[All remote jobs](https://jobicy.com/jobs.md)[![Beyond Finance logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/68cd015e123539d873279c7b82f1ca6a.jpg)](https://jobicy.com/company/beyond-finance.md)[Beyond Finance](https://jobicy.com/company/beyond-finance.md)

# Senior Application Security Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/beyond-finance.md)ShareRemote from🌐 AnywhereSalaryUSD 140k–165k / yrDepartment[Cybersecurity](https://jobicy.com/categories/cybersecurity.md)EmploymentFull TimeExperienceSeniorPublished6 Oct 2026Apply before5 Nov 2026Listing views41Application actions3Application toolkit

## Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

## The role, at a glance.

Beyond Finance is seeking a Senior Application Security Engineer to own and mature its application security program across web, mobile, cloud, and CI/CD environments. The role partners closely with engineering teams to embed secure design, threat modeling, secure coding practices, and vulnerability remediation into the SDLC. Core tooling includes GitHub Advanced Security, Invicti, Hadrian, AppDome, Cloudflare WAF, and AWS-focused security controls. The engineer will also help harden AWS infrastructure, improve security automation, and lead or support application-level incident and vulnerability response. This is a high-impact individual-contributor role requiring strong technical judgment and developer-facing communication.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

4/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThe role requires broad hands-on AppSec expertise spanning code review, cloud security, mobile security, CI/CD automation, and program ownership. It also demands independent prioritization and the ability to influence multiple engineering teams without relying solely on security gates.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$152,500US market range$130k–$180k0$198k

AI insightThe disclosed base salary range is $140,000–$165,000 USD yearly, with a midpoint of $152,500. This is competitive for a US-based senior application security engineer responsible for program ownership; a typical US market base-salary range is approximately $130,000–$180,000, varying by location, cloud security depth, and leadership scope. Annual bonus eligibility is additional compensation and is not included in the base-salary calculation.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Application Security](https://jobicy.com/jobs?search_keywords=Application%20Security.md)[Secure SDLC](https://jobicy.com/jobs?search_keywords=Secure%20SDLC.md)[Threat Modeling](https://jobicy.com/jobs?search_keywords=Threat%20Modeling.md)[OWASP Top 10](https://jobicy.com/jobs?search_keywords=OWASP%20Top%2010.md)[SAST](https://jobicy.com/jobs?search_keywords=SAST.md)[DAST](https://jobicy.com/jobs?search_keywords=DAST.md)[AWS Security](https://jobicy.com/jobs?search_keywords=AWS%20Security.md)[CI/CD Security](https://jobicy.com/jobs?search_keywords=CICD%20Security.md)[Vulnerability Management](https://jobicy.com/jobs?search_keywords=Vulnerability%20Management.md)[Cloudflare WAF](https://jobicy.com/jobs?search_keywords=Cloudflare%20WAF.md)

Sample interview questionsHow would you prioritize findings from SAST, DAST, secret-scanning, and attack-surface-management tools?I would first validate findings and prioritize them using exploitability, asset exposure, data sensitivity, business impact, and the availability of compensating controls. Internet-facing critical issues, exposed secrets, and vulnerabilities with known exploitation paths receive immediate attention, while lower-risk findings are tracked with risk-based remediation SLAs.

Describe how you would introduce threat modeling to teams that have not used it consistently.

I would begin with lightweight, repeatable sessions during design or sprint planning for higher-risk changes. Using a simple architecture diagram and an approach such as STRIDE, I would identify trust boundaries, abuse cases, and practical mitigations, then turn the results into actionable engineering work rather than a separate compliance artifact.

What controls would you implement to secure a GitHub-based CI/CD pipeline?

I would use branch protection, required reviews, least-privilege GitHub Actions permissions, protected environments, dependency and secret scanning, signed or trusted build artifacts, and short-lived cloud credentials through OIDC. I would also integrate SAST and infrastructure-as-code checks with clear triage paths so developers can remediate issues efficiently.

How would you partner with an engineering team when a critical vulnerability cannot be remediated immediately?

I would clarify the technical and business risk, document the affected scope, and work with the team on compensating controls such as WAF rules, feature restrictions, network segmentation, monitoring, or temporary access limitations. I would establish an accountable owner and time-bound remediation plan, while communicating residual risk to the appropriate stakeholders.

How would you assess the security of a new Ruby on Rails or React Native feature before release?

I would review the architecture and data flows, identify authentication, authorization, input-validation, storage, and third-party integration risks, and conduct targeted code and configuration review. I would verify applicable automated scans, test for common OWASP issues, confirm secrets and certificates are handled correctly, and ensure logging and remediation ownership are in place before release.

Opportunity details

## About this role.

At Beyond Finance, we’ve made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care, a culture focused on compliance and ethics, supportive user-centric technology, and customized financial solutions, we’ve helped over 1 million clients on their path to a brighter future.

While we’re proud of what we’ve already accomplished, we’re searching for new collaborators to help us get to the next level! If you’re looking to join a forward-thinking, rapidly growing organization with helping people as its number one goal, we want to hear from you.

### Role Overview

As our Application Security Engineer, you will be the primary owner and driver of our application security program. You’ll work hands-on with engineering teams to embed secure development practices, improve tooling and automation, and guide security considerations for new features, architectures, and services.

This is a high-impact role where you’ll shape the future of AppSec at a company that values security as a core part of product quality.

### What You’ll Do

Application Security Ownership

* Lead and evolve the company’s application security strategy, roadmap, and day-to-day operations.
* Serve as the primary AppSec partner for numerous dev teams working on Ruby on Rails web apps, React Native mobile apps, and various other projects including Python and Go.
* Provide security guidance during design, development, and code review for new features and projects.
* Drive adoption of secure coding practices and threat-modeling across engineering teams.

Tooling & Automation

* Manage and optimize existing AppSec tooling, including:

* GitHub Advanced Security (SAST, SCA, Secret Scanning)
* Invicti (DAST)
* Hadrian (ASM)
* AppDome (mobile application security)
* Cloudflare WAF

* Improve automation and integration of security tools into CI/CD pipelines.
* Identify and implement additional tools or processes to strengthen the security posture.

Secure SDLC & Developer Enablement

* Build and maintain secure development standards, playbooks, and training materials.
* Partner with engineering teams during sprint planning and feature design to proactively address risks.
* Conduct security reviews, code assessments, and vulnerability triage with development teams.

Cloud & DevOps Collaboration

* Work with DevOps to ensure secure AWS infrastructure deployments and configurations.
* Contribute to hardening efforts across ECS, IAM, networking, and supporting cloud services.
* Assist in designing and maintaining secure CI/CD workflows.

Incident & Vulnerability Management

* Lead or support investigation and remediation of application-level vulnerabilities.
* Monitor, prioritize, and track findings from SAST/DAST/ASM tools.
* Collaborate with engineering to ensure timely and effective remediation.

### What We’re Looking For

Required Skills & Experience

* 3-7+ years of experience in Application Security, Product Security, or related engineering roles.
* Strong understanding of secure coding practices, common vulnerabilities (OWASP Top 10), and modern SDLC.
* Experience working with cloud-native applications, ideally in AWS.
* Understanding of SSL certificates & cryptographic key management.
* Hands-on experience with SAST, DAST, WAFs, and/or mobile application security tools.
* Ability to partner effectively with developers and influence secure design decisions.
* Familiarity with GitHub-based workflows and CI/CD pipelines.

Nice to Have

* Development experience with Ruby on Rails or similar dynamic languages.
* Knowledge of AWS ECS/EKS, container security, secrets management and infrastructure-as-code (CloudFormation, Terraform).
* Experience building or maturing an AppSec program from early stages.
* SOAR Automation & Scripting experience.
* Experience working in a PCI-compliant environment working with annual reporting needs.

### The Ideal Candidate

The ideal candidate measures success by reduced risk, not tickets closed, and reaches for secure design and simple guardrails before another scanner or gate. They think like an attacker but bring a developer mindset to their partnership with engineering, connecting the dots across application code, cloud infrastructure, and the pipeline rather than treating each as a separate domain. Engineers trust their technical judgment, and when something is blocked, they come with a proposed path forward.

#LI-LB2

The base annual salary range is listed below. This role is eligible for additional incentives, including an annual bonus.

Base Salary Range

$140,000—$165,000 USD

Why Join Us?

While you make a difference for others, we’ll work to make a difference for you, providing an uplifting, collaborative work environment and benefits that reflect your value to us. For eligible full-time employees, we offer:

* Considerable employer contributions for health, dental, and vision programs
* Generous PTO, paid holidays, and paid parental leave
* 401(k) matching program
* Merit advancement opportunities
* Career development & training

And finally, our team spirit and culture! We cultivate an environment of community, connection, and belonging across our entire organization.

Beyond Finance does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job positions. No fee will be paid to their parties who submit unsolicited candidates directly to Beyond Finance employees or the Beyond Finance HR team. No placement fee will be paid to any third party unless such a request has been made by the Beyond HR team.

Show more

[Apply now >](https://jobicy.com/jobs/154682-senior-application-security-engineer-3.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

*
![Five9 logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/7c3d754e-221.png)
Five9 Oct 6  New

### [Senior Information Security Engineer](https://jobicy.com/jobs/154681-senior-information-security-engineer.md)

Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide. Living our values…

*
![Five9 logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/7c3d754e-221.png)
Five9 Oct 6  New

### [Cloud Governance Engineer](https://jobicy.com/jobs/154675-cloud-governance-engineer.md)

Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide. Living our values…

*
![Collibra logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/25583c1c-221.jpg)
Collibra Oct 5  New

### [Engineer, Security Operations & Engineering](https://jobicy.com/jobs/154592-engineer-security-operations-engineering.md)

Joining Collibra’s Security Operations & Engineering team This is an opportunity to work in the Security Operations & Engineering team within the growing Collibra Security Organization.Security Engineers at Collibra design,…

*
![HackerOne logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8937d355-221.png)
HackerOne Oct 5  New

### [Senior Director, Community](https://jobicy.com/jobs/152527-senior-director-community.md)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to…

*
![HackerOne logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8937d355-221.png)
HackerOne Oct 5  New

### [Product Security Analyst](https://jobicy.com/jobs/152523-product-security-analyst.md)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK Oct 4

### [Blockchain Security Expert – AI Track](https://jobicy.com/jobs/152451-blockchain-security-expert-ai-track.md)

About the Company CertiK is the largest blockchain security auditor and provides a comprehensive suite of tools to secure the industry at scale. To date, CertiK has worked with over…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK Oct 4

### [Blockchain Security Engineer – Senior Level (Solidity / Rust / Golang )](https://jobicy.com/jobs/152447-blockchain-security-engineer-senior-level-solidity-rust-golang.md)

About the Role: We are seeking a Senior Blockchain Security Engineer with a strong security mindset and deep technical expertise across smart contracts, blockchain nodes, and decentralized infrastructure. You will…

*
![1Password logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200909195848-296323.png)
1Password Oct 2

### [Senior Developer (Windows), Product Security](https://jobicy.com/jobs/154432-senior-developer-windows-product-security.md)

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up…

*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)
Nebius Oct 2

### [Cloud Workplace Engineer](https://jobicy.com/jobs/154423-cloud-workplace-engineer.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…

*
![Keyfactor, Inc. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/ba8ae349-221.png)
Keyfactor, Inc. Oct 2

### [Information Security Engineer](https://jobicy.com/jobs/152303-information-security-engineer.md)

About Keyfactor Our mission is to securely connect the world: humans, machines, and AI. Keyfactor is the leader in trust infrastructure for AI and machines, helping the world’s largest enterprises…

[Browse all jobs](https://jobicy.com/jobs.md)