
Senior Application Security Engineer
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in United States.
• Conduct manual penetration tests on the company’s systems.
• Develop AI-assisted tools and automation to enhance penetration testing coverage.
• Establish and execute testing methodologies for LLM applications, agents, and code generated by agents.
• Assess SAST findings, address genuine vulnerabilities, and adjust false-positive rules.
• Carry out secure code reviews for web applications, APIs, and AWS infrastructure.
• Create tools and security services within the Forward application stack.
• Assist with security evaluations from testing to production for AI-generated work.
• Clarify security risks to engineers to help them prioritize and resolve issues.
• Contribute to the development of the company's evolving application security function and standards.
• A minimum of 5 years of experience in application security, offensive security, or product security.
• Practical experience in penetration testing and code reviews for web applications, APIs, and AWS cloud infrastructure.
• A hacker’s mentality with a keen interest in understanding system vulnerabilities.
• A desire to leverage AI for problem-solving.
• Knowledge of the AI/LLM attack surface, including prompt injection, insecure use of agent tools, and vulnerabilities typical of AI-generated code.
• Familiarity with modern programming languages such as Ruby, Python, TypeScript, or Go.
• Experience with secure software development lifecycle (SDLC) practices.
• Ability to effectively communicate risks and priorities to both security and software engineers.
• Typically, a Bachelor's Degree in Computer Science or a related technical field, or equivalent industry experience.
• Must have authorization to work for any employer in the United States.
• OSCP/OSWE or equivalent offensive security certifications are preferred.
• Experience in penetration testing or red-teaming LLM applications and agentic systems is preferred.
• Participation in bug bounty or external testing programs is preferred.
• A background in fintech or other regulated environments is preferred.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• Commuter benefits.
• Flexible time-off policy.
• Paid parental leave.
• 401(k) matching for US employees.
• Wellness reimbursement.
• Volunteering days.
• Annual professional development budget.
• Charitable donation matching.
• Flexible hours.
• Flexible work location: home, office, or a combination.
• Virtual and in-person team events.
Nord Security
Bugcrowd
PowerSchool
PowerSchool
Get handpicked remote jobs straight to your inbox weekly.