Application Security Engineer (X Money)
at SpaceXAI
📍 Washington, United States
📍 Austin, United States
📍 New York City, United States
📍 Palo Alto, United States
📍 Austin, United States
📍 New York City, United States
📍 Palo Alto, United States
USD 100,000-258,000 per year
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AWS @ 1
CI/CD @ 3
Communication @ 3
Compliance @ 3
FinTech @ 3
Fraud @ 3
LLM @ 3
OWASP @ 6
Payments @ 3
Python @ 5
Rust @ 5
Security @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
SpaceXAI is seeking an Application Security Engineer to protect the security and integrity of its payments and financial products throughout the software development lifecycle. The role focuses on code security, CI/CD pipelines, and systems that move and hold customer funds. Experience securing fintech, payments, digital wallet, ledger, or similar high-value platforms is strongly preferred.
Responsibilities
- Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in financial applications.
- Design and implement secure coding guidelines and best practices for development teams.
- Collaborate with development teams to integrate security practices throughout the CI/CD pipeline.
- Perform threat modeling and risk assessments for payments, wallets, ledgers, and related product surfaces.
- Develop mitigation strategies for fraud, abuse, and unauthorized movement of funds or credits.
- Manage vulnerability tracking and remediation efforts, providing guidance to development teams.
- Manage the bug bounty program, including intake, triage, researcher communication, and coordinated disclosure.
- Support incident response activities related to application security.
- Stay current on emerging threats against financial and cloud-native systems and continuously strengthen security controls.
- Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs).
- Design and implement agentic and LLM-based solutions to help detect, investigate, or prevent security problems.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, or a related field.
- 3–5 years of experience in application security, with a strong focus on code security practices.
- Experience in payments, money transmission, digital wallets, or related financial platforms.
- Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities such as the OWASP Top 10.
- Proficiency in Python or Rust and experience with secure coding practices in these languages.
- Experience securing CI/CD pipelines and implementing DevSecOps practices.
- Familiarity with software supply chain security and SBOM generation tools.
- Experience with security testing tools such as Burp Suite and OWASP ZAP, as well as static and dynamic code analysis.
- Experience securing payments, wallets, ledgers, or other high-value transaction systems, including controls against fraud, abuse, and integrity issues.
- Experience designing and implementing agentic and LLM-based solutions for security problems.
- Excellent communication skills, with the ability to explain complex security issues to technical and non-technical audiences.
Preferred Skills And Experience
- Hands-on experience securing applications on AWS; familiarity with other cloud platforms is a plus.
- Relevant security certifications such as BSCP, OSCP, or OSWE.
- Experience managing bug bounty programs.
- Background in data privacy and compliance relevant to financial products and cloud-native applications.
- Experience with GitOps and infrastructure-as-code security.
- Experience building custom security tooling to enhance and automate security processes.
- Contributions to open-source security projects or tools.
Compensation And Benefits
- Base salary: $100,000–$258,000 USD per year.
- Equity.
- Comprehensive medical, vision, and dental coverage.
- 401(k) retirement plan.
- Short- and long-term disability insurance.
- Life insurance, discounts, and other perks.
ITAR Requirements
To conform to U.S. Government export regulations, applicants must be U.S. citizens or nationals, U.S. lawful permanent residents, refugees under 8 U.S.C. § 1157, asylees under 8 U.S.C. § 1158, or eligible to obtain the required authorizations from the U.S. Department of State.
More jobs at SpaceXAI
Member of Technical Staff - Evaluation Infrastructure
SpaceXAI · Palo Alto, United States
USD 180,000-440,000 per year
Expert Team Lead, Medicine
SpaceXAI · World, Australia, Canada, Switzerland, Germany, Spain, France, United Kingdom, Indonesia, Ireland, India, Japan, South Korea, Netherlands, Philippines, United States, Dubai, United Arab Emirates, Asia, Philippines, Singapore, Singapore, Palo Alto, United States
USD 104,000-170,400 per year
Expert Team Lead, Engineering
SpaceXAI · World, Australia, Canada, Switzerland, Germany, Spain, France, United Kingdom, Indonesia, Ireland, India, Japan, South Korea, Netherlands, Philippines, United States, Dubai, United Arab Emirates, Asia, Philippines, Singapore, Singapore, Palo Alto, United States
USD 104,000-170,400 per year
Vulnerability Analyst
SpaceXAI · Washington, United States, Austin, United States, New York City, United States, Palo Alto, United States
USD 100,000-258,000 per year
Network Engineer
SpaceXAI · Palo Alto, United States
USD 150,000-250,000 per year
Similar jobs
Application Security Engineer
SpaceXAI · Palo Alto, United States
USD 100,000-258,000 per year
Offensive Security Engineer
Stripe · United States
USD 179,000-268,400 per year
Security Engineer - Proactive Threat
Stripe · Dublin, Ireland
EUR 112,200-168,200 per year
Lead, Security Controls Assurance - SOX
Anthropic · Washington, United States, New York City, United States, San Francisco, United States, Seattle, United States
USD 410,000-510,000 per year
Sr. Security Engineer - GRC Fintech & Financial Services
SpaceXAI · Washington, United States, New York City, United States, Palo Alto, United States
USD 152,000-258,000 per year
Staff+ Software Engineer, GRC Platform
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-405,000 per year
Security Engineer, Privy
Stripe · New York City, United States
USD 196,900-295,300 per year
Engineering Lead - Consumer Subscriptions
SpaceXAI · Palo Alto, United States
USD 180,000-440,000 per year