Application Security Engineer (X Money)

Palo Alto, CA; Austin, TX; New York, NY; Washington, DC·Posted today
aiinfrastructuremlfintechcybersecuritylogisticspythonrustawsllm
<div class="content-intro"><p><span style="font-family: arial, helvetica, sans-serif;">SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge.&nbsp;</span><span style="font-family: arial, helvetica, sans-serif;">Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. </span><span style="font-family: arial, helvetica, sans-serif;">We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. </span><span style="font-family: arial, helvetica, sans-serif;">All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.</span></p></div><h3 data-pm-slice="1 1 []"><span style="font-family: arial, helvetica, sans-serif;">ABOUT THE ROLE:</span></h3> <p><span style="font-family: arial, helvetica, sans-serif;">We are seeking a skilled and innovative Application Security Engineer to join 𝕏 Money. In this role, you will protect the security and integrity of our payments and financial products throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and systems that move and hold customer funds. Experience securing fintech, payments, digital wallet, ledger, or similar high-value platforms, where fraud, abuse, and unauthorized transfers are a constant concern, is strongly preferred.&nbsp;</span></p> <h3><span style="font-family: arial, helvetica, sans-serif;">RESPONSIBILITIES:</span></h3> <ul> <li>Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in financial applications</li> <li>Design and implement secure coding guidelines and best practices for development teams</li> <li>Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline</li> <li>Perform threat modeling and risk assessments for payments, wallets, ledgers, and related product surfaces, and develop mitigation strategies for fraud, abuse, and unauthorized movement of funds or credits</li> <li>Manage vulnerability tracking and remediation efforts, providing guidance to development teams</li> <li>Manage the bug bounty program, including intake, triage, researcher communication, and coordinated disclosure</li> <li>Support incident response activities related to application security</li> <li>Stay current on emerging threats against financial and cloud-native systems, and continuously strengthen our controls</li> <li>Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs)</li> <li>Design and implement agentic and LLM-based solutions that help detect, investigate, or prevent security problems</li> </ul> <h3><span style="font-family: arial, helvetica, sans-serif;">BASIC QUALIFICATIONS:</span></h3> <ul> <li>Bachelor's degree in Computer Science, Cybersecurity, or a related field</li> <li>3-5 years of experience in application security, with a strong focus on code security practices</li> <li>Experience in payments, money transmission, digital wallets, or related financial platforms</li> <li>Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10)</li> <li>Proficiency in Python or Rust and experience with secure coding practices in these languages</li> <li>Experience securing CI/CD pipelines and implementing DevSecOps practices</li> <li>Familiarity with software supply chain security and SBOM generation tools</li> <li>Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis</li> <li>Experience securing payments, wallets, ledgers, or other high-value transaction systems, including controls against fraud, abuse, and integrity issues</li> <li>Experience designing and implementing agentic and LLM-based solutions for security problems</li> <li>Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences</li> </ul> <h3><span style="font-family: arial, helvetica, sans-serif;">PREFERRED SKILLS AND EXPERIENCE:</span></h3> <ul> <li>Hands-on experience securing applications on AWS; familiarity with other cloud platforms is a plus</li> <li>Relevant security certifications (e.g., BSCP, OSCP, OSWE)</li> <li>Experience managing bug bounty programs</li> <li>Background in data privacy and compliance relevant to financial products and cloud-native applications</li> <li>Experience with GitOps and infrastructure-as-code security</li> <li>Experience building custom security tooling to enhance and automate security processes</li> <li>Contributions to open-source security projects or tools</li> </ul> <h3><span style="font-family: arial, helvetica, sans-serif;"><strong>COMPENSATION AND BENEFITS:</strong></span></h3> <p><span style="font-family: arial, helvetica, sans-serif;">$100,000 - $258,000 USD</span></p> <p><span style="font-family: arial, helvetica, sans-serif;">Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short &amp; long-term disability insurance, life insurance, and various other discounts and perks.</span></p> <h3><strong>ITAR REQUIREMENTS:</strong></h3> <ul> <li>To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR&nbsp;<a href="https://www.pmddtc.state.gov/?id=ddtc_kb_article_page&amp;sys_id=24d528fddbfc930044f9ff621f961987">here</a>.&nbsp;</li> </ul><div class="content-conclusion"><p><em>SpaceXAI is an equal opportunity employer. For details on data processing, view our </em><em><a href="https://x.ai/legal/recruitment-privacy-notice" target="_blank">Recruitment Privacy Notice</a>.</em></p></div>