Application Security Engineer (X Money)
$100k - $258k • Remote • Palo Alto, CA; Austin, TX; New York, NY; Washington, DC
Posted 6h ago
Job Location
Palo Alto, CA; Austin, TX; New York, NY; Washington, DC
Tech Stack
Remote Work Policy
Fully remote
Categories
Applied AI Engineer
About the job
We are seeking a skilled and innovative Application Security Engineer to join 𝕏 Money. In this role, you will protect the security and integrity of our payments and financial products throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and systems that move and hold customer funds. Experience securing fintech, payments, digital wallet, ledger, or similar high-value platforms, where fraud, abuse, and unauthorized transfers are a constant concern, is strongly preferred.
Responsibilities
- Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in financial applications.
- Design and implement secure coding guidelines and best practices for development teams.
- Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline.
- Perform threat modeling and risk assessments for payments, wallets, ledgers, and related product surfaces, and develop mitigation strategies for fraud, abuse, and unauthorized movement of funds or credits.
- Manage vulnerability tracking and remediation efforts, providing guidance to development teams.
- Manage the bug bounty program, including intake, triage, researcher communication, and coordinated disclosure.
- Support incident response activities related to application security.
- Stay current on emerging threats against financial and cloud-native systems, and continuously strengthen our controls.
- Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs).
- Design and implement agentic and LLM-based solutions that help detect, investigate, or prevent security problems.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, or a related field.
- 3-5 years of experience in application security, with a strong focus on code security practices.
- Experience in payments, money transmission, digital wallets, or related financial platforms.
- Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10).
- Proficiency in Python or Rust and experience with secure coding practices in these languages.
- Experience securing CI/CD pipelines and implementing DevSecOps practices.
- Familiarity with software supply chain security and SBOM generation tools.
- Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis.
- Experience securing payments, wallets, ledgers, or other high-value transaction systems, including controls against fraud, abuse, and integrity issues.
- Experience designing and implementing agentic and LLM-based solutions for security problems.
- Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences.
- Hands-on experience securing applications on AWS; familiarity with other cloud platforms is a plus.
- Relevant security certifications (e.g., BSCP, OSCP, OSWE).
- Experience managing bug bounty programs.
- Background in data privacy and compliance relevant to financial products and cloud-native applications.
- Experience with GitOps and infrastructure-as-code security.
- Experience building custom security tooling to enhance and automate security processes.
- Contributions to open-source security projects or tools.
Benefits
- Equity
- Comprehensive medical, vision, and dental coverage
- Access to a 401(k) retirement plan
- Short & long-term disability insurance
- Life insurance
- Various other discounts and perks