding of version control (GitHub), repository management, and CI/CD pipelines.
- A proactive, problem-solving mindset with a genuine enthusiasm for clearing security technical debt and learning modern AppSec practices.
- Interest in AI-assisted development and a basic awareness of AI-related code security risks (e.g., hallucinated packages, unsafe generated patterns).
- Confident, clear communication skills to collaborate effectively across development teams and foster a culture of shared security ownership.
- Professional English, both verbal and written.