Staff Application Security Engineer

EngineersOfAI

San Francisco (CA)

Hybrid

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Up to four weeks per year of fully remote work
Collaborative work environment

Job summary

Brex is seeking a Staff Application Security Engineer in San Francisco to define the technical vision and lead the Application Security team. This hybrid role involves fostering a culture of security excellence while collaborating across teams to mitigate risks in AI implementations.

The ideal candidate should have substantial experience in penetration testing and a deep curiosity for vulnerabilities in complex systems. Enjoy the flexibility of remote work and the energy of a collaborative environment.

Qualifications

  • 5+ years of experience in application security and risk management.
  • Strong understanding of software development lifecycles and secure coding practices.
  • Ability to work cross-functionally and communicate risks effectively.

Responsibilities

  • Lead the technical vision and strategic roadmap for the Application Security team.
  • Establish technical standards and secure defaults across engineering.
  • Architect and secure AI/ML workflows to mitigate risks.
  • Mentor and coach engineers, guiding their technical growth.
  • Drive proactive vulnerability discovery and offensive security testing strategies.
  • Partner with other teams to ensure secure deployment of services.

Skills

Penetration testing
Vulnerability assessment
Communication skills
AI/ML knowledge

Education

Bachelor's degree in Computer Science or related field

Tools

Security testing tools (e.g., Burp Suite)
AI development frameworks

Job description

Why join us

Brex is the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets. By combining global corporate cards and banking with intuitive spend management, bill pay, and travel software, Brex enables founders and finance teams to accelerate operations, gain real-time visibility, and control spend effortlessly. Brex’s AI-native automation and world‑class service eliminate manual expense and accounting tasks for customers so they can focus on what matters most. Tens of thousands of the world's best companies run on Brex, including DoorDash, Coinbase, Robinhood, Zoom, Plaid, Reddit, and SeatGeek.

Working at Brex allows you to push your limits, challenge the status quo, and collaborate with some of the brightest minds in the industry. We’re committed to building a diverse team and inclusive culture and believe your potential should only be limited by how big you can dream. We make this a reality by empowering you with the tools, resources, and support you need to grow your career.

Engineering at Brex

Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It’s an environment where engineering is a craft, and builders become leaders.

What you’ll do

As a Staff Application Security Engineer, you will define the technical vision and long‑term security architecture for the Brex platform. You will serve as the technical leader for the Application Security team, driving the strategic direction of our secure product lifecycle and vulnerability management programs. This role is highly cross‑functional, requiring you to establish deep, collaborative connections across the broader engineering organization to embed security seamlessly into high‑velocity development pipelines.

We’re looking for individuals with a solid foundation in penetration testing and a curiosity for finding vulnerabilities in complex systems. You should have experience identifying and documenting vulnerabilities across common vulnerability classes and be able to communicate their risk clearly to engineering and product teams.

Brex is pioneering the next wave of AI‑driven financial services for dynamic, high‑impact companies like Coinbase, Robinhood, and Anthropic. As we integrate AI across our product suite, you will be at the forefront of securing our novel AI implementations, identifying emerging attack vectors in agentic‑powered features, and hardening distributed LLM architectures. You will mentor team members, raise the technical bar for the organization, and partner with product and engineering leaders to build AI capabilities our customers can trust with their critical financial operations.

Where you’ll work

This role will be based in our San Francisco office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require 3 days per week in the office – Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work!

Responsibilities:
  • Lead the technical vision and strategic roadmap for the Application Security team, aligning security objectives with Brex's enterprise growth and high‑velocity engineering metrics.
  • Establish technical standards and secure defaults across the entire engineering organization, fostering a culture of collaborative security excellence and bridging product platforms, infra, and trust.
  • Architect and secure novel AI/ML and agentic workflows, applying cutting‑edge practices to mitigate risks such as prompt injection, model manipulation, and data poisoning.
  • Mentor and coach engineers within the team and across the broader organization, guiding technical growth, helping individuals level up their security expertise, and accelerating team delivery.
  • Drive proactive vulnerability discovery and offensive security testing strategies, executing complex attack chains to demonstrate business impact and prioritize cross‑functional remediation.
  • Partner with Product Platform, Cloud Infrastructure, and Data engineering teams to ensure core primitives, APIs, and microservices are secure by default from design to deployment.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Application Security Engineer
Staff Application Security Engineer

Brex • United States

Hybrid
USD 240,000 - 300,000
Up to four weeks fully remote work per year
Senior Application Security Engineer (Remote)
Senior Application Security Engineer (Remote)

Brex • United States

On-site
USD 192,000 - 240,000
Senior Security Operations Engineer
Senior Security Operations Engineer

Brex • New York (NY)

Hybrid
USD 192,000 - 240,000
Up to four weeks of fully remote work per year
Flexible work environment
Senior Security Operations Engineer
Senior Security Operations Engineer

Brex • Seattle (WA)

Hybrid
USD 192,000 - 240,000
Four weeks of fully remote work per year
Senior Security Operations Engineer
Senior Security Operations Engineer

Brex • San Francisco (CA)

Hybrid
USD 192,000 - 240,000
Up to four weeks of fully remote work per year
Flexible work environment
Staff Software Engineer, Product Data Platform
Staff Software Engineer, Product Data Platform

Brex • San Francisco (CA)

Hybrid
USD 240,000 - 300,000
AI Engineer, Ecosystem
AI Engineer, Ecosystem

EngineersOfAI • San Francisco (CA)

Hybrid
USD 100,000 - 150,000
Up to four weeks of fully remote work
Senior Software Engineer, Backend (Product Engineering)
Senior Software Engineer, Backend (Product Engineering)

Brex • San Francisco (CA)

Hybrid
USD 192,000 - 240,000
Hybrid work environment
Up to four weeks of fully remote work
Staff Software Engineer, Product Data Platform
Staff Software Engineer, Product Data Platform

Brex • Seattle (WA)

Hybrid
USD 240,000 - 300,000
Staff Software Engineer, Banking
Staff Software Engineer, Banking

Brex • Seattle (WA)

Hybrid
USD 240,000 - 285,000
Up to four weeks fully remote work per year
Hybrid work environment