Remote job
Senior Application Security Engineer
Job details
About this role
Role overview A senior application security engineer is needed to lead initiatives that protect customer-facing products, internal tools, APIs, and AI-enabled systems. The role partners closely with product, platform, infrastructure, data, and engineering teams to embed security throughout the software development lifecycle without slowing the pace of innovation. It suits someone who can drive complex technical projects from planning through remediation in an environment that blends regulated financial software with generative AI.
Responsibilities - Lead application security projects end to end, coordinating contributors and dependencies to deliver durable risk reductions - Run threat modeling and security architecture reviews for customer-facing applications, APIs, distributed services, and AI/ML systems - Design and ship secure-by-default controls such as coding standards, API protections, automated tests, CI/CD safeguards, and secrets management - Identify systemic vulnerabilities with engineering partners, weigh remediation options, and ensure high-risk issues are resolved effectively - Build automation and services that improve vulnerability detection, prioritization, validation, and prevention while reducing developer friction - Assess security of AI-enabled products and developer workflows, including GenAI integrations, agentic systems, model inputs and outputs, sensitive-data handling, and access boundaries - Provide technical leadership during high-severity application security incidents, driving root-cause analysis and follow-up improvements - Mentor engineers, contribute to design and code reviews, and document reusable patterns that strengthen appsec practice across the org
Requirements - 5+ years in security engineering, software engineering, or a related technical role, including 2+ years focused on application or product security - Hands-on experience building reusable appsec guardrails, platforms, or automation adopted by multiple engineering teams - Familiarity with modern frontend frameworks, REST or GraphQL APIs, microservices, and event-driven architectures - Working knowledge of AI/ML and GenAI risks such as prompt injection, insecure tool use, sensitive-data exposure, and model supply-chain threats - Experience using risk metrics or program data to prioritize work and demonstrate improvement - Ability to partner with Legal, Risk, Compliance, or Audit teams in a regulated environment - Security certifications such as CISSP, CSSLP, CCSP, or AWS Security Specialty, or equivalent practical expertise
Nice to have - Experience mentoring engineers and elevating quality through design and code reviews
Benefits and work setup - Anticipated base salary range of $166,900 to $230,900 USD - Remote-first with expectations to collaborate in person during team onsites and planning sessions - Eligibility for hires across the US and Canada (excluding Quebec), operating primarily on East/West coast time zones - Comprehensive medical, dental, vision, and wellness coverage; health savings account contributions where eligible - 401(k) or group retirement plan with company match up to $15,000 annually, plus an employee stock purchase plan - Equity grants vesting quarterly, plus performance-based bonus opportunities - Paid time off, sick leave, company holidays, and paid family and parental leave - Life and disability insurance, employee assistance program, financial wellness resources, and annual wellness and productivity allowances