Staff Security Engineer, Application Security

Socket.dev

New York (NY)

On-site

USD 150,000 - 210,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

fomo is seeking a Staff Security Engineer to own and elevate the application security program. You will be the technical authority on secure software, partnering with engineering to find and fix vulnerabilities, and build scalable tooling across the org.

This role focuses on product and application security, embedded in how our product is designed, built, and shipped. You will influence security direction, drive best practices, and mentor engineers with autonomy.

Qualifications

  • 7+ years in security engineering with a strong focus on application security.
  • Deep hands-on experience with secure code review and threat modeling.
  • Strong software engineering background with ability to read/write production code.
  • Experience building and scaling AppSec tooling (SAST/DAST, SCA, CI/CD security integration).
  • Track record of influencing engineering culture toward security.
  • Familiarity with cloud-native environments (AWS/GCP/Azure), container security, and modern API architectures.
  • Excellent communication skills for both engineers and non-technical stakeholders.
  • Prior experience as a technical lead or staff-level IC with high autonomy.

Responsibilities

  • Lead security architecture reviews and threat modeling for new features and major system changes.
  • Own the secure SDLC program including static/dynamic analysis, dependencies, secrets scanning, and CI/CD gates.
  • Perform deep-dive code reviews and manual penetration testing of high-risk services and web apps.
  • Design and build internal security tooling and guardrails for fast yet safe engineering.
  • Run and mature vulnerability management with triage, severity scoring, and remediation coordination.
  • Manage relationships with external pentest vendors and bug bounty programs.
  • Set technical direction on authentication, authorization, API security, and data protection patterns.
  • Mentor engineers on secure coding practices across the org.
  • Contribute to incident response for application-layer issues.
  • Help define and evolve AppSec roadmap and metrics.

Skills

AppSec
Threat modeling
Code review
SAST/DAST
CI/CD security
Cloud security
Security tooling
Mentoring

Tools

SAST
DAST
SCA
CI/CD tooling

Job description

About fomo

fomo is growing fast, now serving 2M+ users and backed by a $75M Series B (Index Ventures, with Union Square Ventures and Benchmark) at a $550M valuation. As we scale, we're investing in a security function that can keep pace with an increasingly complex product surface without slowing down engineering velocity.

About the role

We're hiring a Staff Security Engineer to own and elevate our application security program. This is a hands-on, high-leverage role for someone who wants to be the technical authority on how we build secure software, not just someone who reviews tickets after the fact. You'll work directly with the engineering team to find and fix vulnerabilities, build tooling that scales security across the org, and shape how fomo thinks about security at the architecture and code level.

This role skews heavily toward product and application security. You won't be spending your time on corporate IT, endpoint management, or employee-facing security operations. Instead, you'll be embedded in how our product is designed, built, and shipped.

What you'll do
  • Lead security architecture reviews and threat modeling for new features and major system changes, partnering directly with engineering and product teams from design through launch

  • Own our secure SDLC program: static and dynamic analysis (SAST/DAST), dependency and software composition analysis, secrets scanning, and CI/CD security gates

  • Perform deep-dive code reviews and manual penetration testing of high-risk services, APIs, and web applications

  • Design and build internal security tooling and guardrails that let engineers move fast without introducing risk

  • Run and mature our vulnerability management program, including triage, severity scoring, and driving remediation with engineering owners

  • Manage relationships with external pentest vendors and bug bounty programs, and turn findings into durable fixes rather than one-off patches

  • Set technical direction on authentication, authorization, API security, and data protection patterns used across the product

  • Mentor engineers on secure coding practices and act as a go-to resource for security questions across the org

  • Contribute to incident response when application-layer issues arise

  • Help define and evolve fomo's overall AppSec roadmap and metrics

What we're looking for
  • 7+ years in security engineering, with a substantial and recent focus on application security (not primarily corporate/IT security)

  • Deep hands‑on experience with secure code review, threat modeling, and common vulnerability classes (OWASP Top 10, auth/session flaws, SSRF, injection, business logic flaws, etc.)

  • Strong software engineering background; comfortable reading and writing production code, not just running scanners

  • Experience building and scaling AppSec tooling and processes (SAST/DAST, SCA, CI/CD security integration) at a growing company

  • Track record of driving security into engineering culture through influence, not just gatekeeping

  • Familiarity with cloud-native environments (AWS/GCP/Azure), container security, and modern API architectures

  • Excellent communication skills; able to explain risk to both engineers and non-technical stakeholders

  • Prior experience as a technical lead or staff-level IC who can operate with high autonomy

Nice to have:

  • Experience with bug bounty program management

  • Background in a high‑growth consumer or marketplace product

Why fomo

You'll be the first dedicated AppSec hire shaping the security foundation of a company at real scale, with the autonomy to set standards rather than inherit them.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer, Application Security
Staff Security Engineer, Application Security

SOLANA FOUNDATION • New York (NY)

On-site
USD 180,000 - 240,000
Equity
Health insurance
401(k) with match
+3
Staff Security Engineer, Application Security
Staff Security Engineer, Application Security

fomo Labs • New York (NY)

On-site
USD 180,000 - 240,000
Competitive cash compensation and.equ
Equity
Comprehensive health insurance
+4
Staff Security Engineer, Application Security
Staff Security Engineer, Application Security

fomo • New York (NY)

On-site
USD 180,000 - 260,000
Health insurance
Equity
401(k) with match
+2
Staff Application Security Engineer — Lead Security Architecture
Staff Application Security Engineer — Lead Security Architecture

fomo Labs • New York (NY)

On-site
USD 180,000 - 240,000
Competitive cash compensation and.equ
Equity
Comprehensive health insurance
+4
Staff AppSec Engineer: Architect Secure, Scalable APIs
Staff AppSec Engineer: Architect Secure, Scalable APIs

SOLANA FOUNDATION • New York (NY)

On-site
USD 180,000 - 240,000
Equity
Health insurance
401(k) with match
+3
Staff AppSec Engineer: Shape Secure Software at Scale
Staff AppSec Engineer: Shape Secure Software at Scale

Socket.dev • New York (NY)

On-site
USD 150,000 - 210,000
Senior AppSec Engineer – Architect Secure Trading Platform
Senior AppSec Engineer – Architect Secure Trading Platform

fomo • New York (NY)

On-site
USD 180,000 - 260,000
Health insurance
Equity
401(k) with match
+2
Staff Frontend Engineer
Staff Frontend Engineer

Socket.dev • New York (NY)

On-site
USD 150,000 - 230,000
Relocation to NYC covered if needed
Top tier medical, dental, vision
Staff Frontend Engineer
Staff Frontend Engineer

SOLANA FOUNDATION • New York (NY)

On-site
USD 180,000 - 280,000
Competitive cash compensation
Equity
Health insurance
+4
Staff Frontend Engineer
Staff Frontend Engineer

fomo • New York (NY)

On-site
USD 150,000 - 190,000
Health insurance
401(k) with match
Group term life insurance
+2