About Addi
We are a leading financial platform, building the future of payments, shopping, and banking—a world where consumers and merchants can transact effortlessly, grow together and where we create abundance and generate pride in them. Today, we serve over 2 million customers and partner with more than 20,000 merchants, making Addi Colombia’s fastest-growing marketplace.
We provide banking solutions (deposits, payments, unsecured credit) and commerce services (e-commerce, marketing) using state-of-the-art technology, bridging the financial gap for millions and redefining how people experience financial freedom. As the country’s leading Buy Now, Pay Later provider, we have secured regulatory approval to operate as a bank, unlocking even greater opportunities for our customers. In the past year, we have also achieved profitability, reinforcing the strength of our business model and our ability to scale sustainably.
Our mission has earned the trust of world-class investors, including Andreessen Horowitz, Architect Capital, GIC, Goldman Sachs, Greycroft, Monashees, Notable Capital, Quona Capital, Union Square Ventures, Victory Park Capital, and more, who back our vision for the future. With their support, we are not just growing—we are transforming Latin America’s financial ecosystem and shaping the next generation to shop, pay, and bank in Colombia.
But what truly sets us apart is how we build. We are a conscious company, driven by deep experience in scaling technology, services and products, and we live by our values every day.
About The Role
This is where you come in. Below, you’ll find what this role is all about—the impact you’ll drive, the challenges you’ll tackle, and what it takes to thrive at Addi. If you’re ready to be part of something big, keep reading.
What’s The Mission You’ll Drive
Design, implement, and operate the Secure Software Development Lifecycle (SSDLC) end to end, embedding security requirements, threat modeling, testing, and vulnerability management into the development process to reduce application risk at scale.
What You Will Do
What We’re Looking For
Hands-on Expertise in Application Security Testing & Tooling
Experienced in using and maintaining application security tools such as Burp Suite, MobSF, trufflehog, Nuclei, and manual code review, including SAST, DAST, and mobile testing solutions.
Tunes tools to reduce false positives and ensures findings are actionable and developer-friendly.
Integrates automated security testing seamlessly into CI/CD pipelines and developer workflows.
Demonstrated Ability to Lead Threat Modeling & Secure Design
Conducts structured threat modeling sessions using frameworks such as DREAD, PASTA, and STRIDE to identify and assess design-level risks.
Translates threat model outputs into clear, prioritized security requirements and architectural controls.
Applies deep understanding of common threat patterns, including OWASP Top 10, API security, mobile, web, and AI-related risks.
Strong Capability in Vulnerability Management & Remediation Support
Manages application vulnerabilities end to end, from identification through remediation verification and closure.
Prioritizes vulnerabilities based on technical severity, exploitability, and business impact.
Partners closely with engineering teams to guide remediation efforts and reduce recurring issues.
Track Record of Delivering Security Assessments, Pentesting & Adversarial Testing
Brings 3+ years of experience coordinating and supporting penetration tests, security assessments, and red team or adversarial exercises.
Analyzes assessment outcomes to identify root causes and drive measurable security improvements.
Ensures findings are systematically tracked, remediated, and incorporated into continuous improvement cycles.
Experienced in Cross-Functional Collaboration & Developer Enablement
Acts as a trusted security partner to engineering teams, balancing risk management with delivery velocity.
Possesses hands-on development experience in at least one programming language (e.g., Java or Python) to enable practical, code-level guidance.
Communicates security risks clearly and pragmatically, contributes to secure coding education, and leverages AI to automate controls or expand security coverage.
Why join us?
How The Hiring Process Looks Like
We believe in a fast, transparent, and engaging hiring experience that allows both you and us to determine if there's a great fit. Here’s what our process looks like:
We value efficiency and respect for your time, so we aim to complete the process as quickly as possible. Our goal is to make this experience insightful and exciting for you, just as much as it is for us. Regardless of the outcome, we are committed to always providing feedback, ensuring that you walk away with valuable insights from your experience with us.
Trabajamos con personas que nos inspiran, que están en constante aprendizaje y que nos dan la oportunidad de aprender.
Nos preocupamos los unos por los otros profundamente y confiamos completamente en nuestros colegas.