Talent.com
Senior Application Security Engineer
Senior Application Security EngineerBrex • San Francisco, CA, United States
Senior Application Security Engineer

Senior Application Security Engineer

Brex • San Francisco, CA, United States
[job_card.variable_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Why join us

Brex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from startups to enterprises — including DoorDash, Flexport, and Compass — use Brex to proactively control spend, reduce costs, and increase efficiency on a global scale.

Working at Brex allows you to push your limits, challenge the status quo, and collaborate with some of the brightest minds in the industry. We’re committed to building a diverse team and inclusive culture and believe your potential should only be limited by how big you can dream. We make this a reality by empowering you with the tools, resources, and support you need to grow your career.

Engineering at Brex

Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It’s an environment where engineering is a craft, and builders become leaders.

What you’ll do

As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will perform code reviews, design reviews, penetration testing, and vulnerability management. You will develop and maintain tooling to perform static and dynamic testing of the Brex platform and tooling which supports secure developer workflows. Application Security is part of our wider Financial Scale organization, which means you will work closely with Security Operations, GRC, Product Security, Front End Platform, IT Infrastructure teams.

We’re looking for individuals with a strong background and interest in penetration testing. You should have a demonstrated ability to find vulnerabilities in complex systems and craft exploits to demonstrate business impact. This role is highly cross functional and collaborative, you will have the opportunity to work with every engineering team across Brex. You should be enthusiastic about working with a variety of backgrounds, roles, and needs. Building a world-class financial service requires world-class security.

Brex is pioneering the next wave of AI-driven financial services for dynamic, high-impact companies like Coinbase, Robinhood, and Anthropic. We're at the early stages of integrating AI across our product suite, this role will have the opportunity to influence and secure the future of AI Security at Brex. You'll be at the forefront of securing our novel AI implementations, identifying attack vectors in agentic-powered features, and partnering with product and engineering teams to build AI capabilities that our customers can trust with their critical financial operations.

Where you’ll work

This role will be based in our San Francisco office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of three coordinated days in the office per week, Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work!

Responsibilities

  • Identifying vulnerabilities, demonstrating business impact, and articulating the risk of specific vulnerabilities to drive prioritization efforts
  • Perform penetration testing and design reviews, looking for vulnerabilities and insecure designs, work with engineering and product to design secure product features
  • Maintain and build internal tools to automate security efforts, perform SAST and DAST testing of the Brex platform, and support secure development practices
  • Build and contribute to a culture of collaborative security excellence through technical leadership, learning sessions, and mentorship within the team and wider organization

Requirements

  • 5+ years work experience in an Application Security or related role
  • Ability to find vulnerabilities in complex systems, demonstrating business impact through custom attack chains
  • Experience with a wide range of secure development activities including— threat modeling, developer education, and incident response
  • Knowledge of Python, scripting languages, and AI / agentic workflows to automate tasks, build tools and improve productivity
  • Collaborative mindset paired with strong written and verbal communication skills
  • Bonus points

  • Proficiency with Kotlin, gRPC, GraphQL, Kubernetes
  • Previous experience as a software engineer
  • Consultancy experience performing web application security reviews
  • Experience with securing distributed systems in AWS and cloud environments
  • Experience with pentesting and securing agentic features and systems
  • Contributions to the wider technical community— open source, public research, mentorship, community organizing, blogging, CVEs, presentations, etc
  • Experience submitting to bug bounty programs or responsible disclosure programs
  • Compensation

    The expected salary range for this role is $192,000 - $240,000. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.

    Please be aware, job-seekers may be at risk of targeting by malicious actors looking for personal data. Brex recruiters will only reach out via or email with a brex.com domain. Any outreach claiming to be from Brex via other sources should be ignored.

    #J-18808-Ljbffr

    [job_alerts.create_a_job]

    Senior Application Security Engineer • San Francisco, CA, United States

    [internal_linking.related_jobs]
    Senior Application Security Engineer

    Senior Application Security Engineer

    Imprint • San Francisco, CA, United States
    [job_card.full_time]
    Imprint is reimagining co-branded credit cards & financial products to be smarter, more rewarding, and truly brand-first. We partner with companies like Rakuten, Booking.H-E-B, Fetch, and Brooks Bro...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Application Security Engineer

    Senior Application Security Engineer

    Zip • San Francisco, CA, United States
    [job_card.full_time]
    The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world. Today, enterprises spend $120T+ per year globally...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Application Security Engineer

    Application Security Engineer

    Cloudflare • San Francisco, California, USA
    [job_card.full_time]
    At Cloudflare we are on a mission to help build a better Internet.Today the company runs one of the worlds largest networks that powers millions of websites and other Internet properties for custom...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Application Security Engineer

    Application Security Engineer

    Perplexity • San Francisco, CA, United States
    [job_card.full_time]
    Perplexity is seeking a highly skilled, experienced and hands‑on Application Security Engineer to join our dynamic security team, revolutionizing the way people search and interact with the interne...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Application Security Engineer - Hybrid / Remote Impact

    Senior Application Security Engineer - Hybrid / Remote Impact

    OpenAI • San Francisco, CA, United States
    [filters.remote]
    [job_card.full_time]
    A leading AI research firm in San Francisco is seeking a Security Engineer for Application Security.The role involves identifying and mitigating security vulnerabilities, conducting assessments, an...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Application Security Engineer

    Senior Application Security Engineer

    Airwallex • San Francisco, CA, United States
    [job_card.full_time]
    Airwallex is the only unified payments and financial platform for global businesses.Powered by our unique combination of proprietary infrastructure and software, we empower over 150,000 businesses ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior & Lead Application Security Engineer

    Senior & Lead Application Security Engineer

    Verticalmove, Inc • San Francisco, CA, United States
    [job_card.full_time]
    Senior & Lead Application Security Engineer.Get AI-powered advice on this job and more exclusive features.ATTN - PLEASE READ CAREFULLY : WE CAN NOT SPONSOR NEW VISAS OR TRANSFER EXISTING VISAS.AT TH...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Application Security Engineer : Build Secure Cloud Apps

    Senior Application Security Engineer : Build Secure Cloud Apps

    CloudFlare • San Francisco, CA, United States
    [job_card.full_time]
    A leading cybersecurity company is seeking a Senior Application Security Engineer.This role involves working closely with engineering teams to secure products, assess new features, and contribute t...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Application Security Engineer

    Senior Application Security Engineer

    Cloudflare, Inc. • San Francisco, CA, United States
    [job_card.full_time]
    At Cloudflare, we are on a mission to help build a better Internet.Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for cust...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Software Engineer - Identity & Security Products

    Senior Software Engineer - Identity & Security Products

    Twilio • San Francisco, CA, United States
    [job_card.full_time]
    At Twilio, we're shaping the future of communications, all from the comfort of our homes.We deliver innovative solutions to. As we continue to revolutionize how the world interacts, we're acquiring ...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Application Security Engineer

    Senior Application Security Engineer

    Altruist • San Francisco, CA, United States
    [job_card.full_time]
    Altruist is transforming the multi-trillion dollar wealth management industry by building an AI platform for wealth professionals. We partner with financial advisors nationwide, empowering them to g...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Application Security Engineer

    Senior Application Security Engineer

    Fastly • San Francisco, CA, United States
    [job_card.full_time]
    Fastly helps people stay better connected with the things they love.Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing,...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Security Engineer, Application & Platform Security

    Senior Security Engineer, Application & Platform Security

    Sentry • San Francisco, CA, United States
    [job_card.full_time]
    Bad software is everywhere, and we’re tired of it.Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology. With more than $217 million in fun...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Security Engineer, Application & Platform Security

    Senior Security Engineer, Application & Platform Security

    Sentry.io • San Francisco, CA, United States
    [job_card.full_time]
    Bad software is everywhere, and we’re tired of it.Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology. With more than $217 million in fun...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Remote Senior Application Security Engineer - Zetachain

    Remote Senior Application Security Engineer - Zetachain

    Zetachain • San Francisco, CA, United States
    [filters.remote]
    [job_card.full_time]
    Application Security or DevSecOps Engineer with broad set of experiences to have an early and formative impact in many areas of the ZetaChain security program. The ideal candidate will be responsibl...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Application Security Engineer

    Application Security Engineer

    AtoB • San Francisco, CA, United States
    [job_card.full_time]
    Our mission is to modernize the payments infrastructure for trucking and logistics.We're building Stripe for Transportation, centering our customers in every way and offering them world-class custo...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Application Security Engineer (Secure-by-Default)

    Senior Application Security Engineer (Secure-by-Default)

    Pantera Capital • San Francisco, CA, United States
    [job_card.full_time]
    Pantera Capital is seeking an experienced Application Security Engineer to join their team in San Francisco.This pivotal role will focus on designing security solutions that foster innovation while...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Application Security Engineer

    Application Security Engineer

    Benchling • San Francisco, California, USA
    [job_card.full_time]
    Biotechnology is rewriting life as we know it from the medicines we take to the crops we grow the materials we wear and the household goods that we rely on every day. But moving at the new speed of ...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]