Senior Application Security Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

Nifty Gateway Studio · 1 week ago

Senior Application Security Engineer

Gemini is a global crypto and Web3 platform, and they are seeking a Senior Application Security Engineer to protect the company and customers against application security threats. The role involves collaborating with engineering and product teams to provide security recommendations and identify security issues throughout the software development lifecycle.

Media and Entertainment

Responsibilities

Support the Gemini Secure Software Development Lifecycle as an application security subject matter expert through design review, threat modeling, code review, and penetration testing
Collaborate and advise engineering teams on application security best practices and vulnerability remediation
Perform deep-dive security reviews to ensure all Gemini products and services follow secure design principles across our product portfolio (web, mobile, and APIs)
Research, build and drive adoption of high-signal application security automation and secure-by-default frameworks
Create and deliver hands-on software security training to engineering teams to enable engineers at scale
Participate in the Application Security on-call rotation to support engineering teams during incidents

Qualification

Application securityPenetration testingThreat modelingSecure code reviewMicroservice architecturesCloud-native environmentsSecure design patternsPythonScalaC++JavaScriptCommunication skillsCollaboration

Required

5+ years of experience in application security or similar roles
Ability to perform design reviews, threat modeling, secure code reviews, or penetration testing with an attacker mindset
Strong background in application security best practices and familiarity with common vulnerabilities (e.g. SSRF, race conditions, privilege escalations, etc.)
Some background in development or scripting experience (Python, Scala, C++, or JavaScript)
Familiarity with and ability to understand business objectives, business context, and security risk
Strong communication skills and the ability to collaborate on a cross-functional team

Preferred

Experience with microservice architectures
Experience with cloud-native environments
Experience with preventing application security vulnerabilities through secure design patterns, automated tooling, or frameworks
Experience with supply chain security

Benefits

Competitive starting salary
A discretionary annual bonus
Long-term incentive in the form of a new hire equity grant
Comprehensive health plans
401K with company matching
Paid Parental Leave
Flexible time off

Company

Nifty Gateway Studio

twittertwittertwitter
company-logo
A digital production studio working with creators and brands to develop immersive social entertainment and creative experiences onchain.