Senior Application Security Engineer
Job Description
<div class="content-intro"><p class="c-mrkdwn__pre" style="text-align: left;" data-stringify-type="pre">At Beyond Finance, we've made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care,<strong> </strong>a culture focused on compliance and ethics, supportive user-centric technology, and customized financial solutions, we've helped over 1 million clients on their path to a brighter future.</p> <p class="c-mrkdwn__pre" style="text-align: left;" data-stringify-type="pre">While we're proud of what we've already accomplished, we're searching for new collaborators to help us get to the next level! If you're looking to join a forward-thinking, rapidly growing organization with helping people as its number one goal, we want to hear from you.</p></div><h2>Role Overview</h2> <p>As our Application Security Engineer, you will be the primary owner and driver of our application security program. You'll work hands-on with engineering teams to embed secure development practices, improve tooling and automation, and guide security considerations for new features, architectures, and services.</p> <p>This is a high-impact role where you'll shape the future of AppSec at a company that values security as a core part of product quality.</p> <h2>What You'll Do</h2> <p><strong>Application Security Ownership</strong></p> <ul> <li>Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.</li> <li>Serve as the primary AppSec partner for numerous dev teams working on Ruby on Rails web apps, React Native mobile apps, and various other projects including Python and Go.</li> <li>Provide security guidance during design, development, and code review for new features and projects.</li> <li>Drive adoption of secure coding practices and threat-modeling across engineering teams.</li> </ul> <p><strong>Tooling & Automation</strong></p> <ul> <li>Manage and optimize existing AppSec tooling, including:</li> </ul> <ul> <li>GitHub Advanced Security (SAST, SCA, Secret Scanning)</li> <li>Invicti (DAST)</li> <li>Hadrian (ASM)</li> <li>AppDome (mobile application security)</li> <li>Cloudflare WAF</li> </ul> <ul> <li>Improve automation and integration of security tools into CI/CD pipelines.</li> <li>Identify and implement additional tools or processes to strengthen the security posture.</li> </ul> <p><strong>Secure SDLC & Developer Enablement</strong></p> <ul> <li>Build and maintain secure development standards, playbooks, and training materials.</li> <li>Partner with engineering teams during sprint planning and feature design to proactively address risks.</li> <li>Conduct security reviews, code assessments, and vulnerability triage with development teams.</li> </ul> <p><strong>Cloud & DevOps Collaboration</strong></p> <ul> <li>Work with DevOps to ensure secure AWS infrastructure deployments and configurations.</li> <li>Contribute to hardening efforts across ECS, IAM, networking, and supporting cloud services.</li> <li>Assist in designing and maintaining secure CI/CD workflows.</li> </ul> <p><strong>Incident & Vulnerability Management</strong></p> <ul> <li>Lead or support investigation and remediation of application-level vulnerabilities.</li> <li>Monitor, prioritize, and track findings from SAST/DAST/ASM tools.</li> <li>Collaborate with engineering to ensure timely and effec