Skip to content
BrexBrex

Senior Application Security Engineer

Senior Application Security Engineer identifies vulnerabilities via code/design reviews, penetration testing, and builds automation tools for SAST/DAST. Requires 5+ years AppSec experience, Python proficiency, and strong collaboration skills; bonus for Kotlin, Kubernetes, AWS.

About the job

Responsibilities

  • Identifying vulnerabilities, demonstrating business impact, and articulating the risk of specific vulnerabilities to drive prioritization efforts
  • Perform penetration testing and design reviews, looking for vulnerabilities and insecure designs, work with engineering and product to design secure product features
  • Maintain and build internal tools to automate security efforts, perform SAST and DAST testing of the Brex platform, and support secure development practices
  • Build and contribute to a culture of collaborative security excellence through technical leadership, learning sessions, and mentorship within the team and wider organization

Requirements

  • 5+ years work experience in an Application Security or related role
  • Ability to find vulnerabilities in complex systems, demonstrating business impact through custom attack chains
  • Experience with a wide range of secure development activities including— threat modeling, developer education, and incident response
  • Knowledge of Python, scripting languages, and AI/agentic workflows to automate tasks, build tools and improve productivity
  • Collaborative mindset paired with strong written and verbal communication skills

Bonus Points

  • Proficiency with Kotlin, gRPC, GraphQL, Kubernetes
  • Previous experience as a software engineer
  • Consultancy experience performing web application security reviews
  • Experience with securing distributed systems in AWS and cloud environments
  • Experience with pentesting and securing agentic features and systems
  • Contributions to the wider technical community— open source, public research, mentorship, community organizing, blogging, CVEs, presentations, etc
  • Experience submitting to bug bounty programs or responsible disclosure programs

Compensation

The expected salary range for this role is $192,000 - $240,000. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.

Skills

Python, Kubernetes, Kotlin, gRPC, GraphQL, AWS, SAST, DAST, Penetration Testing, Threat Modeling

Instacart

Instacart

United States
Senior Detection Engineer II
$192k+/yrRemote6+ YOESecurity Engineering

Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.

Discord

Discord

United States

Senior Platform Security Engineer
$196k+/yrOn-site5+ YOESecurity Engineering

Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.

Harvey

Harvey

San Francisco, CA

Senior Software Engineer, Security
$188k+/yrOn-site5+ YOESecurity Engineering

Build and operate foundational security services covering identity, authorization, secrets, and privileged access for an AI-powered enterprise platform. The role requires 5+ years of production software engineering experience and hands-on security infrastructure expertise.

Front

Front

San Francisco, CA

Senior AI Platform Security Engineer
$187k+/yrOn-site7+ YOESecurity Engineering

This role defines, builds, and secures the internal platform supporting Front’s engineering, GTM, data, and AI tooling. It owns AWS and Snowflake infrastructure, paved-road delivery, observability, access controls, vulnerability management, incident response, compliance support, and AI-client security.

Square

Square

United States

Senior GRC Engineer
$185k+/yrRemote7+ YOESecurity Engineering

Build data pipelines, integrations, policy-as-code, and agentic AI workflows that automate security governance and continuous compliance. The role requires 7+ years of production software engineering experience plus expertise in LLMs, APIs, distributed data, and cloud infrastructure.