We're empowering employees anywhere to make better financial decisions. Need Help? -> Email us at support@brex.
Senior Application Security Engineer
Location
California + 2 moreAll locations: California | New York | Washington
Posted
106 days ago
Salary
$192K - $240K / year
Seniority
Senior
Job Description
Senior Application Security Engineer
Brex
• Identifying vulnerabilities, demonstrating business impact, and articulating the risk of specific vulnerabilities to drive prioritization efforts • Perform penetration testing and design reviews, looking for vulnerabilities and insecure designs, work with engineering and product to design secure product features • Maintain and build internal tools to automate security efforts, perform SAST and DAST testing of the Brex platform, and support secure development practices • Build and contribute to a culture of collaborative security excellence through technical leadership, learning sessions, and mentorship within the team and wider organization
Job Requirements
- 5+ years work experience in an Application Security or related role
- Ability to find vulnerabilities in complex systems, demonstrating business impact through custom attack chains
- Experience with a wide range of secure development activities including— threat modeling, developer education, and incident response
- Knowledge of Python, scripting languages, and AI/agentic workflows to automate tasks, build tools and improve productivity
- Collaborative mindset paired with strong written and verbal communication skills
Benefits
- Health insurance
- 401(k) matching
- Flexible work hours
- Paid time off
- Remote work options
Related Guides
Related Categories
Related Job Pages
More Application Engineer Jobs
Application Security Engineer
Rubrik, Inc.As the pioneer in Zero Trust Data Security™, we enable cyber and operational resilience for enterprises and governments.
• Integrate security controls and practices into Rubrik’s secure SDLC and collaborate with Engineering to embed security into every phase of the development process. • Perform security assessments of applications, identifying vulnerabilities and weaknesses through both automated and manual testing techniques. • Carry out detailed analysis of identified vulnerabilities to ensure high fidelity findings are provided to Engineering teams. • Assist in identifying and implementing frictionless "shift-left" strategies to seamlessly and proactively prevent vulnerabilities earlier in the SDLC. • Aid in the collection, management and reporting of key Application Security metrics to track progress and identify trends. • Analyze and harden existing applications, automation, and deployment processes • Participate in security design reviews and threat modeling of proposed products and feature releases • Work with development teams, operations, governance, and other stakeholders to document security guidance, processes and standards for Rubrik products and services
• Provide technical sales support & solutioning • Review project specifications and technical requirements • Act as the technical SME, partnering with Sales • Provide pre-sales technical support to sales and tendering teams • Design solutions for diesel generators and power plant projects • Develop and deliver technical proposals for bids and tenders • Participate in customer presentations and negotiations • Ensure compliance with local regulations, standards, and codes
• Lead technical support and drive innovation for engineering tools and database systems while ensuring compliance with required standards and regulations • Collaborate with engineering teams to identify needs, develop solutions, and enhance design productivity • Administer and support ECAD tools and infrastructure (install, configure, debug; client/server issue resolution) • Integrate ECAD with enterprise systems (Windchill and/or Teamcenter PLM, ERP, manufacturing) and manage ECAD libraries/databases • Automate workflows and CI/CD (Ansible, Jenkins, OpenShift/Kubernetes, JFrog); script in Java/Python • Architect and operate AWS environments for servers/workstations; manage licensing and identity (LDAP/SAML) • Ensure cybersecurity compliance and network fundamentals (switching/routing); align to company standards • Support and optimize databases (MSSQL, MySQL, PostgreSQL, Oracle RDS, Cassandra) • Evaluate and implement new tools/technologies; provide documentation and training to engineering teams • Support key applications: Siemens Xpedition, EDM, HyperLynx, OneSim, Valor, Capital; Altium Designer; Relyence
• conduct security assessments using both Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies • collaborate with software development teams to integrate security into the development life cycle • conduct security assessments of web, mobile, and other applications • analyze security assessment results to identify vulnerabilities and provide guidance on remediation • design and implement secure software development practices, including threat modeling and secure coding standards • stay current with security threats, trends, and technologies • conduct application security investigations and provide recommendations to mitigate risk • maintain security documentation




