Application Security Engineer (X Money)

xAI

Washington

On-site

USD 120,000 - 160,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health insurance
Vision & dental benefits
Visa sponsorship

Job summary

xAI, a fintech-focused company, seeks an Application Security Engineer to protect secure payments and wallet platforms across the SDLC. You will review code, enforce secure coding standards, and improve threat modeling while collaborating with engineering teams to harden CI/CD pipelines and incident response capabilities.

The role emphasizes hands-on security in payments, wallets, and high-value transactions, with AWS security experience and a path toward advanced security tooling and SBOM

Qualifications

  • Experience with security testing tools and static/dynamic code analysis.
  • Experience securing CI/CD pipelines and implementing DevSecOps practices.
  • Experience with payments, money transmission, digital wallets, or related financial platforms.
  • Hands-on experience securing applications on AWS.

Responsibilities

  • Protect the security and integrity of payments and financial products throughout the software development lifecycle, with emphasis on code security, CI/CD pipelines, and systems that move and hold customer funds.
  • Conduct in-depth code reviews and static analysis to identify and mitigate vulnerabilities in financial applications.
  • Design and implement secure coding guidelines and best practices for development teams.
  • Collaborate with development teams to integrate security practices throughout the CI/CD pipeline.
  • Perform threat modeling and risk assessments for payments, wallets, ledgers, and related product surfaces; develop mitigation strategies for fraud and abuse.

Skills

Python
Rust
DevSecOps
Threat modeling
Communication

Education

Bachelor’s degree in CS/Cybersecurity

Tools

Burp Suite
OWASP ZAP
SBOM tools
GitOps

Job description

  • We are seeking a skilled and innovative Application Security Engineer to join 𝕏 Money
  • In this role, you will protect the security and integrity of our payments and financial products throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and systems that move and hold customer funds
  • Experience securing fintech, payments, digital wallet, ledger, or similar high-value platforms, where fraud, abuse, and unauthorized transfers are a constant concern, is strongly preferred
  • Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in financial applications
  • Design and implement secure coding guidelines and best practices for development teams
  • Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline
  • Perform threat modeling and risk assessments for payments, wallets, ledgers, and related product surfaces, and develop mitigation strategies for fraud, abuse, and unauthorized movement of funds or credits
  • Manage vulnerability tracking and remediation efforts, providing guidance to development teams
  • Manage the bug bounty program, including intake, triage, researcher communication, and coordinated disclosure
  • Support incident response activities related to application security
  • Stay current on emerging threats against financial and cloud-native systems, and continuously strengthen our controls
  • Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs)
  • Design and implement agentic and LLM-based solutions that help detect, investigate, or prevent security problems
Benefits
  • Health and wellness: Comprehensive health insurance including medical, dental, vision, and disability coverage
  • Life and family: Life and AD&D insurance and fertility benefits to ensure our team’s well-being and peace of mind
  • Flexible vacation: We work hard but avoid burn out. Take time off when you need it
  • Visa sponsorship: We support international talent with visa sponsorship to join our team
  • 401(k) plan: Retirement savings plan to secure your financial future

Familiarity with software supply chain security and SBOM generation toolsExperience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysisExperience in payments, money transmission, digital wallets, or related financial platformsExperience designing and implementing agentic and LLM-based solutions for security problemsDeep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10)Bachelor’s degree in Computer Science, Cybersecurity, or a related fieldExperience securing CI/CD pipelines and implementing DevSecOps practicesExcellent communication skills, able to explain complex security issues to both technical and non-technical audiencesExperience securing payments, wallets, ledgers, or other high-value transaction systems, including controls against fraud, abuse, and integrity issuesProficiency in Python or Rust and experience with secure coding practices in these languages3-5 years of experience in application security, with a strong focus on code security practicesTo conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of StateExperience managing bug bounty programsContributions to open-source security projects or toolsExperience with GitOps and infrastructure-as-code securityBackground in data privacy and compliance relevant to financial products and cloud-native applicationsExperience building custom security tooling to enhance and automate security processesRelevant security certifications (e.g., BSCP, OSCP, OSWE)Hands-on experience securing applications on AWS; familiarity with other cloud platforms is a plus

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Cybersecurity Jobs • Austin (TX)

On-site
USD 100,000 - 258,000
Equity
401(k) retirement plan
Disability insurance
+2
Application Security Engineer (X Money)
Application Security Engineer (X Money)

SpaceXAI • Palo Alto (CA)

On-site
USD 100,000 - 258,000
Equity
Benefits package (medical, vision, and
Application Security Engineer (X Money)
Application Security Engineer (X Money)

Maven Ventures • California (MO)

On-site
USD 100,000 - 258,000
Equity
Medical insurance
401(k)
Application Security Engineer (X Money) New Palo Alto, CA; Austin, TX; New York, NY; Washington, DC
Application Security Engineer (X Money) New Palo Alto, CA; Austin, TX; New York, NY; Washington, DC

Maxxd • New York (NY)

On-site
USD 100,000 - 258,000
Equity
Medical, Vision & Dental
401(k)
+2
Security Engineer
Security Engineer

Financial Information Technologies LLC • Tampa (FL)

On-site
USD 90,000 - 130,000
Security Engineer
Security Engineer

Fintech Brand • Tampa (FL)

On-site
USD 90,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Application Security Engineer
Application Security Engineer

Prediktive • New York (NY)

Remote
USD 130,000 - 190,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Security Engineer (Application Security)
Security Engineer (Application Security)

Trail of Bits • United States

Hybrid
USD 90,000 - 130,000
Health Insurance
Vision, Dental, Life & Disability
401k with company matching
+3