Brex

Brex

Brex is an AI-powered spend platform that offers integrated corporate cards, expenses, travel, and payments in over 100 countries. With a unified platform for corporate cards, expense management, reimbursements, travel, business accounts, and bill pay,...

Diversified Financial Services
1K-5K
Founded 2017
$1800M raised

Description

  • Identify vulnerabilities, demonstrate business impact, and communicate risk to drive prioritization.
  • Perform penetration testing and design reviews to uncover insecure designs and security issues.
  • Work with engineering and product teams to design secure product features.
  • Build, maintain, and improve internal security tools to automate security efforts.
  • Perform SAST and DAST testing across the Brex platform.
  • Support and improve secure development practices and developer workflows.
  • Collaborate with Security Operations, GRC, Product Security, Front End Platform, and IT Infrastructure teams.
  • Contribute technical leadership, learning sessions, and mentorship to strengthen security culture.
  • Help secure AI and agentic features by identifying attack vectors and partnering on safe implementation.

Requirements

  • 5+ years of experience in Application Security or a related role.
  • Ability to find vulnerabilities in complex systems and demonstrate business impact through custom attack chains.
  • Experience with secure development activities such as threat modeling, developer education, and incident response.
  • Knowledge of Python, scripting languages, and AI/agentic workflows for automation and tool building.
  • Strong written and verbal communication skills with a collaborative mindset.
  • Strong background and interest in penetration testing.
  • Preferred: proficiency with Kotlin, gRPC, GraphQL, and Kubernetes.
  • Preferred: previous experience as a software engineer.
  • Preferred: consultancy experience performing web application security reviews.
  • Preferred: experience securing distributed systems in AWS and other cloud environments.
  • Preferred: experience pentesting and securing agentic features and systems.
  • Preferred: contributions to the technical community such as open source, research, mentorship, blogging, CVEs, or presentations.
  • Preferred: experience submitting to bug bounty programs or responsible disclosure programs.

Benefits

  • Expected salary range of $192,000 to $240,000.
  • Equity and other forms of compensation may be provided as part of the total package.
  • Opportunity to work on AI-driven financial services and early-stage AI security initiatives.
  • Access to tools, resources, and support to grow your career.
  • Inclusive culture and a diverse team environment.
  • Work with highly collaborative engineering and security teams across the company.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Lead Security Engineer - Penetration Testing & AI Security

HighLevel 251-1K Internet Software & Services

HighLevel is seeking a Lead Security Engineer to secure its SaaS platform and AI-enabled products through application security leadership, secure development practices, and adversarial testing of AI systems.

Bash CI/CD Cybersecurity DevSecOps Docker Go JavaScript JWT Kubernetes Microservices OpenID Connect OWASP Penetration Testing Python SAML
4 days, 7 hours ago

Application Security Engineer II - Contract ( 6 months )

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a remote Application Security Engineer to triage and validate vulnerability submissions for client bug bounty programs, assess severity, and coordinate responses with researchers and customers.

Burp Suite Nmap
6 days, 6 hours ago

Cyber Security Engineer (Application Security)

TherapyNotes 51-250 Health Care Providers & Services

TherapyNotes is seeking a hands-on Cyber Security Engineer to own application security across the SDLC and CI/CD pipeline for its healthcare-regulated behavioral health SaaS platform.

AWS Azure CI/CD Cybersecurity GitHub Actions HIPAA SIEM Terraform
1 week ago

Principal Technical Consultant – Cloud and Application Security

AHEAD 1K-5K IT Services

AHEAD is seeking a Principal Technical Consultant to lead client security engagements and support business development and practice growth across cloud security, application security, threat management, and DevSecOps.

AWS Azure Bash DevSecOps Docker GCP GraphQL Kubernetes PowerShell Python REST API Sentinel Serverless SIEM Splunk Terraform Vertex AI
1 week, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers