Senior Application Security Engineer

5 months, 1 week ago
Full-time
Senior
Cybersecurity
Brex

Brex

Brex is an AI-powered spend platform that offers integrated corporate cards, expenses, travel, and payments in over 100 countries. With a unified platform for corporate cards, expense management, reimbursements, travel, business accounts, and bill pay,...

Diversified Financial Services
1K-5K
Founded 2017
$1800M raised

Description

  • Identify vulnerabilities, demonstrate business impact, and communicate risk to drive prioritization.
  • Perform penetration testing and design reviews to uncover insecure designs and security issues.
  • Work with engineering and product teams to design secure product features.
  • Build, maintain, and improve internal security tools to automate security efforts.
  • Perform SAST and DAST testing across the Brex platform.
  • Support and improve secure development practices and developer workflows.
  • Collaborate with Security Operations, GRC, Product Security, Front End Platform, and IT Infrastructure teams.
  • Contribute technical leadership, learning sessions, and mentorship to strengthen security culture.
  • Help secure AI and agentic features by identifying attack vectors and partnering on safe implementation.

Requirements

  • 5+ years of experience in Application Security or a related role.
  • Ability to find vulnerabilities in complex systems and demonstrate business impact through custom attack chains.
  • Experience with secure development activities such as threat modeling, developer education, and incident response.
  • Knowledge of Python, scripting languages, and AI/agentic workflows for automation and tool building.
  • Strong written and verbal communication skills with a collaborative mindset.
  • Strong background and interest in penetration testing.
  • Preferred: proficiency with Kotlin, gRPC, GraphQL, and Kubernetes.
  • Preferred: previous experience as a software engineer.
  • Preferred: consultancy experience performing web application security reviews.
  • Preferred: experience securing distributed systems in AWS and other cloud environments.
  • Preferred: experience pentesting and securing agentic features and systems.
  • Preferred: contributions to the technical community such as open source, research, mentorship, blogging, CVEs, or presentations.
  • Preferred: experience submitting to bug bounty programs or responsible disclosure programs.

Benefits

  • Expected salary range of $192,000 to $240,000.
  • Equity and other forms of compensation may be provided as part of the total package.
  • Opportunity to work on AI-driven financial services and early-stage AI security initiatives.
  • Access to tools, resources, and support to grow your career.
  • Inclusive culture and a diverse team environment.
  • Work with highly collaborative engineering and security teams across the company.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Application Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a remote Application Security Engineer to triage and validate vulnerability submissions for large-scale bug bounty programs while coordinating with clients and security researchers.

Burp Suite Nmap
6 hours, 47 minutes ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Senior Product Security Engineer to secure its AI-native market intelligence platform by embedding AI/ML security, secure architecture, and assurance practices across the product lifecycle.

CI/CD DevSecOps Encryption Java JavaScript Kubernetes Python SAML Secrets Management TLS
7 hours, 17 minutes ago

Product Security Engineer

Modern Health 251-1K Health Care Providers & Services

Modern Health is hiring a remote Product Security Engineer to strengthen security and compliance across its mental health platform, applications, cloud infrastructure, and software development lifecycle.

Agile AWS Bash CI/CD Cybersecurity Datadog Django Flask GitLab HashiCorp Vault Packer Penetration Testing PostgreSQL Python Redis Terraform
2 days, 7 hours ago

Application Security Engineer - Senior

Banco Plata, S.A., Institución de Banca Múltiple. 1001-5000 Banking / financial services

Plata is seeking an Application Security Engineer to join its Information Security team and embed security controls, testing, and practices throughout the software development lifecycle.

Burp Suite CI/CD Kubernetes Microservices OWASP Penetration Testing
4 days, 7 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers