Senior Application Security Engineer
Core
Partner with engineering, product, and business teams to design and build secure crypto products, embedding security judgment into requirements, architecture, and code.
Role type
Senior IC application security engineer (crypto/Web3)
Builds
AppSec tooling including AI agents for secure design/code review, AI-enhanced SAST/DAST pipelines, and automation to eliminate security toil
Domain
Financial services / Cryptocurrency / Web3
Deliverable
production ML models | product features
Required skills
Threat modeling, secure code review, penetration testing, secure design reviews, vulnerability analysis (SSRF, race conditions, privilege escalations), security tooling development, scripting (Python, Scala, C++, JavaScript)
Preferred skills
AI application security tooling, supply chain security, SLSA/OWASP SPVS frameworks, microservice architectures, cloud-native environments
Technologies
Python, Scala, C++, JavaScript, SAST, DAST, CI/CD pipelines
Responsibilities
Lead secure design reviews, threat modeling, code review, and penetration testing for high-risk products; Build and ship AppSec tooling including AI agents and automated pipelines; Partner with engineering teams to remediate vulnerabilities and drive secure coding practices
Seniority
Senior, hands-on IC
