Application Security Engineer (X Money)

SpaceXAI

Palo Alto (CA)

On-site

USD 100,000 - 258,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity
Benefits package (medical, vision, and

Job summary

SpaceXAI seeks an Application Security Engineer to protect payments and financial products across the SDLC, focusing on code security, CI/CD pipelines, and fund movement controls. Fintech and cloud-native security expertise preferred.

Responsibilities include threat modeling, vulnerability remediation, and SBOM maintenance, with collaboration across product and engineering teams to strengthen defenses and incident response readiness.

Qualifications

  • Bachelor's degree in CS, cybersecurity, or related field.
  • 3-5 years in application security with focus on code security.
  • Experience in payments, digital wallets, or fintech.
  • Strong knowledge of OWASP Top 10 and secure coding.
  • Proficiency in Python or Rust and secure coding practices.
  • Experience securing CI/CD pipelines and DevSecOps.
  • Familiarity with SBOM and software supply chain security.
  • Experience with Burp Suite and OWASP ZAP.
  • Strong communication to explain security to non-technical audiences.

Responsibilities

  • Conduct in-depth code reviews and static analysis of financial applications.
  • Design secure coding guidelines for development teams.
  • Integrate security into CI/CD pipelines.
  • Perform threat modeling and risk assessments for payments and wallets.
  • Manage vulnerability tracking and remediation guidance.
  • Manage bug bounty program intake, triage, and disclosure.
  • Support incident response related to application security.
  • Stay informed on emerging threats to fintech and cloud-native systems.
  • Evaluate and secure software supply chains and SBOMs.
  • Design agentic and LLM-based security solutions.

Skills

3-5 years experience
Code security practices
DevSecOps
Threat modeling
Communication skills
Cloud security

Education

Bachelor's degree in CS/Cybersecurity or related field

Tools

Burp Suite
OWASP ZAP
SBOM tools
GitOps

Job description

SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE:

We are seeking a skilled and innovative Application Security Engineer to join X Money. In this role, you will protect the security and integrity of our payments and financial products throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and systems that move and hold customer funds. Experience securing fintech, payments, digital wallet, ledger, or similar high-value platforms, where fraud, abuse, and unauthorized transfers are a constant concern, is strongly preferred.

RESPONSIBILITIES:
  • Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in financial applications
  • Design and implement secure coding guidelines and best practices for development teams
  • Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline
  • Perform threat modeling and risk assessments for payments, wallets, ledgers, and related product surfaces, and develop mitigation strategies for fraud, abuse, and unauthorized movement of funds or credits
  • Manage vulnerability tracking and remediation efforts, providing guidance to development teams
  • Manage the bug bounty program, including intake, triage, researcher communication, and coordinated disclosure
  • Support incident response activities related to application security
  • Stay current on emerging threats against financial and cloud-native systems, and continuously strengthen our controls
  • Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs)
  • Design and implement agentic and LLM-based solutions that help detect, investigate, or prevent security problems
BASIC QUALIFICATIONS:
  • Bachelor's degree in Computer Science, Cybersecurity, or a related field
  • 3-5 years of experience in application security, with a strong focus on code security practices
  • Experience in payments, money transmission, digital wallets, or related financial platforms
  • Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10)
  • Proficiency in Python or Rust and experience with secure coding practices in these languages
  • Experience securing CI/CD pipelines and implementing DevSecOps practices
  • Familiarity with software supply chain security and SBOM generation tools
  • Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis
  • Experience securing payments, wallets, ledgers, or other high-value transaction systems, including controls against fraud, abuse, and integrity issues
  • Experience designing and implementing agentic and LLM-based solutions for security problems
  • Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences
PREFERRED SKILLS AND EXPERIENCE:
  • Hands-on experience securing applications on AWS; familiarity with other cloud platforms is a plus
  • Relevant security certifications (e.g., BSCP, OSCP, OSWE)
  • Experience managing bug bounty programs
  • Background in data privacy and compliance relevant to financial products and cloud-native applications
  • Experience with GitOps and infrastructure-as-code security
  • Experience building custom security tooling to enhance and automate security processes
  • Contributions to open-source security projects or tools
COMPENSATION AND BENEFITS:

$100,000 - $258,000 USD

Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

ITAR REQUIREMENTS:
  • To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. section 1157, or (iv) Asylee under 8 U.S.C. section 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here (https://www.pmddtc.state.gov/?id=ddtc_kb_article_page&sys_id=24d528fddbfc930044f9ff621f961987).

SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer (X Money)
Application Security Engineer (X Money)

Maven Ventures • California (MO)

On-site
USD 100,000 - 258,000
Equity
Medical insurance
401(k)
Application Security Engineer (X Money) New Palo Alto, CA; Austin, TX; New York, NY; Washington, DC
Application Security Engineer (X Money) New Palo Alto, CA; Austin, TX; New York, NY; Washington, DC

Maxxd • New York (NY)

On-site
USD 100,000 - 258,000
Equity
Medical, Vision & Dental
401(k)
+2
Sr. Security Engineer - GRC Fintech & Financial Services
Sr. Security Engineer - GRC Fintech & Financial Services

SpaceXAI • Palo Alto (CA)

On-site
USD 152,000 - 228,000
Equity
Comprehensive medical, vision, dental
401(k) retirement plan
Senior BSA/AML Investigator
Senior BSA/AML Investigator

Maven Ventures • Palo Alto (CA)

On-site
USD 125,000 - 145,000
Application Security Engineer
Application Security Engineer

Cybersecurity Jobs • Austin (TX)

On-site
USD 100,000 - 258,000
Equity
401(k) retirement plan
Disability insurance
+2
Software Engineer - X Money
Software Engineer - X Money

Maven Ventures • Palo Alto (CA)

On-site
USD 180,000 - 440,000
Senior BSA/AML Investigator
Senior BSA/AML Investigator

SpaceXAI • Palo Alto (CA), New York (NY)

On-site
USD 120,000 - 145,000
Equity
401(k) retirement plan
Medical, vision, dental coverage
+3
Software Engineer - X Money
Software Engineer - X Money

SpaceXAI • Palo Alto (CA)

On-site
USD 180,000 - 440,000
Equity
Medical coverage
Vision coverage
+5
Infrastructure Security Engineer
Infrastructure Security Engineer

Xai • Austin (TX)

On-site
USD 100,000 - 258,000
Fraud Analyst (Sat-Weds)
Fraud Analyst (Sat-Weds)

SpaceXAI • Palo Alto (CA)

Hybrid
USD 100,000 - 135,000
Comprehensive medical coverage
Vision and dental coverage
401(k) retirement plan
+1