Skip to content
IntercomIntercom

Application Security Engineer

Build and operate customer-facing application security capabilities for a SaaS company, including identity, access control, security tooling, threat modeling, and incident response. The role partners closely with engineering teams and helps secure AI-powered products and development workflows.

About the job

Responsibilities

  • Own and engineer tier-zero security capabilities that help customers securely deploy and manage Fin.
  • Design, build, and evolve customer-facing security features, including authentication, SAML/SSO, permissions systems, audit and activity logging, malicious URL scanning, and other enterprise security controls.
  • Partner with engineering teams throughout the software development lifecycle to build secure products and services.
  • Perform architecture reviews, threat modelling exercises, and security assessments for new features and systems.
  • Build security tooling, automation, and developer-facing building blocks that make secure development easier and more scalable.
  • Contribute to secure development standards, guidance, and best practices across Fin.
  • Lead application security initiatives across the software development lifecycle, helping teams identify and address security risks early.
  • Participate in a shared on-call rotation and lead security incident response, investigation, and remediation efforts.
  • Drive security initiatives from problem definition through design, implementation, and measurable outcomes.
  • Partner with teams building AI-powered products to assess and mitigate emerging security risks.
  • Help shape Fin's AI-first approach to security, including AI-powered detection, red-team automation, continuous monitoring, and emerging defensive capabilities.
  • Support the secure adoption of AI-assisted software development tools and engineering workflows.

Requirements

  • Proven application security, product security, or security engineering experience within a SaaS environment.
  • Strong software engineering skills with experience designing, building, and operating production systems.
  • Deep understanding of modern application security threats, secure software development practices, and threat modelling.
  • Experience designing, building, or securing authentication, authorization, identity, or enterprise security capabilities.
  • Experience conducting architecture reviews and security assessments for complex systems.
  • Hands-on security incident response experience, including leading investigations and remediation efforts.
  • Strong programming skills and experience building tools, automation, or developer-focused solutions.
  • Comfort using modern AI-assisted development tools to improve productivity and engineering effectiveness.
  • Ability to communicate security concepts clearly and collaborate effectively with engineering teams.
  • A pragmatic approach to balancing security, customer impact, and engineering velocity.

Nice-to-haves

  • Experience building or owning authentication, SAML/SSO, identity, or access management capabilities.
  • Experience securing AI-powered products or familiarity with security considerations for large language models, agentic systems, retrieval-based architectures, or AI tool integrations.
  • Experience building security automation or security-focused platform capabilities at scale.
  • Familiarity with cloud security, infrastructure security, or distributed systems.
  • Experience working across both large-scale SaaS environments and high-growth companies.

Compensation and Benefits

  • Competitive salary and equity in a fast-growing start-up.
  • Lunch served every weekday, snacks, and a fully stocked kitchen.
  • Regular compensation reviews.
  • Unlimited access to Claude Code and other AI tools.
  • Pension scheme with matching up to 4%.
  • Life assurance and comprehensive health and dental insurance for employees and dependents.
  • Flexible paid time off policy.
  • Paid maternity leave and six weeks of paternity leave.
  • Cycle-to-Work Scheme and secure bike storage.
  • MacBooks are standard, with Windows available for certain roles.

Skills

Application Security, Product Security, SaaS, Authentication, Saml/Sso, Authorization, Identity Management, Threat Modeling, Security Assessments, Incident Response, Security Automation, Cloud Security, Infrastructure Security, Distributed Systems, LLMs

Writer

Writer

London, United Kingdom

Security Engineer, Application Security
No salary listedHybrid4+ YOESecurity Engineering

Build and scale application security for an enterprise AI platform through threat modeling, secure architecture, automated controls, code review, penetration testing, and AI/ML threat research. Requires 4+ years of application security experience and proficiency in at least two programming languages.

Stripe

Stripe

Dublin, Ireland

Abuse Investigator
No salary listedOn-site3+ YOESecurity Engineering

Investigates high-risk accounts and leads incident response for fraud and product-abuse events, using behavioral analysis and threat intelligence to identify root causes and improve detection. Requires 3+ years of incident response and fraud-data analysis experience, plus strong Python and SQL skills.

Stripe

Stripe

Seattle, WA
Abuse Investigator
No salary listedOn-site3+ YOESecurity Engineering

Investigates and leads response to high-risk fraud and product-abuse incidents, analyzes threat patterns, and drives root-cause and prevention improvements. Requires 3+ years of incident response and fraud-oriented data analysis, plus Python, SQL, and security investigation expertise.

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Kodex

Kodex

Sydney, Australia

Threat Intelligence Specialist – EMEA
No salary listedRemote3+ YOESecurity Engineering

The Threat Intelligence Specialist investigates identity fraud and threat actors, conducts pivot-based OSINT, and collaborates with law enforcement agencies across EMEA. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.