Application Security Engineer

3 hours, 49 minutes ago
Full-time
Mid Level
Cybersecurity
Brex

Brex

Brex is an AI-powered spend platform that offers integrated corporate cards, expenses, travel, and payments in over 100 countries. With a unified platform for corporate cards, expense management, reimbursements, travel, business accounts, and bill pay,...

Diversified Financial Services
1K-5K
Founded 2017
$1800M raised

Description

  • Identify vulnerabilities across common vulnerability classes, document findings clearly, and communicate risk to drive remediation efforts.
  • Participate in penetration testing and design reviews to surface vulnerabilities and insecure designs.
  • Contribute to internal tooling and automation that support SAST and DAST testing of the Brex platform.
  • Collaborate with engineering and product teams to support the design of secure product features.
  • Actively contribute to a culture of security awareness through knowledge sharing and peer learning.
  • Work closely with Security Operations, GRC, Product Security, Front End Platform, and IT Infrastructure teams.
  • Help secure AI-powered and agentic features by identifying attack surfaces introduced by LLM-based systems.
  • Apply emerging AI security best practices to support trustworthy financial products.

Requirements

  • 4+ years of work experience in Application Security or a related role.
  • Demonstrated ability to find and document vulnerabilities in complex systems and communicate business risk clearly.
  • Hands-on experience with secure development activities such as code review, threat modeling, or penetration testing.
  • Experience identifying security risks in AI/ML systems such as prompt injection, model manipulation, or data poisoning.
  • Familiarity with agentic workflows and LLM-powered attack surfaces.
  • Knowledge of Python or scripting languages to automate tasks and build tooling.
  • Strong written and verbal communication skills with a collaborative mindset.
  • Experience with Kotlin, gRPC, GraphQL, or Kubernetes is preferred.
  • Previous experience as a software engineer is preferred.
  • Experience securing distributed systems in AWS and cloud environments is preferred.
  • Experience with web application security reviews is preferred.
  • Contributions to open source, public research, CTFs, blogging, CVEs, presentations, bug bounty, or responsible disclosure programs are preferred.
  • Published AI security research or contributions to AI security frameworks are preferred.

Benefits

  • Expected salary range of $152,000 - $190,000.
  • Equity and other forms of compensation may be provided as part of the total package.
  • Opportunity to work on AI security for a fast-growing financial technology platform.
  • Cross-functional collaboration with security, engineering, and product teams.
  • Access to tools, resources, and support to grow your career.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Product Security Analyst

Omilia 251-1K IT Services

Omilia is hiring a Senior Product Security Analyst to own product and application security reviews across the software lifecycle, helping protect cloud-based SaaS products, platforms, and customers as the company scales.

Agile AWS Microservices Penetration Testing
2 hours, 3 minutes ago

Senior Cyber Engineer

ESG News 11-50 Internet Software & Services

The Financial Times is hiring a Senior Cyber Security Engineer to strengthen application and cloud security across its AWS-hosted, cloud-native technology estate.

Agile AWS CI/CD CloudFormation GitHub Python Scrum SIEM Splunk Terraform
17 hours, 1 minute ago

Senior Staff Product Security Engineer

Greenlight 251-1K Capital Markets

Greenlight is hiring a Senior Staff Product Security Engineer to define and drive the product security strategy for its family fintech platform and help protect customer financial, location, and personal data across the engineering organization.

Android AWS Burp Suite DynamoDB GCP Helm iOS Java Kotlin Kubernetes Microservices MySQL Node.js Penetration Testing Rancher React Redis Swift SwiftUI
17 hours, 55 minutes ago

Director Security Engineer | DevSecOps

Wellhub 1-10 Gas Utilities

Wellhub is hiring a Director of Security Engineering in Brazil to lead application security, DevSecOps, and security engineering for its global subscription platform across 10 product verticals.

API Gateway AWS Burp Suite CI/CD Elasticsearch GCP Go Java JavaScript Kubernetes Microservices Prisma Python Secrets Management Sentinel SIEM SonarQube Splunk
18 hours, 1 minute ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers