Staff Application Security Engineer (Web3)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: New York, New York; Miami, Florida; or remote within the United States. Hybrid work is available at U.S. hub offices, while employees outside hub areas may work remotely. In-person onboarding at a office is required.
Salary: $168,000–$240,000 annual base salary in New York, excluding discretionary bonus and equity.
Company
is a publicly traded crypto and Web3 platform providing secure financial products and services to individuals and institutions in more than 70 countries.
What you will do
- Own and evolve secure software development lifecycle guardrails as an application security subject matter expert.
- Lead architecture reviews, threat modeling, secure code reviews, and penetration testing for high-risk applications and services.
- Design and build AI agents for automated threat modeling, secure code generation and review, and reduced AppSec toil.
- Create and deliver hands-on application security training for engineering teams.
- Participate in the application security on-call rotation and lead post-incident hardening.
Requirements
- Proven ability to perform design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset.
- Strong application security background and knowledge of vulnerabilities including SSRF, race conditions, and privilege escalation.
- Deep code review experience in Scala, Java, Go, or other common languages, plus hands-on experience with Python, Go, or similar languages for building tools.
- Experience implementing custom detection and prevention controls beyond the OWASP Top 10.
- Experience in regulated environments such as financial services, fintech, or crypto, with the ability to assess business context and security risk.
- Typically 7–10+ years of experience or equivalent impact in application security, product security, or similar roles.
Nice to have
- Experience building AI application security tooling with agents or skills.
- Experience with supply chain security, SLSA, OWASP SPVS, and CI/CD security controls.
- Experience preventing application security vulnerabilities at scale through secure design patterns, automated tooling, or frameworks.
- Experience with microservice architectures and cloud-native environments.
Culture & Benefits
- Hybrid work at U.S. hub offices or remote work for employees outside hub areas.
- Competitive starting pay, discretionary annual bonus, and new-hire equity grant.
- Comprehensive health plans and 401(k) with company matching.
- Paid parental leave and flexible time off.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →