← Back to list
Job · Principal

Staff Application Security Engineer

Security Engineer • Principal • Remote • Full-time • European Union EU/EMEA

Staff-level Application Security Engineer role owning and driving the application security program at a debt-relief fintech, embedding secure development practices across Ruby on Rails, React Native, Python, and Go teams.

Responsibilities

  • ▹Lead and evolve the company's application security strategy, roadmap, and day-to-day operations
  • ▹Serve as the primary AppSec partner for development teams working on Ruby on Rails web apps, React Native mobile apps, and Python and Go projects
  • ▹Provide security guidance during design, development, and code review for new features and projects
  • ▹Drive adoption of secure coding practices and threat modeling across engineering teams
  • ▹Manage and optimize AppSec tooling, including GitHub Advanced Security (SAST, SCA, Secret Scanning), Invicti (DAST), Hadrian (ASM), AppDome (mobile application security), and Cloudflare WAF
  • ▹Improve automation and integration of security tools into CI/CD pipelines
  • ▹Build and maintain secure development standards, playbooks, and training materials
  • ▹Partner with engineering teams during sprint planning and feature design to proactively address risks
  • ▹Conduct security reviews, code assessments, and vulnerability triage with development teams
  • ▹Work with DevOps to ensure secure AWS infrastructure deployments, contributing to hardening ECS, IAM, and networking
  • ▹Lead or support investigation and remediation of application-level vulnerabilities
  • ▹Monitor, prioritize, and track findings from SAST, DAST, and ASM tools

Requirements

  • ▹8+ years of experience in Application Security, Product Security, or related engineering roles
  • ▹Strong understanding of secure coding practices, common vulnerabilities (OWASP Top 10), and modern SDLC
  • ▹Experience working with cloud-native applications, ideally in AWS
  • ▹Understanding of SSL certificates and cryptographic key management
  • ▹Hands-on experience with SAST, DAST, WAFs, and/or mobile application security tools
  • ▹Ability to partner effectively with developers and influence secure design decisions
  • ▹Familiarity with GitHub-based workflows and CI/CD pipelines

Soft skills

Ability to partner effectively with developersAbility to influence secure design decisionsEnd-to-end ownership of the application security program

About the company

Beyond Finance's mission is to help everyday Americans escape the cycle of crippling debt through compassionate, individualized care, a culture focused on compliance and ethics, and customized financial solutions; the company has helped over 1 million clients.

Similar jobs