S
Application Security Engineer
Application Security
Burp Suite
Ci/cd Security
Cybersecurity Tools
DevSecOps
Engineer
Gitops
Information Security
InfoSec
Infrastructure As Code Security
Owasp
Owasp Zap
Secure Application Development
Security
Security Automation
Security Testing
Software Security
Software Supply Chain
Threat Modeling
Web App Security Testing
Job Description
SpaceXAI is hiring an Application Security Engineer in Austin, TX (onsite) to secure payments and financial products across the software development lifecycle.
Responsibilities
- Run in-depth code reviews and static analysis to find and address vulnerabilities in financial applications
- Create and implement secure coding guidelines and best practices for development teams
- Partner with engineering teams to embed security practices into CI/CD pipelines
- Lead threat modeling and risk assessments for payments, wallets, ledgers, and related surfaces
- Develop mitigation strategies for fraud, abuse, and unauthorized movement of funds or credits
- Own vulnerability tracking and remediation, including guidance to development teams
- Manage the bug bounty program: intake, triage, researcher communication, and coordinated disclosure
- Support application security incident response activities
- Monitor emerging threats targeting financial and cloud-native systems and strengthen controls continuously
- Evaluate and secure software supply chains, including creating and maintaining Software Bills of Materials (SBOMs)
- Design and implement agentic and LLM-based solutions to detect, investigate, or prevent security issues
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field
- 3-5 years of experience in application security with a strong focus on code security practices
- Experience in payments, money transmission, digital wallets, or related financial platforms
- Deep understanding of secure coding, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10)
- Proficiency in Python or Rust and secure coding practices in these languages
- Experience securing CI/CD pipelines and implementing DevSecOps
- Familiarity with software supply chain security and SBOM generation tools
- Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic analysis
- Experience securing payments, wallets, ledgers, or other high-value transaction systems, including controls against fraud, abuse, and integrity issues
- Experience designing and implementing agentic and LLM-based solutions for security problems
- Excellent communication skills for explaining complex security topics to technical and non-technical audiences
Technologies
- Python, Rust
- OWASP Top 10
- Burp Suite, OWASP ZAP
- Software Bills of Materials (SBOMs)
- DevSecOps, CI/CD pipelines
- agentic solutions, LLM-based solutions
- GitOps
- infrastructure-as-code
Benefits
- Equity
- Comprehensive medical, vision, and dental coverage
- Access to a 401(k) retirement plan
- Short & long-term disability insurance
- Life insurance
- Various other discounts and perks
Preferred Skills and Experience
- Hands-on experience securing applications on AWS (familiarity with other cloud platforms is a plus)
- Relevant security certifications (e.g., BSCP, OSCP, OSWE)
- Experience managing bug bounty programs
- Background in data privacy and compliance relevant to financial products and cloud-native applications
- Experience with GitOps and infrastructure-as-code security
- Experience building custom security tooling to enhance and automate security processes
- Contributions to open-source security projects or tools
Compensation
- $100,000 - $258,000 USD per year
- Base salary is part of a total rewards package that includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k), short & long-term disability insurance, life insurance, and various other discounts and perks
ITAR Requirements
- To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State.
- Learn more about the ITAR here