Назад
2 дня назад

Application Security Engineer (Fintech)

100 000 - 258 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Fintech): Protecting payment, wallet, ledger, and financial product systems across the software development lifecycle with an accent on code security, CI/CD pipelines, vulnerability remediation, and secure software supply chains. Focus on threat modeling high-value transaction systems, managing bug bounty and incident response activities, and building agentic and LLM-based solutions for security detection and prevention.

Location: Palo Alto, CA; Austin, TX; New York, NY; or Washington, DC

Base salary: $100,000–$258,000 USD per year

Company

xAI develops AI systems focused on understanding the universe and advancing human knowledge.

What you will do

  • Conduct code reviews, static analysis, vulnerability tracking, and remediation for financial applications.
  • Define secure coding standards and integrate security practices into CI/CD pipelines.
  • Perform threat modeling and risk assessments for payments, wallets, ledgers, and other high-value transaction systems.
  • Develop controls against fraud, abuse, unauthorized transfers, and integrity issues.
  • Manage the bug bounty program and support incident response activities.
  • Secure software supply chains, maintain SBOMs, and build agentic and LLM-based security solutions.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
  • 3–5 years of application security experience focused on code security.
  • Experience with payments, money transmission, digital wallets, ledgers, or comparable financial platforms.
  • Strong knowledge of secure coding, application security frameworks, OWASP Top 10, and Python or Rust.
  • Experience with CI/CD security, DevSecOps, software supply chain security, SBOM tools, Burp Suite or OWASP ZAP, and static/dynamic analysis.
  • Must satisfy U.S. ITAR eligibility requirements: U.S. citizenship or nationality, lawful permanent residence, refugee or asylee status, or eligibility to obtain required U.S. authorizations.

Nice to have

  • Experience securing applications on AWS, with GitOps and infrastructure-as-code security.
  • Security certifications such as BSCP, OSCP, or OSWE.
  • Experience managing bug bounty programs, financial data privacy and compliance, or building custom security tooling.
  • Contributions to open-source security projects or tools.

Culture & Benefits

  • Small, highly motivated organization with a flat structure and hands-on engineering culture.
  • Medical, vision, and dental coverage.
  • 401(k) retirement plan, short- and long-term disability insurance, and life insurance.
  • Equity, discounts, and additional employee perks.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →