How to apply for Senior Engineer, Security

Taptap Send

About Taptap Send

Taptap Send is a mobile app for low-cost international money transfers to Africa, Asia, and Latin America. It operates in a space where security and trust directly affect whether people can move money safely. If you want your security work to have a clear real-world effect, this is a place where that connection is direct.

About the role

This is a find-and-fix security engineering role inside the Platform Engineering team. You will not just report vulnerabilities; you will write the Terraform and application changes that close them. You will work with the CISO, who sets the security agenda and helps you push fixes through other teams when remediation stalls.

A typical day

A typical day might involve reviewing new Snyk or Prowler findings, writing Terraform to close an IAM or network boundary issue, and checking in with another team on a fix you are driving. You might also run a threat model session for a new service or prepare for the annual external penetration test by testing your own environment first. The exact daily rhythm is not described in the job details, so ask about team ceremonies and on-call expectations in your interview.

Who Taptap Send is looking for

  • You have hands-on AWS security experience across IAM, least privilege, network boundaries, secrets management, and logging coverage.
  • You can write Terraform and application code to fix vulnerabilities yourself, not just hand off findings.
  • You have run vulnerability management programs using tools like Snyk, Prowler, or ASV findings and driven them to verified fixes.
  • You have done penetration testing, threat modelling, and security reviews early enough to change a design before it ships.

Tips for this application

  • Lead with concrete examples where you wrote the fix, not just found the issue. Name the Terraform or application change you made.
  • Show experience with the exact tooling mentioned: Snyk, Prowler, AWS IAM, WAF, and ASV findings. Use those names in your resume.
  • Describe a time you drove a fix owned by another team to completion. This role explicitly requires that cross-team push.
  • Mention any work with payment or custody provider integrations, since the job description calls those out specifically.
  • Keep your application focused on infrastructure and application security engineering, not compliance or policy-only work.

What to cover in your cover letter

['A specific vulnerability you remediated end-to-end, including the Terraform or code you wrote to close it.', 'Your experience defining and enforcing security baselines as code for new services.', 'A time you ran penetration testing or threat modelling that changed a design before launch.', 'How you have worked with a CISO or security leader to escalate and unblock remediation across teams.']

Draft a cover letter

Research before applying

  • Read Taptap Send's public materials on how the money transfer product works and which countries it serves.
  • Look up what Snyk, Prowler, and ASV findings are if you are not already familiar with them, since they are named in the job description.
  • Check Taptap Send's engineering blog or public posts to understand their AWS and platform setup, if available.
  • Find out who the CISO is and any public talks or posts they have given about Taptap Send's security agenda.
Taptap Send website

Likely interview topics

Based on the job description, expect questions about:

  • Walk through a vulnerability you found in AWS infrastructure and the exact Terraform change you wrote to fix it.
  • How do you define and enforce least privilege across IAM in a growing AWS environment?
  • Describe your process for running vulnerability management from Snyk, Prowler, or ASV findings through to verified fixes.
  • How do you approach threat modelling for a new service that integrates with a payment or custody provider?
  • Tell us about a time a fix belonged to another team and remediation stalled. How did you drive it to completion?
Practise interview questions

Common mistakes to avoid

  • Applying as a compliance-only or policy-only security person. This role requires writing Terraform and application code.
  • Listing tools without showing remediation outcomes. The job description stresses verified fixes, not just findings.
  • Ignoring the cross-team aspect. This role expects you to drive fixes owned by other teams, with CISO support.

Deadline

No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.