Application Security Engineer
New York City; Portland, Oregon; Chicago, Illinois; Los Angeles, California; San Francisco, California; Remote
Gemini
Gemini makes crypto simple. Find, Trade and Buy over 80 coins including bitcoin on the best cryptocurrency platform. Start trading crypto here.Empower the Individual Through Crypto
Gemini is a crypto exchange and custodian that allows customers to buy, sell, store, and earn more than 30 cryptocurrencies like bitcoin, bitcoin cash, ether, litecoin, and Zcash. Gemini is a New York trust company that is subject to the capital reserve requirements, cybersecurity requirements, and banking compliance standards set forth by the New York State Department of Financial Services and the New York Banking Law. Gemini was founded in 2014 by twin brothers Cameron and Tyler Winklevoss to empower the individual through crypto.
Crypto is about giving you greater choice, independence, and opportunity. We are here to help you on your journey. We build crypto products that are simple, elegant, and secure. Whether you are an individual or an institution, we want to help you buy, sell, and store your bitcoin and cryptocurrency. Crypto is not just a technology, it's a movement.
At Gemini, our mission is to empower the individual and that includes giving our employees flexibility of choice — our Office Optional Policy allows employees to choose to work from one of our physical locations or from home.
Select roles that are location-specific will still be eligible for flexible schedules.
The Department: Information Security
In the emerging industry of digital assets, there is nothing more important than trust (which is why Gemini’s very first hires were Security experts). The Gemini Security team forms the backbone of all that we do and is as diverse as the number of challenges we tackle in the crypto space. From security architecture and engineering to maintenance of cold storage systems and data centers to cybersecurity and litigation support, our team ensures that our customers, clients, and employees are safe, secure, and supported.
The Role: Application Security Engineer - Advisory
The Application Security team at Gemini ensures that software engineering teams across the company are enabled to securely design, build, test, and maintain the applications that power our business. We aspire to establish a "paved road" for our engineers so that they can more-easily deliver secure software with minimal friction, supporting their work across the entire Secure Development Lifecycle (SDL). The Application Security team considers how we’re balancing friction with security value, fighting back “security theater” by using our expertise with an empathetic, customer-service approach.
Whether we're creating educational opportunities, tailoring secure-development technologies, advising on a new product design, or leading a detailed code review, the Application Security Advisory team is focused on supporting our engineers as early-and-often as possible so that “security first principles" are integrated and verified at every stage of the development lifecycle. Success for our team is measured through a maturity model, tracking our growth as a program with capabilities that increase engineer velocity and ever-improving security.
Responsibilities:
- Support engineers across the SDL as an application security subject matter expert, including design reviews, threat modeling, code review, and penetration testing
- Collaborate with product and engineering on architecting resilient, security-first services
- Perform deep-dive security assessments to ensure all Gemini products and services follow secure design principles across our product portfolio (web, mobile, APIs)
- Create and deliver educational content to our engineers including hands-on training courses
- Develop automation for high-signal, low-noise security tooling to increase code base coverage
- Partner with third-party security firms to provide external validation of software development
Minimum Qualifications:
- 3+ years of experience working in application security roles or performing similar job functions
- Prior participation in source code reviews, security design reviews, threat modeling, penetration testing, or defining security requirements
- Enjoys working directly with software engineers, including in new languages and tool chains
- Awareness of numerous vulnerability classes, with knowledge of modern mitigation techniques
- Detail-oriented communication skills via email, Slack, pull requests, and/or in-person presentations
- Creating and extending software for development tooling to improve security automation
Preferred Qualifications:
- Have worked directly with enterprise Scala, Python, and/or C++ code bases
- Experience exploiting and securing modern web applications
- Experience working with low-level cryptographic implementations/primitives
- Experience with blockchain-based technologies and/or smart contracts
It Pays to Work Here
We take a holistic approach to compensation at Gemini, which includes:
- Competitive Compensation and Profit-Sharing Equity
- Flexible vacation policy
- Retirement Plan Matching
- Generous Parental leave
- Comprehensive health plans
- Training and professional development
At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace and affirmative action employer. If you have a specific need that requires accommodation, please let a member of the People Team know.
#LI-AH1
#LI-REMOTE
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs Application security Automation Banking Blockchain C Compliance Crypto Pentesting Python Scala Security assessment
Perks/benefits: Career development Competitive pay Equity Flex hours Flex vacation Home office stipend Parental leave Startup environment
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Senior Cyber Security Engineer jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Principal Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Staff Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Product Security Engineer jobs
- Open Manager Pentest H/F jobs
- Open Cyber Security Specialist jobs
- Open Senior Information Security Analyst jobs
- Open Cybersecurity Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Chief Information Security Officer jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Consultant jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Security Specialist jobs
- Open Senior Penetration Tester jobs
- Open Security Researcher jobs
- Open Cybersecurity Specialist jobs
- Open Senior Security Architect jobs
- Open IT Security Engineer jobs
- Open Security Operations Analyst jobs
- Open CISM-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open ISO 27001-related jobs
- Open Pentesting-related jobs
- Open Application security-related jobs
- Open Agile-related jobs
- Open GCP-related jobs
- Open Vulnerability management-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open Analytics-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Java-related jobs
- Open Security assessment-related jobs
- Open Malware-related jobs
- Open DevOps-related jobs
- Open Security Clearance-related jobs
- Open IDS-related jobs
- Open EDR-related jobs
- Open CEH-related jobs
- Open Forensics-related jobs
- Open Kubernetes-related jobs