CybersecurityJobs.io
← Back to all jobs

Job Description

Lead a hands-on application security program that strengthens fomo Labs’ secure SDLC, tooling, and architecture patterns.

Responsibilities

  • Drive security architecture reviews and threat modeling for new features and major system changes; partner with engineering and product teams from design through launch
  • Own the secure SDLC program, including SAST, DAST, dependency and software composition analysis (SCA), secrets scanning, and CI/CD security gates
  • Conduct deep-dive code reviews and manual penetration testing for high-risk services, APIs, and web applications
  • Design and build internal AppSec tooling and guardrails to help engineers move quickly without increasing risk
  • Run and mature vulnerability management: triage, severity scoring, and driving remediation with engineering owners
  • Manage external pentest vendor relationships and bug bounty programs; convert findings into durable fixes instead of one-off patches
  • Set technical direction on authentication, authorization, API security, and data protection patterns across the product
  • Mentor engineers on secure coding practices and serve as an org-wide point of contact for AppSec questions
  • Support incident response when application-layer issues occur
  • Help define and evolve the AppSec roadmap and related metrics

Requirements

  • 7+ years in security engineering with substantial, recent focus on application security (not primarily corporate/IT security)
  • Strong hands-on experience in secure code review, threat modeling, and common vulnerability classes (including OWASP Top 10, auth/session flaws, SSRF, injection, and business logic flaws)
  • Solid software engineering foundation; able to read and write production code rather than only running scanners
  • Experience building and scaling AppSec tooling and processes at a growing company, including SAST/DAST, SCA, and CI/CD security integration
  • Proven ability to drive security into engineering culture through influence, not only gatekeeping
  • Familiarity with cloud-native environments (AWS, GCP, Azure), container security, and modern API architectures
  • Excellent communication skills to explain risk to engineers and non-technical stakeholders
  • Experience as a technical lead or staff-level IC with high autonomy

Technologies

  • SAST, DAST, SCA, CI/CD
  • OWASP Top 10
  • AWS, GCP, Azure
  • Containers, API architectures

Benefits

  • Competitive cash compensation and equity
  • Comprehensive health insurance (medical, dental, vision) for you and your dependents, including tax savings benefits such as HSAs and FSAs
  • 401(k) with match
  • Group term life insurance
  • Flexible time off
  • Annual company offsites

Nice to Have

  • Experience with bug bounty program management
  • Background in a high-growth consumer or marketplace product

Location: New York, NY (onsite)  |  Compensation: USD 270,000 - 330,000 per yearly

Similar Jobs