Senior Application Security Engineer

3 weeks, 4 days ago
Full-time
Senior
Cybersecurity
Brex

Brex

Brex is an AI-powered spend platform that offers integrated corporate cards, expenses, travel, and payments in over 100 countries. With a unified platform for corporate cards, expense management, reimbursements, travel, business accounts, and bill pay,...

Diversified Financial Services
1K-5K
Founded 2017
$1800M raised

Description

  • Identify vulnerabilities, demonstrate business impact, and communicate risk to drive prioritization.
  • Perform penetration testing and design reviews to uncover insecure designs and security issues.
  • Work with engineering and product teams to design secure product features.
  • Build, maintain, and improve internal security tools to automate security efforts.
  • Perform SAST and DAST testing across the Brex platform.
  • Support and improve secure development practices and developer workflows.
  • Collaborate with Security Operations, GRC, Product Security, Front End Platform, and IT Infrastructure teams.
  • Contribute technical leadership, learning sessions, and mentorship to strengthen security culture.
  • Help secure AI and agentic features by identifying attack vectors and partnering on safe implementation.

Requirements

  • 5+ years of experience in Application Security or a related role.
  • Ability to find vulnerabilities in complex systems and demonstrate business impact through custom attack chains.
  • Experience with secure development activities such as threat modeling, developer education, and incident response.
  • Knowledge of Python, scripting languages, and AI/agentic workflows for automation and tool building.
  • Strong written and verbal communication skills with a collaborative mindset.
  • Strong background and interest in penetration testing.
  • Preferred: proficiency with Kotlin, gRPC, GraphQL, and Kubernetes.
  • Preferred: previous experience as a software engineer.
  • Preferred: consultancy experience performing web application security reviews.
  • Preferred: experience securing distributed systems in AWS and other cloud environments.
  • Preferred: experience pentesting and securing agentic features and systems.
  • Preferred: contributions to the technical community such as open source, research, mentorship, blogging, CVEs, or presentations.
  • Preferred: experience submitting to bug bounty programs or responsible disclosure programs.

Benefits

  • Expected salary range of $192,000 to $240,000.
  • Equity and other forms of compensation may be provided as part of the total package.
  • Opportunity to work on AI-driven financial services and early-stage AI security initiatives.
  • Access to tools, resources, and support to grow your career.
  • Inclusive culture and a diverse team environment.
  • Work with highly collaborative engineering and security teams across the company.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Application Security Engineer

Onit 251-1K IT Services

Onit is hiring a Senior Application Security Engineer in Pune to secure its SaaS applications, APIs, and AI-driven platform through hands-on security architecture, risk assessment, and vulnerability management.

AWS Azure CI/CD DevSecOps GCP GraphQL OAuth OpenID Connect REST API SAML SonarQube System Design
5 hours, 39 minutes ago

Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is hiring a security engineering professional to support application security tooling and secure development practices for its cybersecurity clients, including Fortune 500 companies and U.S. government agencies.

Azure Burp Suite CI/CD CircleCI GitHub Actions Jenkins SaltStack
7 hours, 39 minutes ago

Staff Product Security Engineer

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a Staff Product Security Engineer to embed security into its cloud-native, open source software delivery pipelines and product stack, with the goal of reducing risk and hardening production systems.

AWS CI/CD GCP GitHub Actions Go Kubernetes OWASP Penetration Testing Python Secrets Management Tekton
8 hours, 10 minutes ago

Senior Cyber Engineer

ESG News 11-50 Internet Software & Services

The Financial Times is hiring a Senior Cyber Security Engineer to strengthen application and cloud security across its AWS-hosted, cloud-native technology estate.

Agile AWS CI/CD CloudFormation GitHub Python Scrum SIEM Splunk Terraform
1 day, 6 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers