Senior Application Security Engineer

New York City, NY

FalconX

FalconX is a digital assets prime brokerage with trading, financing, & custody for leading financial institutions. Deepest global liquidity & bespoke trade execution.

View company page

Who are we?

FalconX is the most advanced digital asset platform for institutions. We provide trade execution, credit & treasury management, prime offering and market making services. Given our global operations, industry-leading technology and deep liquidity, we have facilitated client transactions of $1 trillion in volume. Our products & services are regulated, compliant and trusted.

We are a team of engineers, product builders, institutional sales and trading leaders, operations experts, and business strategists. Our teammates have entrepreneurial experience and come from companies such as Google, Apple, Paypal, Citadel, Bridgewater, and Goldman Sachs. And, we embody our values: Think big; Drive bold outcomes; Be one team; Iterate with speed; and be an entrepreneur.

We prioritize learning. Outcomes are mission-critical, but we also believe that learning in success and in failure will drive our continued success. Our industry is emergent - there’s no shortage of experiments to get involved with and to continue growing and learning together. 

Qualifications

  • We’re looking for a seasoned software security architect who understands secure software development and has a strong understanding of DevSecOps architecture
  • You understand secure engineering best practices and propose solutions to both technically savvy and non-technical audiences
  • You know the software security secure development best practices specific to development languages and frameworks 
  • You know the security tooling landscape and have implemented security programs at organizations with complex application architecture
  • You have a growth mindset, push yourself toward excellence, and focus on continuous functional improvements
  • You have a passion for cyber security demonstrated through participation/leadership in conferences, webinars, Capture the Flag (CTF), TryHackMe, Bug Bounty, Submission of CVEs and/or personal projects
  • Strong understanding of past, current, and emerging security exploits
  • At least 8+ years of experience in software engineering, architecture, and software security
  • 5+ years of previous experience with software security initiatives and/or transformations
  • Knowledge of OWASP Top 10, Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), API Security Testing Tools, Automated Mobile Testing Tools, BSIMM, OpenSAMM and Threat Modeling tools
  • At least one security certification (ex CISSP, OSCP, GWEB, CEH, GRTP, GWEB)
  • Experience with multiple languages such as Java, Rust, Python, and/or Java Script
  • Understand how to detect and prioritize front-end, API's, Microservices, and Container vulnerabilities
  • Familiar with common build/automation tooling: ex Jenkins, GIT

Responsibilities

  • Provide subject matter expertise, roadmaps, strategies, and reference architectures for application and product security
  • Provide thought leadership in the areas of security tool automation, optimization, application vulnerability management, and strategies for risk reduction
  • Create a design of comprehensive architectural patterns for secure development standards for front-end, APIs, and mobile
  • Develop and maintain application security policies, standards, and guidelines and ensure their adherence across projects
  • Develop a strategy to automate software security vulnerability verification throughout the development process
  • Collaborate closely with cross-functional engineers to identify application-based vulnerabilities, design secure application architectures, and guide the integration of security measures into the development process
  • Create architecture design for tool integrations and implement tooling within CI/CD pipeline, limit manual testing and troubleshooting
  • Lead security engineer and software engineer training related to high-risk security risks
  • Evaluate products for security gaps through threat modeling and pen testing

Base pay for this role is expected to be between $164,000 and $215,000 USD. This expected base pay range is based on information at the time this post was generated. This role will also be eligible for other forms of compensation such as a performance linked bonus, equity, and a competitive benefits package. Actual compensation for a successful candidate will be determined based on a number of factors such as skillset, experience, and qualifications.

Inclusivity Statement

FalconX is committed to building a diverse, inclusive, equitable, and safe workspace for all people. Our roles are intended for people from all walks of life. We encourage all those interested in applying to our organization to submit an application regardless if you are missing some of the listed background requirements, skills, or experiences!

As part of our commitment to inclusivity, FalconX would like to acknowledge that the EEOC survey has limited potential responses that you can select. For legal reasons, FalconX must use this language to align with federal requirements, however, we want to ensure that you are able to provide a response to our own voluntary survey questions about your identity that best aligns with your most true self.

FalconX is an equal opportunity employer and will not discriminate against an applicant or employee based on race, color, religion, national origin, ancestry, ethnicity, sex (including gender, pregnancy, sexual orientation, and gender identity), age, physical or mental disability, veteran or military status, genetic information, citizenship, or any other legally-recognized protected basis under federal, state, or local law.

Applicants with disabilities may be entitled to reasonable accommodation under the Americans with Disabilities Act and other applicable state or local laws. A reasonable accommodation is a change in the way things are normally done which will ensure an equal employment opportunity without imposing undue hardship on FalconX. Please inform FalconX’s People team at recruiting@falconx.io, if you need assistance with participating in the application process.

Apply now Apply later
  • Share this job via
  • or

Tags: APIs Application security Automation BSIMM CEH CI/CD CISSP CTF DAST DevSecOps Exploits Java Microservices OSCP OWASP Pentesting Product security Python Rust SAST Strategy Vulnerabilities Vulnerability management

Perks/benefits: Career development Competitive pay Conferences Equity Salary bonus

Region: North America
Country: United States
Job stats:  3  0  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.