Senior Application Security Engineer - Gemini

Remote $140k–$200k senior 4 months ago full-time quality 8.6/10

Role in brief

Gemini seeks a Senior Application Security Engineer to secure its crypto products and integrate security into engineering workflows. The role involves leading security reviews, building AppSec tooling, and collaborating with development teams to improve secure coding practices. This position suits experienced security professionals with a background in application security, tooling automation, and development skills in languages like Python or Scala.

application securityAIPythonScalaC++JavaScript

About the role

This role focuses on enhancing the security posture of Gemini's crypto products and services. The engineer will lead secure design reviews, threat modeling, and penetration testing for critical systems such as custody, trading, and payments. A core part of the work involves identifying vulnerabilities and guiding engineering teams toward remediation, ultimately driving long-term improvements in secure coding practices across the organization.

A significant aspect of this position is the development of security tooling and automation. This includes designing and building AI agents for secure design and code review, enhancing SAST/DAST pipelines with AI, and creating automation to reduce repetitive security tasks. The successful candidate will apply an attacker mindset to proactively identify and mitigate risks, contributing directly to the robustness of Gemini's offerings.

Success in this role means not only securing existing products but also embedding security principles deeply within development processes. This involves partnering closely with engineering teams, influencing without direct authority, and ensuring that security considerations are integrated from the initial design phase through to deployment. The goal is to prevent vulnerabilities at scale through secure design patterns, automated tooling, and comprehensive frameworks.

The base salary for this position ranges from $140,000 to $200,000 annually, applicable to candidates in New York, California, and Washington.

Skills that matter here

  • application security: This role requires leading secure design reviews, threat modeling, and penetration testing for high-risk products.
  • AI: The engineer will build and ship code for AppSec tooling, including AI agents for secure design and code review, and AI-enhanced SAST/DAST pipelines.
  • Python: Development or scripting experience in Python is required for building security tooling and automation.
  • Scala: Development or scripting experience in Scala is required for building security tooling and automation.
  • C++: Development or scripting experience in C++ is required for building security tooling and automation.
  • JavaScript: Development or scripting experience in JavaScript is required for building security tooling and automation.

Who this role suits

  • A person who can approach security challenges with an attacker's mindset, proactively identifying potential weaknesses.
  • Someone who enjoys both leading security assessments and building automated tools to solve security problems.
  • An individual skilled at collaborating with diverse engineering teams, influencing them to adopt secure coding practices.
  • A professional with a strong background in application security best practices and common vulnerabilities, capable of applying this knowledge in a fast-paced environment.

From the employer

Responsibilities:

  • Lead secure design reviews, threat modeling, code review, and penetration testing for high-risk products such as crypto custody, trading systems, and payments
  • Build and ship code: design and build AppSec tooling including AI agents for secure design and code review, AI-enhanced SAST/DAST pipelines, and automation that eliminates repeatable security toil
  • Partner with engineering teams to remediate vulnerabilities and drive long-term improvements in secure coding practices

Minimum Qualifications:

  • 5+ years of experience in application security or similar roles
  • Ability to perform design reviews, threat modeling, secure code reviews, or penetration testing with an attacker mindset
  • Experience building or meaningfully contributing to security tooling and automation
  • Strong background in application security best practices and familiarity with common vulnerabilities (e.g. SSRF, race conditions, privilege escalations, etc.)
  • Some background in development or scripting experience (Python, Scala, C++, or JavaScript) with the ability to read and write code
  • Strong communication skills to influence without authority and the ability to collaborate on a cross-functional team with competing priorities

Preferred Qualifications:

  • Experience building AI application security tooling using agents or skills
  • Experience with supply chain security, common frameworks (SLSA, OWASP SPVS) and other CI/CD security controls
  • Familiarity with highly regulated environments (financial services, fintech, crypto, or equivalent) and ability to understand business objectives, business context, and security risk
  • Experience with preventing application security vulnerabilities at scale through secure design patterns, automated tooling, or frameworks
  • Experience with microservice architectures and cloud-native environments

It Pays to Work Here

The compensation & benefits package for this role includes:

  • Competitive starting pay
  • A discretionary annual bonus
  • Long-term incentive in the form of a new hire equity grant
  • Comprehensive health plans
  • 401K with company matching
  • Paid Parental Leave
  • Flexible time off

Salary Range

The base salary range for this role is between $140,000 - $200,000 in the State of New York, the State of California and the State of Washington. This range is not inclusive of our discretionary bonus or equity package.

Questions about this role

What is the remote work policy for this role?

This is a remote position, but the salary range provided is specifically for candidates located in New York, California, and Washington.

What level of experience is required for this position?

This is a senior-level role, requiring a minimum of 5 years of experience in application security or similar fields.

What technical skills are important for this role?

Key technical skills include application security, experience with AI, and development or scripting in languages such as Python, Scala, C++, or JavaScript.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to Gemini.