Application Security Engineer securing payments, wallet, and ledger systems across the SDLC: code review and static analysis, CI/CD and supply-chain security, threat modeling, vulnerability and bug-bounty management, incident response, and building agentic/LLM-based security tooling. Requires 3-5 years of AppSec experience and Python or Rust; on-site in Palo Alto, Austin, New York, or Washington,
You will secure financial applications throughout the software development lifecycle. You will review code, integrate security controls into CI/CD pipelines, model threats, manage vulnerabilities and bug bounty activities, support incident response, secure software supply chains, and develop agentic and LLM-based security solutions.
Responsibilities
Conduct code reviews and static analysis to identify and mitigate security vulnerabilities
Design and implement secure coding guidelines and best practices
Integrate security practices throughout CI/CD pipelines
Perform threat modeling and risk assessments for payments, wallets, ledgers, and related products
Develop mitigations for fraud, abuse, and unauthorized movement of funds or credits
Manage vulnerability tracking and remediation
Manage the bug bounty program, including triage and coordinated disclosure
Support application-security incident response
Evaluate and secure software supply chains and maintain SBOMs
Design and implement agentic and LLM-based security solutions
Requirements
Bachelor's degree in Computer Science, Cybersecurity, or a related field
3-5 years of application security experience focused on code security
Experience with payments, money transmission, digital wallets, or related financial platforms
Knowledge of secure coding practices, application security frameworks, and OWASP Top 10 vulnerabilities
Proficiency in Python or Rust
Experience securing CI/CD pipelines and implementing DevSecOps practices
Familiarity with software supply chain security and SBOM generation tools
Experience with Burp Suite, OWASP ZAP, and static or dynamic code analysis
Experience securing high-value transaction systems against fraud, abuse, and integrity issues
Experience designing and implementing agentic and LLM-based security solutions
Communication skills for technical and non-technical audiences