Staff Application Security Engineer

Beyond Finance

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

Responsibilities

  • Lead and evolve the company's application security strategy, roadmap, and day-to-day operations
  • Serve as the primary AppSec partner for dev teams working on Ruby on Rails, React Native, Python, and Go
  • Provide security guidance during design, development, and code review
  • Drive adoption of secure coding practices and threat-modeling
  • Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, AppDome, and Cloudflare WAF
  • Improve automation and integration of security tools into CI/CD pipelines
  • Build and maintain secure development standards, playbooks, and training materials
  • Work with DevOps to ensure secure AWS infrastructure deployments and configurations
  • Lead investigation and remediation of application-level vulnerabilities

Requirements

  • 8+ years of experience in Application Security, Product Security, or related engineering roles
  • Strong understanding of secure coding practices and OWASP Top 10
  • Experience with cloud-native applications, ideally in AWS
  • Understanding of SSL certificates and cryptographic key management
  • Hands-on experience with SAST, DAST, WAFs, and mobile application security tools
  • Familiarity with GitHub-based workflows and CI/CD pipelines

Preferred Qualifications

  • Development experience with Ruby on Rails
  • Knowledge of AWS ECS/EKS, container security, and Infrastructure-as-Code (Terraform, CloudFormation)
  • Experience building or maturing an AppSec program from early stages
  • SOAR Automation and scripting experience
  • Experience working in a PCI-compliant environment

About the Company

Beyond Finance helps everyday Americans escape the cycle of debt through compassionate, individualized care and customized financial solutions.

Skills & tools

AppSecAWSRuby on Rails

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 018+ years AppSec experience
  2. 02OWASP Top 10 knowledge
  3. 03AWS experience
  4. 04SAST/DAST experience
  5. 05CI/CD familiarity
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches