Senior Application Security Engineer
4 days ago
Why join us
Brex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from startups to enterprises — including DoorDash, Flexport, and Compass — use Brex to proactively control spend, reduce costs, and increase efficiency on a global scale.
Working at Brex allows you to push your limits, challenge the status quo, and collaborate with some of the brightest minds in the industry. We're committed to building a diverse team and inclusive culture and believe your potential should only be limited by how big you can dream. We make this a reality by empowering you with the tools, resources, and support you need to grow your career.
Engineering at Brex
Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It's an environment where engineering is a craft, and builders become leaders.
What you'll do
As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will perform code reviews, design reviews, penetration testing, and vulnerability management. You will develop and maintain tooling to perform static and dynamic testing of the Brex platform and tooling which supports secure developer workflows. Application Security is part of our wider Financial Scale organization, which means you will work closely with Security Operations, GRC, Product Security, Front End Platform, IT Infrastructure teams.
We're looking for individuals with a strong background and interest in penetration testing. You should have a demonstrated ability to find vulnerabilities in complex systems and craft exploits to demonstrate business impact. This role is highly cross functional and collaborative, you will have the opportunity to work with every engineering team across Brex. You should be enthusiastic about working with a variety of backgrounds, roles, and needs. Building a world-class financial service requires world-class security.
Brex is pioneering the next wave of AI-driven financial services for dynamic, high-impact companies like Coinbase, Robinhood, and Anthropic. We're at the early stages of integrating AI across our product suite, this role will have the opportunity to influence and secure the future of AI Security at Brex. You'll be at the forefront of securing our novel AI implementations, identifying attack vectors in agentic-powered features, and partnering with product and engineering teams to build AI capabilities that our customers can trust with their critical financial operations.
Where you'll work
This role will be based in our San Francisco office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of three coordinated days in the office per week, Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work
Responsibilities
- Identifying vulnerabilities, demonstrating business impact, and articulating the risk of specific vulnerabilities to drive prioritization efforts
- Perform penetration testing and design reviews, looking for vulnerabilities and insecure designs, work with engineering and product to design secure product features
- Maintain and build internal tools to automate security efforts, perform SAST and DAST testing of the Brex platform, and support secure development practices
- Build and contribute to a culture of collaborative security excellence through technical leadership, learning sessions, and mentorship within the team and wider organization
Requirements
- 5+ years work experience in an Application Security or related role
- Ability to find vulnerabilities in complex systems, demonstrating business impact through custom attack chains
- Experience with a wide range of secure development activities including— threat modeling, developer education, and incident response
- Knowledge of Python, scripting languages, and AI/agentic workflows to automate tasks, build tools and improve productivity
- Collaborative mindset paired with strong written and verbal communication skills
Bonus points
- Proficiency with Kotlin, gRPC, GraphQL, Kubernetes
- Previous experience as a software engineer
- Consultancy experience performing web application security reviews
- Experience with securing distributed systems in AWS and cloud environments
- Experience with pentesting and securing agentic features and systems
- Contributions to the wider technical community— open source, public research, mentorship, community organizing, blogging, CVEs, presentations, etc
- Experience submitting to bug bounty programs or responsible disclosure programs
Compensation
The expected salary range for this role is $192,000 - $240,000. However, the starting base pay will depend on a number of factors including the candidate's location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.
Please be aware, job-seekers may be at risk of targeting by malicious actors looking for personal data. Brex recruiters will only reach out via LinkedIn or email with a domain. Any outreach claiming to be from Brex via other sources should be ignored.
-
Senior Security Engineer, Application
6 days ago
San Francisco, California, United States Sentry Full time €113,000 - €124,000About SentryBad software is everywhere, and we're tired of it. Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology.With more than $217 million in funding and 100,000+ organizations that believe we're on to something, we're building performance and error monitoring tools that help companies like...
-
Senior Application Security Engineer
2 days ago
San Francisco, California, United States Zip Full time $160,000 - $220,000 per yearThe simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world. Today, enterprises spend $120T+ per year globally (>30 times larger than annual consumer e-commerce spend) and rely on vendors more than ever before to run their businesses.Our cofounders started Zip in 2020 to...
-
Application Security Engineer
2 days ago
San Francisco, California, United States Perplexity Full time $70,000 - $90,000 per yearPerplexity is seeking a highly skilled, experienced and hands-on Application Security Engineer to join our dynamic security team, revolutionizing the way people search and interact with the internet. You'll build the systems, tools, and processes that make security seamless for developers and strong by default, enabling rapid innovation while protecting our...
-
Application Security Engineer
2 days ago
San Francisco, California, United States Perplexity Full time $250,000 - $350,000 per yearPerplexity is an AI-powered answer engine founded in December 2022 and growing rapidly as one of the world's leading AI platforms. Perplexity has raised over $1B in venture investment from some of the world's most visionary and successful leaders, including Elad Gil, Daniel Gross, Jeff Bezos, Accel, IVP, NEA, NVIDIA, Samsung, and many more. Our objective is...
-
Senior Solutions Engineer
4 days ago
San Francisco, California, United States Opal Security Full time $150,000 - $250,000 per yearAbout Opal Security:At Opal, we're building modern identity governance for the AI era – intelligent access management that empowers enterprises to move fast while staying secure. Our mission is to bring clarity, control, and confidence to complex enterprise environments, helping teams govern access without slowing down innovation.The Role:As aSenior...
-
Senior Security Engineer
7 days ago
San Francisco, California, United States Qualified Full time $190,000 - $210,000 per yearQualified is the Agentic Marketing Platform for B2B companies. With Piper the AI SDR Agent, Qualified offers a whole new way to grow inbound pipeline. Piper operates across both the website and email, working to engage website visitors, capture leads, and convert buyers into pipeline around the clock. Hundreds of the world's leading brands—including...
-
Senior Security Engineer
4 days ago
San Francisco, California, United States Qualified Full time $150,000 - $250,000 per yearQualified is the Agentic Marketing Platform for B2B companies. With Piper the AI SDR Agent, Qualified offers a whole new way to grow inbound pipeline. Piper operates across both the website and email, working to engage website visitors, capture leads, and convert buyers into pipeline around the clock. Hundreds of the world's leading brands—including...
-
Software Engineer, Application Security
4 days ago
San Francisco, California, United States Glean Full time $185,000 - $280,000 per yearAbout GleanFounded in 2019, Glean is an innovative AI-powered knowledge management platform designed to help organizations quickly find, organize, and share information across their teams. By integrating seamlessly with tools like Google Drive, Slack, and Microsoft Teams, Glean ensures employees can access the right knowledge at the right time, boosting...
-
Senior Security GRC Engineer
4 days ago
San Francisco, California, United States Docusign Full time $151,200 - $254,350Company OverviewDocusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people's lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now,...
-
Senior Product Manager
4 days ago
San Francisco, California, United States Contrast Security Full time $120,000 - $180,000 per yearAt Contrast Security, we're redefining how organizations protect their software at the speed of modern development. With industry-leading Application Detection and Response (ADR), we give teams the power to detect, stop and fix real threats in real time. If you're passionate about building smarter, faster, more effective security, you'll fit right in.We're...