A complete application in a minute — tailored resume and cover letter, ready to send.
xAI, a fintech-focused company, seeks an Application Security Engineer to protect secure payments and wallet platforms across the SDLC. You will review code, enforce secure coding standards, and improve threat modeling while collaborating with engineering teams to harden CI/CD pipelines and incident response capabilities.
The role emphasizes hands-on security in payments, wallets, and high-value transactions, with AWS security experience and a path toward advanced security tooling and SBOM
Familiarity with software supply chain security and SBOM generation toolsExperience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysisExperience in payments, money transmission, digital wallets, or related financial platformsExperience designing and implementing agentic and LLM-based solutions for security problemsDeep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10)Bachelor’s degree in Computer Science, Cybersecurity, or a related fieldExperience securing CI/CD pipelines and implementing DevSecOps practicesExcellent communication skills, able to explain complex security issues to both technical and non-technical audiencesExperience securing payments, wallets, ledgers, or other high-value transaction systems, including controls against fraud, abuse, and integrity issuesProficiency in Python or Rust and experience with secure coding practices in these languages3-5 years of experience in application security, with a strong focus on code security practicesTo conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of StateExperience managing bug bounty programsContributions to open-source security projects or toolsExperience with GitOps and infrastructure-as-code securityBackground in data privacy and compliance relevant to financial products and cloud-native applicationsExperience building custom security tooling to enhance and automate security processesRelevant security certifications (e.g., BSCP, OSCP, OSWE)Hands-on experience securing applications on AWS; familiarity with other cloud platforms is a plus