Skip to content

Staff Application Security Engineer

Lead technical vision and architecture for Brex's Application Security team. Drive AI/ML security strategy, offensive testing, and secure product lifecycle across engineering orgs. Requires 8+ years in appsec with AI security expertise.

240k – 300kSan Francisco, CASecurity EngineeringHybrid8+ YOE

About the role

Responsibilities

  • Lead the technical vision and strategic roadmap for the Application Security team, aligning security objectives with Brex's enterprise growth and high-velocity engineering metrics.
  • Establish technical standards and secure defaults across the entire engineering organization, fostering a culture of collaborative security excellence and bridging product platforms, infra, and trust.
  • Architect and secure novel AI/ML and agentic workflows, applying cutting-edge practices to mitigate risks such as prompt injection, model manipulation, and data poisoning.
  • Mentor and coach engineers within the team and across the broader organization, guiding technical growth, helping individuals level up their security expertise, and accelerating team delivery.
  • Drive proactive vulnerability discovery and offensive security testing strategies, executing complex attack chains to demonstrate business impact and prioritize cross-functional remediation.
  • Partner with Product Platform, Cloud Infrastructure, and Data engineering teams to ensure core primitives, APIs, and microservices are secure by default from design to deployment.

Requirements

  • 8+ years of experience in Application Security, Product Security, or software engineering with a primary focus on offensive and defensive application security.
  • Proven track record of technical leadership and team mentorship on complex, multi-quarter security engineering initiatives in a fast-paced environment.
  • Deep proficiency and technical expertise in AI security, including hands-on experience securing agentic architectures, LLM gateways, and evaluating adversarial AI vectors.
  • Strong systems-thinking capabilities with extensive experience defining secure product development lifecycles, threat modeling complex topologies, and cloud-native container security (AWS, Kubernetes).
  • Proficiency in Python, Go, or similar languages to architect internal tooling, pipeline automation, and advanced detection/scanning engines.
  • Exceptional written and verbal communication skills, with a demonstrated ability to navigate ambiguity, influence technical leaders, and manage up and out across EPD organizations.

Nice-to-Haves

  • Experience with Kotlin, gRPC, GraphQL, Kubernetes
  • Previous experience in building and scaling security teams
  • Experience with securing distributed systems in AWS and cloud environments
  • Contributions to the wider technical community — open source, public research, CTF participation, blogging, CVEs, or presentations
  • Experience submitting to bug bounty or responsible disclosure programs
  • Published AI security research or contributions to AI security frameworks

Compensation

  • Expected salary range: $240,000 - $300,000 USD
  • Equity and other forms of compensation may be provided as part of a total compensation package.

Skills

Application SecurityPenetration TestingAi SecurityLlm SecurityThreat ModelingAWSKubernetesPythonGoVulnerability Management

Member of Technical Staff, Trust & Safety Engineer

Trust & Safety Engineer building red teaming systems, content moderation infrastructure, and safety tooling for generative AI models. Requires 3+ years software engineering experience with Python/TypeScript and comfort across the stack from model evals to AWS/GCP infrastructure.

240k – 290kUnited StatesSecurity EngineeringRemote3+ YOES3AWS

Staff Security Engineer

Leads technical security design reviews, defines standards for protecting healthcare data, architects automated defenses, and mentors engineering on security practices. Requires exceptional technical judgment in cloud security, AppSec, or data domains.

239k – 275kUnited StatesSecurity EngineeringRemoteAWSWiz

Staff Software Engineer, Product Security

Leads security integration into AI platform, owns critical code reviews for authentication and access control, architects secure tools, and mentors engineers on security practices. Requires 8+ years in product/application security with proven vulnerability remediation track record.

238k – 312kSan Francisco, CASecurity EngineeringHybrid8+ YOEAWSGCP

Staff Software Engineer, Identity & Access Management

Designs and implements identity and access management systems for Snowflake's Data Cloud, focusing on AI security, authentication protocols, and scalable authorization. Requires 10+ years experience with large-scale distributed systems and strong skills in Java/C#/C++.

236k – 339kBellevue, WASecurity EngineeringOn-site10+ YOEC#C++

Staff, Security Engineer (App & Product Sec)

Leads security program as first dedicated hire, building roadmap for cloud, app security, and compliance (HIPAA, SOC 2, HITRUST). Improves AWS/GCP security, vulnerability management, IAM, and embeds security in SDLC for high-growth healthcare tech company. Requires 8+ years experience.

235k – 300kSan Francisco, CA +1Security EngineeringHybrid8+ YOEAWSGCP