Application Security Engineer (X Money)

USD 100,000-258,000 per year
MIDDLE
✅ On-site

Tech Stack

AWS @ 1 CI/CD @ 3 Communication @ 3 Compliance @ 3 FinTech @ 3 Fraud @ 3 LLM @ 3 OWASP @ 6 Payments @ 3 Python @ 5 Rust @ 5 Security @ 6

Details

SpaceXAI is seeking an Application Security Engineer to protect the security and integrity of its payments and financial products throughout the software development lifecycle. The role focuses on code security, CI/CD pipelines, and systems that move and hold customer funds. Experience securing fintech, payments, digital wallet, ledger, or similar high-value platforms is strongly preferred.

Responsibilities

  • Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in financial applications.
  • Design and implement secure coding guidelines and best practices for development teams.
  • Collaborate with development teams to integrate security practices throughout the CI/CD pipeline.
  • Perform threat modeling and risk assessments for payments, wallets, ledgers, and related product surfaces.
  • Develop mitigation strategies for fraud, abuse, and unauthorized movement of funds or credits.
  • Manage vulnerability tracking and remediation efforts, providing guidance to development teams.
  • Manage the bug bounty program, including intake, triage, researcher communication, and coordinated disclosure.
  • Support incident response activities related to application security.
  • Stay current on emerging threats against financial and cloud-native systems and continuously strengthen security controls.
  • Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs).
  • Design and implement agentic and LLM-based solutions to help detect, investigate, or prevent security problems.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, or a related field.
  • 3–5 years of experience in application security, with a strong focus on code security practices.
  • Experience in payments, money transmission, digital wallets, or related financial platforms.
  • Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities such as the OWASP Top 10.
  • Proficiency in Python or Rust and experience with secure coding practices in these languages.
  • Experience securing CI/CD pipelines and implementing DevSecOps practices.
  • Familiarity with software supply chain security and SBOM generation tools.
  • Experience with security testing tools such as Burp Suite and OWASP ZAP, as well as static and dynamic code analysis.
  • Experience securing payments, wallets, ledgers, or other high-value transaction systems, including controls against fraud, abuse, and integrity issues.
  • Experience designing and implementing agentic and LLM-based solutions for security problems.
  • Excellent communication skills, with the ability to explain complex security issues to technical and non-technical audiences.

Preferred Skills And Experience

  • Hands-on experience securing applications on AWS; familiarity with other cloud platforms is a plus.
  • Relevant security certifications such as BSCP, OSCP, or OSWE.
  • Experience managing bug bounty programs.
  • Background in data privacy and compliance relevant to financial products and cloud-native applications.
  • Experience with GitOps and infrastructure-as-code security.
  • Experience building custom security tooling to enhance and automate security processes.
  • Contributions to open-source security projects or tools.

Compensation And Benefits

  • Base salary: $100,000–$258,000 USD per year.
  • Equity.
  • Comprehensive medical, vision, and dental coverage.
  • 401(k) retirement plan.
  • Short- and long-term disability insurance.
  • Life insurance, discounts, and other perks.

ITAR Requirements

To conform to U.S. Government export regulations, applicants must be U.S. citizens or nationals, U.S. lawful permanent residents, refugees under 8 U.S.C. § 1157, asylees under 8 U.S.C. § 1158, or eligible to obtain the required authorizations from the U.S. Department of State.

More jobs at SpaceXAI

Similar jobs