Beyond Finance

Beyond Finance

Beyond Finance is a next generation FinTech company with offices in Chicago, Houston, and San Diego. They offer simple and transparent financial products customized to clients' individual circumstances. Their objective is to provide personalized financ...

Banks
251-1K
Founded 2016
$805M raised

Description

  • Lead and evolve the application security strategy, roadmap, and day-to-day operations.
  • Serve as the primary AppSec partner for development teams across web, mobile, Python, and Go projects.
  • Provide security guidance during design, development, and code review for new features and services.
  • Drive adoption of secure coding practices and threat modeling across engineering teams.
  • Manage and optimize AppSec tooling, including SAST, DAST, ASM, mobile security, and WAF solutions.
  • Improve automation and integration of security tools into CI/CD pipelines.
  • Build and maintain secure development standards, playbooks, and training materials.
  • Partner with engineering teams during sprint planning and feature design to identify and reduce risk early.
  • Conduct security reviews, code assessments, and vulnerability triage with development teams.
  • Work with DevOps to secure AWS deployments, configurations, and CI/CD workflows.

Requirements

  • 8+ years of experience in Application Security, Product Security, or related engineering roles.
  • Strong understanding of secure coding practices, the OWASP Top 10, and modern SDLC practices.
  • Experience working with cloud-native applications, ideally in AWS.
  • Understanding of SSL certificates and cryptographic key management.
  • Hands-on experience with SAST, DAST, WAFs, and/or mobile application security tools.
  • Ability to partner effectively with developers and influence secure design decisions.
  • Familiarity with GitHub-based workflows and CI/CD pipelines.
  • Development experience with Ruby on Rails or similar dynamic languages (nice to have).
  • Knowledge of AWS ECS/EKS, container security, secrets management, and infrastructure as code such as CloudFormation or Terraform (preferred).
  • Experience building or maturing an AppSec program from early stages, SOAR automation and scripting experience, or PCI-compliance exposure (preferred).

Benefits

  • Base salary range of $160,000 to $195,000 USD.
  • Eligible for additional incentives, including an annual bonus.
  • Considerable employer contributions for health, dental, and vision coverage.
  • Generous PTO, paid holidays, and paid parental leave.
  • 401(k) matching program.
  • Merit advancement opportunities.
  • Career development and training.
  • Collaborative, community-oriented work environment.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Application Security Engineer

Canopy 51-250 Internet Software & Services

Canopy is hiring a Senior Application Security Engineer to help secure its remote Utah-based SaaS platform for accounting firms, with a focus on hardening infrastructure, applications, observability, and the software supply chain.

AWS CI/CD Kubernetes Network Security SIEM WAF
14 hours, 1 minute ago

Senior Security Engineer - Product Security

Ondo Finance 11-50 Diversified Financial Services

Ondo Finance is hiring a Senior Security Engineer for Product Security to secure its tokenized real-world asset platform by partnering with product engineering on threat modeling, secure reviews, and security-by-default delivery.

CI/CD Encryption Go JavaScript OAuth OpenID Connect Penetration Testing Python Rust Terraform TypeScript
2 days, 13 hours ago

Senior Application Security Engineer

Counterpart Health 51-200 hospital & health care

Counterpart Health is hiring a Senior Application Security Engineer to secure its AI-enabled primary care platform, Counterpart Assistant, by finding and fixing vulnerabilities that affect clinicians during live patient visits.

Penetration Testing
2 days, 14 hours ago

Staff Product Security Engineer

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a Staff Product Security Engineer to embed security into its cloud-native product and delivery pipelines for hardened open source software.

AWS CI/CD GCP GitHub Actions Go Kubernetes OWASP Penetration Testing Python Secrets Management Tekton
3 days, 13 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers