Remote job
Security Engineer - AppSec
Job details
About this role
Role overview
A global stablecoin payments platform is hiring an application security specialist to set the quality bar for every non-blockchain security finding across APIs, backend services, cloud infrastructure, and money-moving paths. The role sits on a small security engineering team that runs an AI-driven red team against code and cloud, gates pull requests before merge, and authors configuration baselines. The position calls for someone who can push back on engineering decisions while keeping collaborative relationships intact.
Responsibilities
- Triage red team findings before they reach engineers: reproduce issues, cut false positives, assign severity, and produce fix tickets clear enough to act on without a meeting; improve the scoring that grades findings - Harden backend services and APIs, especially the money-moving paths, and frequently write the fix personally - Own edge defenses including DDoS protection, rate limiting, WAF rules, and abuse controls - Author configuration baselines for cloud, code, and SaaS environments, then convert them into automated enforcement checks - Grow automated PR security gating so more issues are blocked before merge - Maintain attack surface coverage and run architecture reviews for new and high-risk systems - Evaluate, test, and select security tools, retiring any that fail to justify their cost
Requirements
- Four or more years in application security, product security, or security-focused backend engineering - Demonstrated ownership of security decisions, including the ability to challenge a senior engineer's design while preserving the working relationship - Ability to read unfamiliar TypeScript or Node.js codebases and identify the bug that actually matters, separating real issues from noise - Hands-on cloud security experience (GCP preferred), Terraform, and edge defense configuration such as WAFs and rate limiting - Experience running threat models or architecture reviews and conducting tool bake-offs - Preference for shipping enforcement checks over producing documentation, with heavy AI tool use applied with appropriate skepticism
Nice to have
- Fintech, payments, or card issuing background, with PCI DSS familiarity a plus - Pentest, bug bounty, or red team experience - Building security scanners, static analysis rules, or LLM-based review tools - AI security for autonomous agents and agentic payments, or corporate security paired with IT
Benefits and work setup
- Unlimited paid time off with a 10-day annual minimum - Flexible workplace supporting home, office, or hybrid work, plus a home office setup stipend for new hires - Health, dental, and vision plans heavily subsidized, with company-paid life insurance - 401(k) retirement plan with a 4% company match - Equity option plan for all employees - Monthly health and wellness stipend for eligible expenses such as gym memberships, massages, or acupuncture - Office-based lunch and dinner via a meal credit - Periodic team and company summits, including domestic and international offsites