Application Security Engineer

Remote $120k–$154k 1 month ago full-time quality 7.8/10

Role in brief

Figure is seeking an Application Security Engineer to strengthen software security practices from development to deployment. This role involves designing and implementing security solutions, integrating security into CI/CD pipelines, and conducting regular assessments. Ideal for an engineer who can lead security initiatives, mentor peers, and manage vulnerability programs in a blockchain-focused financial technology environment.

About the role

This role focuses on enhancing the security of software applications within a company that uses blockchain to transform capital markets. The work involves architecting and implementing security solutions, such as firewalls, intrusion detection, and encryption protocols. A key part of the job is integrating security into development and deployment processes, collaborating closely with DevOps teams to automate secure practices.

The engineer will conduct security assessments, threat modeling, and architecture reviews to identify vulnerabilities and design mitigation strategies. This includes managing external penetration tests and prioritizing remediation efforts. Success in this position means significantly improving the company's security posture while maintaining a balance with development speed and innovation.

Beyond technical implementation, the role involves leading cross-team security initiatives and mentoring other engineers on security best practices. The person in this role will also participate in incident response, on-call rotations, and post-incident reviews, contributing to a continuous improvement cycle for the company's defenses. Building a culture where security is considered from the design phase is an important aspect of this position.

The listed salary range for this full-time remote role is between $120,000 and $154,440 USD.

Skills that matter here

  • firewalls: This role will involve architecting and implementing firewall solutions as part of end-to-end security measures.
  • intrusion detection: The engineer will design and implement intrusion detection systems to protect applications.
  • encryption protocols: Responsibilities include implementing various encryption protocols to secure data and communications.
  • security event management: This position requires managing security events to monitor and respond to potential threats.
  • cloud security controls: The role involves designing and implementing security controls specifically for cloud environments.
  • CI/CD pipelines: This role requires integrating security gates and automation into continuous integration and continuous delivery pipelines.

Who this role suits

  • A person who can lead security initiatives and enjoys mentoring other engineers on best practices.
  • Someone who can balance the need for robust security with the demands of innovation and development speed.
  • An individual who is proactive in identifying risks through threat modeling and architecture reviews.
  • A candidate who is comfortable participating in incident response and on-call rotations to continuously improve defenses.

From the employer

What You’ll Do

  • Architect, design, and implement end-to-end security solutions, including firewalls, intrusion detection, encryption protocols, security event management, and cloud security controls.
  • Collaborate with DevOps to integrate security into CI/CD pipelines, ensuring automation and repeatability of secure deployments.
  • Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.
  • Lead cross-team initiatives that significantly improve our security posture while balancing speed and innovation.
  • Mentor engineers on security best practices and build a culture of security by design.
  • Actively participate in incident response, on-call rotations, and post-incident reviews to continuously improve defenses.

What We Look For

  • Improve and run Figure's vulnerability management program including triage, prioritization, tracking remediation, and reporting on risk reduction over time.
  • Collaborate with DevOps to integrate security gates at various points throughout the software development lifecycle, ensuring automation and repeatability of secure deployments.
  • Manage third-party penetration tests, including scoping, vendor coordination, and tracking remediation of findings.
  • Automate sources of toil, such as routine patching or dependency upgrades.
  • Conduct threat modeling and security reviews for new features and services, partnering with engineering teams early in the design process.
  • Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.
  • Lead cross-team initiatives that significantly improve our security posture while balancing speed and innovation.
  • Actively participate in incident response, on-call rotations, and post-incident reviews to continuously improve defenses.
  • Adhere to all company security policies and data handling procedures.
  • Complete mandatory security awareness training within required timeframes.
  • Promptly report any suspected security incidents or suspicious activity to the Security team.

Benefits

  • Comprehensive medical, dental, and vision coverage, with 100% employer-paid premiums for employees and their dependents on select plans.
  • Company HSA, FSA, Dependent Care FSA, 401(k), and commuter benefits.
  • Employer-paid life and disability insurance.
  • 11 observed holidays and PTO plan.
  • Up to 12 weeks of paid family leave.
  • Continuing education reimbursement.

Questions about this role

What is the remote work policy for this role?

This is a fully remote position.

What is the salary range for this position?

The salary for this role ranges from $120,000 to $154,440 USD.

What kind of security programs will I manage?

You will improve and run the company's vulnerability management program, including triage, prioritization, and tracking remediation, and manage third-party penetration tests.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to Figure.