← Back to list
Job · Principal

Staff Application Security Engineer

Security Engineer • Principal • Remote • Full-time European Union EU/EMEA

Staff-level Application Security Engineer role owning and driving the application security program at a debt-relief fintech, embedding secure development practices across Ruby on Rails, React Native, Python, and Go teams.

Responsibilities

  • Lead and evolve the company's application security strategy, roadmap, and day-to-day operations
  • Serve as the primary AppSec partner for development teams working on Ruby on Rails web apps, React Native mobile apps, and Python and Go projects
  • Provide security guidance during design, development, and code review for new features and projects
  • Drive adoption of secure coding practices and threat modeling across engineering teams
  • Manage and optimize AppSec tooling, including GitHub Advanced Security (SAST, SCA, Secret Scanning), Invicti (DAST), Hadrian (ASM), AppDome (mobile application security), and Cloudflare WAF
  • Improve automation and integration of security tools into CI/CD pipelines
  • Build and maintain secure development standards, playbooks, and training materials
  • Partner with engineering teams during sprint planning and feature design to proactively address risks
  • Conduct security reviews, code assessments, and vulnerability triage with development teams
  • Work with DevOps to ensure secure AWS infrastructure deployments, contributing to hardening ECS, IAM, and networking
  • Lead or support investigation and remediation of application-level vulnerabilities
  • Monitor, prioritize, and track findings from SAST, DAST, and ASM tools

Requirements

  • 8+ years of experience in Application Security, Product Security, or related engineering roles
  • Strong understanding of secure coding practices, common vulnerabilities (OWASP Top 10), and modern SDLC
  • Experience working with cloud-native applications, ideally in AWS
  • Understanding of SSL certificates and cryptographic key management
  • Hands-on experience with SAST, DAST, WAFs, and/or mobile application security tools
  • Ability to partner effectively with developers and influence secure design decisions
  • Familiarity with GitHub-based workflows and CI/CD pipelines

Soft skills

Ability to partner effectively with developersAbility to influence secure design decisionsEnd-to-end ownership of the application security program

About the company

Beyond Finance's mission is to help everyday Americans escape the cycle of crippling debt through compassionate, individualized care, a culture focused on compliance and ethics, and customized financial solutions; the company has helped over 1 million clients.

Similar jobs