Senior Application Security Engineer
Beyondfinance · Remote
About this role
**Senior Application Security Engineer** **About Beyond Finance** Beyond Finance helps everyday Americans escape the cycle of crippling debt and build a brighter financial future through compassionate, individualized care, a compliance-and-ethics culture, supportive user-centric technology, and customized financial solutions—supporting over 1 million clients. **Role Overview** As the Application Security Engineer, you’ll be the primary owner and driver of the application security program. You’ll work hands-on with engineering teams to embed secure development practices, improve tooling and automation, and guide security considerations for new features, architectures, and services. This is a high-impact role where you’ll shape the future of AppSec at a company that treats security as a core part of product quality. --- ## What You’ll Do **Application Security Ownership** - Lead and evolve the company’s application security strategy, roadmap, and day-to-day operations. - Serve as the primary AppSec partner for multiple dev teams building Ruby on Rails web apps, React Native mobile apps, and other projects (including Python and Go). - Provide security guidance during design, development, and code review for new features and projects. - Drive adoption of secure coding practices and threat modeling across engineering teams. **Tooling & Automation** - Manage and optimize existing AppSec tooling, including: - GitHub Advanced Security (SAST, SCA, Secret Scanning) - Invicti (DAST) - Hadrian (ASM) - AppDome (mobile application security) - Cloudflare WAF - Improve automation and integrate security tools into CI/CD pipelines. - Identify and implement additional tools or processes to strengthen the security posture. **Secure SDLC & Developer Enablement** - Build and maintain secure development standards, playbooks, and training materials. - Partner with engineering teams during sprint planning and feature design to proactively address risks. - Conduct security reviews, code assessments, and vulnerability triage with development teams. **Cloud & DevOps Collaboration** - Work with DevOps to ensure secure AWS infrastructure deployments and configurations. - Contribute to hardening efforts across ECS, IAM, networking, and supporting cloud services. - Assist in designing and maintaining secure CI/CD workflows. **Incident & Vulnerability Management** - Lead or support investigation and remediation of application-level vulnerabilities. - Monitor, prioritize, and track findings from SAST/DAST/ASM tools. - Collaborate with engineering to ensure timely and effective remediation. --- ## What We’re Looking For **Required Skills & Experience** - 3–7+ years of experience in Application Security, Product Security, or related engineering roles. - Strong understanding of secure coding practices, common vulnerabilities (OWASP Top 10), and modern SDLC. - Experience with cloud-native applications, ideally in AWS. - Understanding of SSL certificates and cryptographic key management. - Hands-on experience with SAST, DAST, WAFs, and/or mobile application security tools. - Ability to partner effectively with developers and influence secure design decisions. - Familiarity with GitHub-based workflows and CI/CD pipelines. **Nice to Have** - Development experience with Ruby on Rails or similar dynamic languages. - Knowledge of AWS ECS/EKS, container security, secrets management, and infrastructure-as-code (CloudFormation, Terraform). - Experience building
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.