Skip to content

Senior Application Security Engineer

192k – 240kUnited StatesRemote5+ YOE
Summary

Senior Application Security Engineer focused on finding vulnerabilities, performing penetration testing, and building security tooling across Brex's platform. Requires 5+ years in application security with strong Python and AI workflow knowledge.

About the role

Responsibilities

  • Identifying vulnerabilities, demonstrating business impact, and articulating the risk of specific vulnerabilities to drive prioritization efforts
  • Perform penetration testing and design reviews, looking for vulnerabilities and insecure designs, work with engineering and product to design secure product features
  • Maintain and build internal tools to automate security efforts, perform SAST and DAST testing of the Brex platform, and support secure development practices
  • Build and contribute to a culture of collaborative security excellence through technical leadership, learning sessions, and mentorship within the team and wider organization

Requirements

  • 5+ years work experience in an Application Security or related role
  • Ability to find vulnerabilities in complex systems, demonstrating business impact through custom attack chains
  • Experience with a wide range of secure development activities including— threat modeling, developer education, and incident response
  • Knowledge of Python, scripting languages, and AI/agentic workflows to automate tasks, build tools and improve productivity
  • Collaborative mindset paired with strong written and verbal communication skills

Nice-to-Haves

  • Proficiency with Kotlin, gRPC, GraphQL, Kubernetes
  • Previous experience as a software engineer
  • Consultancy experience performing web application security reviews
  • Experience with securing distributed systems in AWS and cloud environments
  • Experience with pentesting and securing agentic features and systems
  • Contributions to the wider technical community— open source, public research, mentorship, community organizing, blogging, CVEs, presentations, etc
  • Experience submitting to bug bounty programs or responsible disclosure programs

Compensation

The expected salary range for this role is $192,000 - $240,000. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.

Skills
PythonKotlingRPCGraphQLKubernetesAWSSASTDASTpenetration testingthreat modeling
Similar roles at this salary range
All Security Engineering jobs →
Shield AI

Senior Staff Cybersecurity Engineer, Platform Security

Senior technical owner building secure-by-default infrastructure, IaC modules, policy-as-code guardrails, and CI/CD security tooling for cloud and platform engineering teams.

160k – 240kSan Diego, CASecurity EngineeringOn-site7+ YOEGoOPA
Upstart

Principal Security Engineer, Data Security

Principal-level security engineer defining infrastructure security strategy and leading cross-functional efforts to secure cloud, Kubernetes, and developer platforms at scale.

191k – 264kUnited StatesSecurity EngineeringRemote8+ YOEGoAWS
Rula

Staff Software Engineer - Trust & Safety

Staff-level engineer to found and lead a new Trust & Safety engineering team, architecting systems to detect fraud, billing anomalies, and credential abuse for a mental healthcare platform.

207k – 243kLos Angeles, CASecurity EngineeringRemote8+ YOESQLAWS
Apollo

Senior Application Security Engineer

Senior individual contributor responsible for strengthening Apollo's secure software development lifecycle, performing application security reviews, threat modeling, vulnerability management, and AI security for product, platform, and AI-powered features.

190k – 273kUnited StatesSecurity EngineeringRemote5+ YOEGCPRuby
Betterment

Sr. Engineering Manager, Application Security

Senior Engineering Manager leading Application Security squad to build secure software by default through threat modeling, design reviews, vulnerability management, and developer tooling. Requires hands-on team leadership and expertise across the AppSec stack.

210k – 250kNew York, NYSecurity EngineeringHybrid7+ YOEAWSCI/CD