Beyond Finance

Beyond Finance

Beyond Finance is a next generation FinTech company with offices in Chicago, Houston, and San Diego. They offer simple and transparent financial products customized to clients' individual circumstances. Their objective is to provide personalized financ...

Banks
251-1K
Founded 2016
$805M raised

Description

  • Lead and evolve the application security strategy, roadmap, and day-to-day operations.
  • Serve as the primary AppSec partner for development teams across web, mobile, Python, and Go projects.
  • Provide security guidance during design, development, and code review for new features and services.
  • Drive adoption of secure coding practices and threat modeling across engineering teams.
  • Manage and optimize AppSec tooling, including SAST, DAST, ASM, mobile security, and WAF solutions.
  • Improve automation and integration of security tools into CI/CD pipelines.
  • Build and maintain secure development standards, playbooks, and training materials.
  • Partner with engineering teams during sprint planning and feature design to identify and reduce risk early.
  • Conduct security reviews, code assessments, and vulnerability triage with development teams.
  • Work with DevOps to secure AWS deployments, configurations, and CI/CD workflows.

Requirements

  • 8+ years of experience in Application Security, Product Security, or related engineering roles.
  • Strong understanding of secure coding practices, the OWASP Top 10, and modern SDLC practices.
  • Experience working with cloud-native applications, ideally in AWS.
  • Understanding of SSL certificates and cryptographic key management.
  • Hands-on experience with SAST, DAST, WAFs, and/or mobile application security tools.
  • Ability to partner effectively with developers and influence secure design decisions.
  • Familiarity with GitHub-based workflows and CI/CD pipelines.
  • Development experience with Ruby on Rails or similar dynamic languages (nice to have).
  • Knowledge of AWS ECS/EKS, container security, secrets management, and infrastructure as code such as CloudFormation or Terraform (preferred).
  • Experience building or maturing an AppSec program from early stages, SOAR automation and scripting experience, or PCI-compliance exposure (preferred).

Benefits

  • Base salary range of $160,000 to $195,000 USD.
  • Eligible for additional incentives, including an annual bonus.
  • Considerable employer contributions for health, dental, and vision coverage.
  • Generous PTO, paid holidays, and paid parental leave.
  • 401(k) matching program.
  • Merit advancement opportunities.
  • Career development and training.
  • Collaborative, community-oriented work environment.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Application Security Engineer

Vannevar Labs 11-50 Aerospace & Defense

Vannevar is hiring an Application Security Engineer to secure its defense-focused SaaS platform by embedding application security practices throughout the software development lifecycle.

CI/CD DevSecOps GitHub Actions JavaScript Python TypeScript
7 hours, 49 minutes ago

Senior Implementation Engineer - DevOps & Application Security

Workana 1K-5K Internet Software & Services

Endor Labs is seeking a Technical Implementation Engineer in Panama to lead customers through integrating and adopting its application security platform across their development environments.

CI/CD DevSecOps Gradle Maven
1 day, 8 hours ago

Senior Manager, Product Security

Tines 51-250 Construction & Engineering

Tines is seeking a Senior Manager, Product Security to lead and scale its product security program for cloud-native, AI-forward products while partnering with engineering and product leaders to manage risk and support growth.

AWS CI/CD DevSecOps Docker Kubernetes Penetration Testing Ruby Rust TypeScript
4 days, 8 hours ago

Application Security Engineer

Glean 11-50 Internet Software & Services

Glean is hiring a remote Application Security Engineer to lead vulnerability management and strengthen software supply-chain security across its Work AI platform.

AWS Burp Suite CI/CD Cybersecurity GCP Kubernetes Microservices
4 days, 8 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers