Staff Application Security Engineer
Job Description
Gemini Trust Company’s AppSec team is focused on protecting key and high-impact attack surfaces across the Gemini ecosystem, including on-chain systems, exchange environments, and credit card workflows. In this hybrid role based in New York, you will set the technical direction for application security strategy while helping scale an agentic secure development lifecycle using purpose-built AI.
As a Staff Application Security Engineer, you will work alongside senior engineering leadership with significant autonomy, partnering across Security, Engineering, and Product to strengthen how critical systems are designed, reviewed, tested, and hardened over time.
What you’ll do
- Own and evolve Gemini Secure Software Development Lifecycle guardrails as an application security subject matter expert
- Lead architecture reviews, threat modeling, code reviews, and penetration testing for high-risk applications and services
- Design and build AI agents across the SDLC, including automated threat modeling during design, AI-driven secure code generation and review, and efforts to reduce AppSec toil
- Create and deliver hands-on application security training to enable engineers at scale
- Participate in the Application Security on-call rotation and lead post-incident hardening activities
What you bring
- Proven ability to run design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset
- Strong application security fundamentals and familiarity with common vulnerabilities such as SSRF, race conditions, and privilege escalations
- Deep code review experience in Scala, Java, Go, or other common languages, plus hands-on experience in at least Python, Go, or similar for building; comfortable reviewing production services written in other languages
- Experience implementing custom application security detection and prevention controls beyond the OWASP Top 10
- Familiarity with highly regulated environments (financial services, fintech, crypto, or equivalent), including the ability to understand business objectives and security risk in context
- Strong cross-functional communication and collaboration with Security, Engineering, and Product teams
- Typically 7-10+ years of experience (or equivalent impact) in application security, product security, or a similar function
Tools and focus areas
- Scala, Java, Go, Python
- OWASP Top 10, SSRF
- SLSA, OWASP SPVS
Bonus and benefits
- Competitive starting pay
- Discretionary annual bonus
- Long-term incentive via a new hire equity grant
- Comprehensive health plans
- 401K with company matching
- Paid Parental Leave
- Flexible time off
Additional preferred qualifications
- Experience building AI application security tooling using agents or related skills
- Experience with supply chain security, common frameworks such as SLSA and OWASP SPVS, and other CI/CD security controls
- Experience preventing application security vulnerabilities at scale through secure design patterns, automated tooling, or frameworks
- Experience with microservice architectures and cloud-native environments
Salary and location
- Location: New York, NY (hybrid)
- Base salary range (State of New York): USD 168,000 - 240,000 per year
- The stated range does not include the discretionary bonus or equity package.
- Compensation is determined based on factors including skillset, experience, job scope, and current market data.
- Hybrid work in the United States: onboarding is required in-person at one of Gemini’s office locations.
Equal Employment Opportunity
Gemini Trust Company is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. If you need an accommodation to apply, contact the People Team.