Senior Application Security Engineer; Blue Team
Listed on 2026-09-10
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection
Senior Application Security Engineer (Blue Team)
Senior
· Hybrid
· San Francsico, CA, Los Angeles +1
Important: if an employer asks you to log into their system via iCloud or Google, send a code, an SMS or Telegram password, run some code, or install software — refuse. These are signs of fraud.
•••••••
• is transforming the multi-trillion dollar wealth management industry by building an AI platform for wealth professionals. We partner with financial advisors nationwide, empowering them to grow, optimize time and resources, and deliver superior outcomes for their clients.
We're looking for exceptional talent to help us achieve our mission of making financial advice better, more affordable, and accessible to all. If you're passionate about challenging the status quo and want to do the most important work of your life, we'd love to meet you!
But first, our values
Kindness - Kindness doesn’t just equal niceness. We listen to understand. We embrace, and encourage healthy debate and diverse perspectives. We approach conflict openly, honestly, and respectfully.
Brilliance - Humility is the skill we’re most proud of and possessing a growth mindset is always top of mind. We take ownership in everything we touch; regularly using our unique superpowers to reach a common goal as a team. We succeed and fail as one.
Grit - When challenges arise, we stay laser focused on achieving our mission and finding a way forward, even when it’s hard. We are nimble and maintain a sense of urgency, swiftly adapting to change and overcoming obstacles.
About the position
•••••••
• is in the midst of an exciting phase and we’re excited to hire a Senior Application Security Engineer to join our growing Security team. Your expertise will ensure our products are secure — from design and code through the CI/CD pipeline.
This role follows a hybrid schedule, with three days per week onsite in our San Francisco FiDi or Culver City office.
Your impact
- Educate and train development teams on secure coding practices and emerging security threats.
- Perform technical security assessments and code reviews across our Java/Spring services
- Engage in threat modeling to anticipate potential security threats and develop strategies to mitigate them.
- Assist teams in building libraries, repeatable patterns, and paved-road components that ensure security is a part of every new feature.
- Own and tune SAST, DAST, software composition analysis (SCA), and security tooling in CI/CD pipelines; triage findings and drive them to remediation with clear prioritization.
- Partner with engineering to close service-to-service authentication/authorization gaps and other systemic issues.
- Work with Detection & Response and our offensive security engineers to turn findings into durable detections and prevention.
- Contribute to our secure SDLC standards and developer security guardrails.
What you’ll bring
- Experience - 4+ years of experience working as an Application/Product Security Engineer:
- Extensive experience with security assessments, security design reviews, or threat modeling
- Hands-on secure code review (Java/Spring or similar)
- Experience operating SAST/DAST/SCA and secrets-scanning tooling in a CI/CD pipeline
- Strong ability to work independently
- Education - A B.A. / B.S. degree in relevant fields such as Computer Science or Computer Engineering or Information Security or relevant experience
- Technical aptitude - You’re technologically savvy and can easily get up to speed on modern tech stacks (i.e., Java, Spring, Terraform, Kubernetes, etc.)
- Ownership - The pride you put into every aspect of your work is unparalleled and undeniable
- Superb communication - Intentional dialogue is a superpower. You listen as well as you share your perspective with others.
- Resilience - We’re inspired by…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).