Назад
3 дня назад

Application Security Engineer (Cybersecurity)

100 000 - 258 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Страна
US
vacancy_detail.hirify_telegram_tooltipВакансия из Telegram канала -

Мэтч & Сопровод

Покажет вашу совместимость и напишет письмо

Описание вакансии

TL;DR
Application Security Engineer (Cybersecurity): Securing financial applications, CI/CD pipelines, software supply chains, and high-value transaction systems with an accent on code security, fraud prevention, and secure development practices. Focus on threat modeling payment products, managing vulnerabilities and bug bounty activities, and designing agentic and LLM-based security solutions.

Application Security Engineer

Company

SpaceXAI

Conditions

6 days ago Salary: 100K - 258K

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will secure financial applications throughout the software development lifecycle. You will review code, integrate security controls into CI/CD pipelines, model threats, manage vulnerabilities and bug bounty activities, support incident response, secure software supply chains, and develop agentic and LLM-based security solutions.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, or a related field
  • 3-5 years of application security experience focused on code security
  • Experience with payments, money transmission, digital wallets, or related financial platforms
  • Knowledge of secure coding practices, application security frameworks, and OWASP Top 10 vulnerabilities
  • Proficiency in Python or Rust
  • Experience securing CI/CD pipelines and implementing DevSecOps practices
  • Familiarity with software supply chain security and SBOM generation tools
  • Experience with Burp Suite, OWASP ZAP, and static or dynamic code analysis
  • Experience securing high-value transaction systems against fraud, abuse, and integrity issues
  • Experience designing and implementing agentic and LLM-based security solutions
  • Communication skills for technical and non-technical audiences

Responsibilities

  • Conduct code reviews and static analysis to identify and mitigate security vulnerabilities
  • Design and implement secure coding guidelines and best practices
  • Integrate security practices throughout CI/CD pipelines
  • Perform threat modeling and risk assessments for payments, wallets, ledgers, and related products
  • Develop mitigations for fraud, abuse, and unauthorized movement of funds or credits
  • Manage vulnerability tracking and remediation
  • Manage the bug bounty program, including triage and coordinated disclosure
  • Support application-security incident response
  • Evaluate and secure software supply chains and maintain SBOMs
  • Design and implement agentic and LLM-based security solutions

Benefits

  • Equity
  • Medical coverage
  • Vision coverage
  • Dental coverage
  • 401(k) retirement plan
  • Short-term disability insurance
  • Long-term disability insurance
  • Life insurance
  • Discounts and perks

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →

Текст вакансии взят без изменений

Источник -