Application Security Engineer (X Money)
xAI · Palo Alto, CA; Austin, TX; New York, NY; Washington, DC
About this role
**SpaceXAI — Application Security Engineer (X Money)** *SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge.* ## About the Role We’re seeking a skilled and innovative **Application Security Engineer** to join **X Money**. You’ll protect the security and integrity of our **payments and financial products** throughout the software development lifecycle—especially around **code security**, **CI/CD pipelines**, and systems that **move and hold customer funds**. Experience securing **fintech / payments / digital wallet / ledger** (or similar high-value platforms) where **fraud, abuse, and unauthorized transfers** are constant concerns is strongly preferred. ## Responsibilities - Conduct in-depth **code reviews** and **static analysis** to identify and mitigate security vulnerabilities in financial applications - Design and implement **secure coding guidelines** and best practices for development teams - Collaborate with development teams to integrate security practices throughout the **CI/CD pipeline** - Perform **threat modeling** and **risk assessments** for payments, wallets, ledgers, and related product surfaces; develop mitigations for fraud, abuse, and unauthorized movement of funds/credits - Manage **vulnerability tracking** and **remediation**, providing guidance to development teams - Manage the **bug bounty program** (intake, triage, researcher communication, coordinated disclosure) - Support **incident response** activities related to application security - Stay current on emerging threats to **financial** and **cloud-native** systems; continuously strengthen controls - Evaluate and secure **software supply chains**, including producing and maintaining **SBOMs (Software Bills of Materials)** - Design and implement **agentic and LLM-based solutions** to help detect, investigate, or prevent security problems ## Basic Qualifications - Bachelor’s degree in **Computer Science, Cybersecurity,** or related field - **3–5 years** of experience in **application security**, with a strong focus on **code security** - Experience in **payments**, **money transmission**, **digital wallets**, or related financial platforms - Deep understanding of **secure coding practices**, application security frameworks, and common vulnerabilities (e.g., **OWASP Top 10**) - Proficiency in **Python or Rust** and experience with secure coding practices in these languages - Experience securing **CI/CD pipelines** and implementing **DevSecOps** practices - Familiarity with **software supply chain security** and **SBOM** generation tools - Experience with security testing tools (e.g., **Burp Suite**, **OWASP ZAP**) and static/dynamic code analysis - Experience securing **payments/wallets/ledgers** or other high-value transaction systems, including controls against fraud/abuse/integrity issues - Experience designing and implementing **agentic and LLM-based solutions** for security problems - Excellent communication skills; able to explain complex security issues to technical and non-technical audiences ## Preferred Skills and Experience - Hands-on experience securing applications on **AWS** (other cloud platforms a plus) - Relevant security certifications (e.g., **BSCP, OSCP, OSWE**) - Experience managing **bug bounty programs** - Background in **data privacy** and compliance relevant to financial products and cloud-native applications - Experience with **GitOps** and **infrastruct
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.