Senior Application Security & DevSecOps Engineer

MrBeast

Greenville (NC)

On-site

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive Salary
Medical, Dental, Vision
Company-paid Life Insurance
401k with company match
Relocation assistance
Tech package
Flexible vacation

Job summary

MrBeast is seeking a Senior Application Security & DevSecOps Engineer to own the security of our web, mobile apps, and APIs. You will run offensive testing, build security tooling, and integrate security into our deployment pipelines with Kubernetes and Terraform. Read and reason about production code in a developer‑centric stack (Kotlin/Gradle, Python).

You will lead secure coding practices, threat modeling, and a robust bug bounty program to protect products used by millions.

Qualifications

  • 8+ years in Application Security or offensive security.
  • Read, write, and review production code; Kotlin/Gradle experience preferred.
  • Deep mobile security expertise across iOS and Android.
  • Strong API security knowledge including OAuth/OIDC, REST, and GraphQL.

Responsibilities

  • Lead secure code reviews and threat modeling for web, mobile, and API surfaces.
  • Own the vulnerability lifecycle—discovery, triage, remediation guidance, and verification.
  • Build internal AppSec tooling and lightweight security libraries.
  • Run internal penetration tests and red‑team style assessments.
  • Manage bug bounty program and coordinate with researchers.
  • Secure CI/CD pipelines with SAST/DAST/SCA in GitHub Actions.

Skills

Application security
Offensive security
Kotlin
Gradle
Python
Frida
Burp Suite
CodeQL
Semgrep
GitHub Actions
Kubernetes
Terraform

Tools

Frida
Burp Suite
MobSF
objection
MobSF
CodeQL
Semgrep
GitHub Actions

Job description

Location: (On-site / Hybrid / Remote – NY, Bay Area, Chicago, Greenville)
Department: Technology

About The Role

This is a hands‑on Application Security role, not a generalist security position. As Senior Application Security & DevSecOps Engineer, you will own the security of our web and mobile applications and the APIs behind them — finding the vulnerabilities before anyone else does, running our offensive testing and bug bounty programs, and building security into the pipelines that ship our code.

You’ll work close to the code. Our stack is heavily automated and developer‑centric: a custom DSL layer governs how code reaches production, translating into Kubernetes and Terraform deployment tasks, and our backend leans on Kotlin and Gradle. You should be able to read and reason about production code, write your own tooling, and own the security of the build and release process end to end — not hand the hard parts to DevOps.

If you think like an attacker, are fluent in mobile and API internals, and want to own AppSec for products that millions of people use, this role is for you.

What You'll Do
Application Security (core)
  • Lead secure code review and threat modeling for web, mobile, and API surfaces, and drive secure‑by‑design practices with engineering teams.
  • Own the application vulnerability lifecycle — discovery, triage, severity, remediation guidance, and verification — and partner with engineers on durable fixes, not just findings.
  • Build internal AppSec tooling and lightweight security libraries that make the secure path the easy path for developers.
Mobile Application Security
  • Own security for our iOS and Android apps: secure local storage (Keychain / Keystore), certificate pinning, jailbreak/root and tampering detection, anti‑reverse‑engineering, and secure app‑to‑API communication.
  • Assess apps against OWASP MASVS / MASTG, and review third‑party SDKs and dependencies for risk.
  • Perform mobile‑focused testing with tooling such as Frida, objection, MobSF, Burp Suite, and static/dynamic RE tools.
Offensive Security & Penetration Testing
  • Run internal penetration tests and red‑team‑style assessments against our apps, APIs, and supporting services.
  • Validate and weaponize findings to demonstrate real impact, then drive them to resolution.
  • Pressure‑test authentication, authorization, session handling, and business‑logic flows (OAuth/OIDC, GraphQL/REST, IDOR, privilege escalation).
Bug Bounty Program
  • Own and operate our bug bounty program (e.g., HackerOne / Bugcrowd): scope definition, researcher communication, triage, deduplication, severity, and payout coordination.
  • Close the loop by feeding bounty findings back into secure code review, threat models, and CI/CD checks so the same class of bug doesn't recur.
  • Track program health and report on trends, top vulnerability classes, and time‑to‑fix.
CI/CD & Pipeline Security
  • Own the security posture of our CI/CD pipelines and deployment toolchain, including the custom DSL that translates to Kubernetes and Terraform.
  • Integrate and tune SAST, DAST, and dependency/SCA scanning (e.g., Semgrep, CodeQL) as meaningful, low‑noise gates in GitHub Actions.
  • Implement secrets scanning, build/release integrity, artifact signing, and supply‑chain controls (SBOMs, provenance).
  • Drive a security‑focused cleanup of existing pipelines and automate the manual, one‑off deployment steps that exist today.
What You Bring
Required Experience
  • 8+ years focused on Application Security and/or offensive security (penetration testing, exploit development).
  • Strong software‑development skills — you can read, write, and review production code rather than just operating tools. Experience with Kotlin and Gradle (and/or Swift/Android for mobile) is highly relevant to our stack; Python for automation and custom tooling.
  • Deep mobile application security expertise across iOS and Android: OWASP MASVS/MASTG, cert pinning, secure storage, anti‑tampering/RE, and mobile testing tooling (Frida, objection, MobSF, Burp).
  • Hands‑on penetration testing of web apps, mobile apps, and APIs, with the ability to demonstrate real exploitability.
  • API security depth — OAuth/OIDC, REST and GraphQL, authn/authz and business‑logic flaws.
  • CI/CD security experience with GitHub Actions, including SAST/DAST/SCA integration, secrets scanning, and securing the build/release pipeline.
  • Strong security fundamentals, including applied cryptography — a clear command of certificates and PKI, encryption vs. key management, and where HSMs fit.
Strongly Preferred
  • Experience running or scaling a bug bounty / VDP program (HackerOne, Bugcrowd, or similar).
  • Offensive security certifications (OSCP, OSWE, GMOB, or equivalent demonstrated skill).
  • Experience securing consumer fintech/Gaming/Reels apps and the regulatory expectations that come with handling user funds and data for teens and their subscriptions.
  • Software‑supply‑chain security experience (SBOMs, artifact signing, provenance).
  • Reverse engineering / binary analysis (Ghidra, Hopper, IDA).
What Success Looks Like
  • Critical and high‑severity application vulnerabilities are found internally — by you and your tooling — before they reach users or external researchers.
  • Our mobile apps meet a defined, measurable security bar across iOS and Android.
  • The bug bounty program is well‑run, fairly triaged, and consistently feeds improvements back into the SDLC.
  • Every meaningful change ships through CI/CD with security checks that engineers trust because they're accurate, not noisy.
  • Manual, one‑off deployment steps are automated away, and the build/release path is hardened end to end.
Why This Role Is Different
  • You’ll own application security for products used by millions — not review tickets for a generic security backlog.
  • You’ll work close to the code in a Kotlin/Gradle, highly automated stack where AppSec and software engineering are the same discipline.
  • You’ll run real offensive testing and a real bug bounty program, then turn those findings into lasting fixes.
  • You’ll operate at the intersection of Application Security, Offensive Security, and CI/CD — and build the systems, not just audit them.
Benefits
The Perks, Why Work On the MrBeast Team

We are redefining what entertainment and storytelling look like at global scale. Every piece of content we publish reaches millions and influences culture in real time. This is your opportunity to lead the team that decides how those moments come to life across every screen.

  • Competitive Salary
  • Generous Medical (Blue Cross Blue Shield), Dental, Vision and company‑paid Life Insurance
  • Company contributions to employee Health Savings Accounts (HSA)
  • 401k Plan with Safe Harbor company‑matching
  • Flexible vacation policy and paid company holidays
  • Company‑provided technology package
  • Relocation assistance where applicable, including travel and company‑provided housing for the first 90 days
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security & DevSecOps Engineer
Senior Application Security & DevSecOps Engineer

Mrbeastyoutube • New York (NY)

Hybrid
USD 150,000 - 210,000
Competitive salary
Medical, Dental, Vision
HSA contributions
+4
Staff Embedded InfoSec Engineer
Staff Embedded InfoSec Engineer

Mrbeastyoutube • San Mateo (CA)

On-site
USD 170,000 - 250,000
Competitive salary
Comprehensive benefits package
Relocation assistance
+1
Principal Compliance & Security Engineer
Principal Compliance & Security Engineer

Mrbeastyoutube • San Mateo (CA)

Hybrid
USD 230,000 - 320,000
Equity
Hybrid in-office schedule (Bay Area/NY
Medical, dental, vision
+5
Technical Program Manager
Technical Program Manager

MrBeast • New York (NY), San Francisco (CA)

On-site
USD 140,000 - 190,000
Medical benefits
Dental & Vision
Life Insurance
+5
Senior IT Platform Engineer
Senior IT Platform Engineer

MrBeast • San Mateo (CA)

On-site
USD 115,000 - 173,000
Generous Medical, Dental, Vision
Company-paid Life Insurance
HSA contributions
+4
Staff Engineer / Architect, Data & Identity
Staff Engineer / Architect, Data & Identity

Mrbeastyoutube • San Mateo (CA)

Hybrid
USD 170,000 - 223,000
Medical
Dental
Vision
+5
Head of Customer Experience & Platform Integrity
Head of Customer Experience & Platform Integrity

MrBeast • San Mateo (CA)

On-site
USD 250,000 - 380,000
Competitive Salary
Relocation assistance for housing
Company-provided technology package
+1
Senior Full Stack Engineer
Senior Full Stack Engineer

Mrbeastyoutube • San Mateo (CA)

On-site
USD 289,000
Competitive Salary
Medical (Blue Cross Blue Shield)
Dental
+7
Technical Program Manager
Technical Program Manager

MrBeast • San Angelo (TX)

Hybrid
USD 90,000 - 130,000
Competitive Salary
Medical (Blue Cross Blue Shield)
Dental, Vision and company-paid Life
+4
Director Engineering Frontend (App Framework E-Commerce)
Director Engineering Frontend (App Framework E-Commerce)

Mrbeastyoutube • San Francisco (CA)

Hybrid
USD 150,000 - 200,000
Equity package
Generous medical, dental, and vision insurance
401k plan with matching
+1