Staff Application Security Engineer

Posted 1ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Staff Application Security Engineer owning AppSec strategy, tooling, and secure SDLC practices. Protecting Beyond Finance’s debt-relief fintech products across applications, cloud infrastructure, and CI/CD.

Responsibilities:

  • Lead and evolve the company's application security strategy, roadmap, and day-to-day operations
  • Serve as the primary AppSec partner for development teams working on Ruby on Rails web apps, React Native mobile apps, Python, and Go projects
  • Provide security guidance during design, development, and code review
  • Drive secure coding practices and threat modeling across engineering teams
  • Manage and optimize GitHub Advanced Security, Invicti, Hadrian, AppDome, and Cloudflare WAF
  • Improve security-tool automation and CI/CD integration
  • Build secure development standards, playbooks, and training materials
  • Partner with engineering during sprint planning and feature design to address risks proactively
  • Conduct security reviews, code assessments, and vulnerability triage
  • Work with DevOps on secure AWS infrastructure deployments and configurations
  • Harden ECS, IAM, networking, and supporting cloud services
  • Design and maintain secure CI/CD workflows
  • Lead or support investigation and remediation of application-level vulnerabilities
  • Monitor, prioritize, and track SAST, DAST, and ASM findings
  • Collaborate with engineering on timely and effective remediation

Requirements:

  • 8+ years of experience in Application Security, Product Security, or related engineering roles
  • Strong understanding of secure coding practices, OWASP Top 10, and modern SDLC
  • Experience with cloud-native applications, ideally AWS
  • Understanding of SSL certificates and cryptographic key management
  • Hands-on experience with SAST, DAST, WAFs, and/or mobile application security tools
  • Ability to partner with developers and influence secure design decisions
  • Familiarity with GitHub-based workflows and CI/CD pipelines
  • Development experience with Ruby on Rails or similar dynamic languages (nice to have)
  • Knowledge of AWS ECS/EKS, container security, secrets management, and infrastructure-as-code with CloudFormation or Terraform (nice to have)
  • Experience building or maturing an AppSec program from early stages (nice to have)
  • SOAR automation and scripting experience (nice to have)
  • Experience in a PCI-compliant environment with annual reporting needs (nice to have)

Benefits:

  • Considerable employer contributions for health, dental, and vision programs
  • Generous PTO, paid holidays, and paid parental leave
  • 401(k) matching program
  • Merit advancement opportunities
  • Career development & training
  • Annual bonus eligibility
  • Uplifting, collaborative work environment
  • Community, connection, and belonging across the organization