Senior Application Security Engineer (Red Team)
Core
Red team offensive security engineer who continuously attacks web, API, mobile, and cloud infrastructure to break security controls and build better defenses.
Role type
Senior IC application security engineer (red team)
Builds
Secure web applications, APIs, Android/iOS mobile apps, and cloud infrastructure for a wealth management AI platform
Domain
Fintech / Wealth Management / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Web application pentesting, API security testing, Mobile application pentesting (Android/iOS), Cloud pentesting, Identity-focused offensive testing, Purple-team exercises, Offensive tooling development, Phishing and social-engineering assessment, Risk rating and remediation guidance
Preferred skills
Regulated environment experience (fintech), OWASP MASVS knowledge, Adversary emulation experience, OSCP/OSWE/GXPN certifications
Technologies
Burp Suite, Java, Spring, Terraform, Kubernetes
Responsibilities
Pentest web applications, APIs, mobile apps, and cloud infrastructure; Conduct authorization and exploitability assessments on high-risk attack paths; Run purple-team exercises with Detection & Response; Develop offensive tooling and testing playbooks; Document findings with reproducible PoCs and actionable remediation
Seniority
Senior, hands-on IC