Staff Security Engineer, Application Security
Senior
Application Security
Cloud Platforms
Cloud Security
Data Security
DevSecOps
Dynamic Application Security Testing
Engineer
Facilities Management
Information Security
InfoSec
Management
Project Management
Risk Governance
Risk Management
Secure Software Development Lifecycle
Security
Security Assurance
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Software Security
Solution Architecture
Job Description
Lead a hands-on application security program that strengthens fomo Labs’ secure SDLC, tooling, and architecture patterns.
Responsibilities
- Drive security architecture reviews and threat modeling for new features and major system changes; partner with engineering and product teams from design through launch
- Own the secure SDLC program, including SAST, DAST, dependency and software composition analysis (SCA), secrets scanning, and CI/CD security gates
- Conduct deep-dive code reviews and manual penetration testing for high-risk services, APIs, and web applications
- Design and build internal AppSec tooling and guardrails to help engineers move quickly without increasing risk
- Run and mature vulnerability management: triage, severity scoring, and driving remediation with engineering owners
- Manage external pentest vendor relationships and bug bounty programs; convert findings into durable fixes instead of one-off patches
- Set technical direction on authentication, authorization, API security, and data protection patterns across the product
- Mentor engineers on secure coding practices and serve as an org-wide point of contact for AppSec questions
- Support incident response when application-layer issues occur
- Help define and evolve the AppSec roadmap and related metrics
Requirements
- 7+ years in security engineering with substantial, recent focus on application security (not primarily corporate/IT security)
- Strong hands-on experience in secure code review, threat modeling, and common vulnerability classes (including OWASP Top 10, auth/session flaws, SSRF, injection, and business logic flaws)
- Solid software engineering foundation; able to read and write production code rather than only running scanners
- Experience building and scaling AppSec tooling and processes at a growing company, including SAST/DAST, SCA, and CI/CD security integration
- Proven ability to drive security into engineering culture through influence, not only gatekeeping
- Familiarity with cloud-native environments (AWS, GCP, Azure), container security, and modern API architectures
- Excellent communication skills to explain risk to engineers and non-technical stakeholders
- Experience as a technical lead or staff-level IC with high autonomy
Technologies
- SAST, DAST, SCA, CI/CD
- OWASP Top 10
- AWS, GCP, Azure
- Containers, API architectures
Benefits
- Competitive cash compensation and equity
- Comprehensive health insurance (medical, dental, vision) for you and your dependents, including tax savings benefits such as HSAs and FSAs
- 401(k) with match
- Group term life insurance
- Flexible time off
- Annual company offsites
Nice to Have
- Experience with bug bounty program management
- Background in a high-growth consumer or marketplace product
Location: New York, NY (onsite) | Compensation: USD 270,000 - 330,000 per yearly
Similar Jobs
A