Source Job

UK Unlimited PTO

  • Protect applications trusted by millions of users in the Web3 ecosystem.
  • Combine hands-on security engineering with threat modeling, code reviews, and developer enablement.
  • Embed security throughout the software development lifecycle to build resilient products.

Application Security Threat Modeling JavaScript Blockchain Node.js

20 jobs similar to Senior Application Security Engineer

Jobs ranked by similarity.

US

  • Own threat modeling and secure code reviews for new products and features.
  • Maintain and tune AppSec tooling, and run the bug bounty program.
  • Design and evolve the secure SDLC, and partner with engineering teams to implement secure-by-default patterns.

Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. The company operates at the intersection of traditional finance and on-chain systems, with a focus on security and innovation.

US

  • Partner with engineering and product teams to identify application security risks and provide practical mitigation recommendations.
  • Analyze code, configurations, and logs to detect vulnerabilities and improve security workflows.
  • Communicate security risks clearly to technical and non-technical stakeholders and drive scalable solutions.

US Unlimited PTO

  • Partner with product and engineering teams to identify security risks and implement secure solutions throughout the product lifecycle.
  • Lead threat modeling activities, secure design reviews, and security-focused code reviews to improve development practices.
  • Build, maintain, and improve application security tooling and participate in incident response activities.

The partner company is a fast-moving engineering organization focused on protecting modern software products and the sensitive data they manage. The team values innovation, inclusion, and continuous improvement, and offers a collaborative culture with high ownership.

Global

  • Define and build a new runtime protection product line for Node.js environments, owning the technical strategy and execution from concept to deployment.
  • Design detection methodologies that distinguish malicious activity from legitimate behavior at scale using large-scale threat intelligence and modern engineering tools.
  • Collaborate with security specialists and engineering teams while leveraging AI-assisted workflows to deliver high-impact security capabilities.

The partner company specializes in building innovative runtime protection solutions for Node.js applications. It fosters a remote-first, highly autonomous culture with a focus on professional growth and cutting-edge security research.

$99,750–$137,250/yr
Canada

  • Partner with product and engineering teams to identify application security risks and recommend mitigations.
  • Read application code, configuration, and pull requests to understand security risks and suggest improvements.
  • Contribute to vulnerability management, automation, and security tooling to scale AppSec efforts.

Affirm is reinventing credit to make it more honest and friendly, providing consumers the flexibility to buy now and pay later without hidden fees. We are a remote-first company with a culture centered on people, transparency, and offering competitive benefits including health coverage and flexible spending.

Canada

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
  • Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
  • Contribute to security architecture reviews and support bug bounty programs and incident response.

Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.

Europe

  • Act as an Application Security SME, partnering with Engineering and Product teams to embed security throughout the SDLC.
  • Lead application security reviews, threat modeling, code reviews, and penetration testing to identify and mitigate risks.
  • Design and automate security controls across CI/CD pipelines, including SAST, SCA, and other AppSec tooling.

Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America, backed by leading investors, and places millions of workers.

Global

  • Assist in developing secure software by writing and optimising Rust code for security-critical components.
  • Conduct deep manual and automated code audits to identify and mitigate security vulnerabilities.
  • Design and implement machine learning models for automated security analysis and threat mitigation.

Parity builds core blockchain infrastructure for a decentralized web, including Polkadot and Kusama. Our remote-first global team develops open-source software and is committed to a respectful, innovative culture.

$130,100–$187,000/yr
US

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.

Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.

$73,000–$83,950/yr
Canada

  • Design, build, and maintain scalable and secure software applications for enterprise and government clients.
  • Collaborate across teams to solve complex technical challenges and mentor others.
  • Write clean, maintainable code while ensuring security and architectural best practices.

AOT Technologies is a boutique consulting firm that partners with enterprises, startups, and governments to solve complex mission-critical challenges. The company is a small to medium-sized team with a collaborative culture and transparent leadership.

India

  • Lead security architecture reviews and threat modeling exercises for applications and platforms.
  • Partner with engineering and product teams to identify risks and recommend mitigation strategies.
  • Develop security standards, automation, and developer enablement materials to promote secure-by-design practices.

Our partner company is dedicated to building secure digital products through innovative security practices. They offer a collaborative, remote-friendly culture with opportunities for professional growth.

UK

  • Perform hands-on security testing and code review across web applications and APIs.
  • Conduct threat modeling and embed secure development practices into the SDLC.
  • Build and tune security tooling, including SAST, DAST, and CI/CD automation.

Prolific builds human data infrastructure for AI development, connecting researchers with a global participant pool to collect high-quality, ethically sourced behavioral data. They are a mission-driven company trusted by world-leading research institutions and AI labs, with a remote-first culture.

$130,000–$190,000/yr
US

  • Own and manage the application vulnerability remediation program, prioritizing findings and guiding developers.
  • Partner with engineering teams to validate fixes and implement long-term security improvements.
  • Define and maintain secure SDLC processes, including security reviews and threat modeling.

The company develops internet-facing financial software, APIs, and cloud-based solutions. It operates with a remote-first culture and emphasizes security and compliance.

$88,800–$125,800/yr
Canada 3w PTO 12w maternity 12w paternity

  • Proactively identify and drive security improvements across the product and platform.
  • Partner with engineering teams to threat model new features and review designs early in development.
  • Build and improve security tooling, libraries, and workflows to make secure development the default path.

Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.

$116,000–$183,000/yr
US

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
  • Lead triage and technical validation of incoming reports across multiple intake channels, driving end-to-end vulnerability remediation.
  • Collaborate with the Security Incident Response Team on active incidents and perform targeted code reviews.

Mozilla Corporation is a non-profit-backed technology company that has shaped the internet for the better over the last 25 years. With over 225 million people using our products monthly, we are a mission-driven organization focused on privacy, open-source software, and reclaiming the internet for people.

Nigeria

  • Conduct thorough security assessments and penetration testing to identify vulnerabilities in web and mobile applications.
  • Collaborate with development teams to integrate security best practices and design secure application architectures.
  • Lead incident response and ensure compliance with security standards and regulations.

Moniepoint Inc. is an all-in-one African financial platform serving 20 million businesses with payments, banking, and tools. As Nigeria's largest merchant acquirer, it processes over $250 billion annually and fosters a culture of innovation and teamwork.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

US

  • Lead bug bounty program strategy and vulnerability management initiatives.
  • Collaborate with engineering and security teams to drive remediation efforts.
  • Conduct code reviews and develop security tooling to improve efficiency.

This company operates a global technology platform. It values security, collaboration, and continuous learning, with a team dedicated to protecting user privacy and safety.

US Unlimited PTO

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services.
  • Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle.
  • Serve as a product security point of contact for incidents, contributing to investigation, root-cause analysis, and post-incident improvement.

Lime is a global leader in micromobility, on a mission to build a future where transportation is shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered more than one billion rides across 30 countries and is a fast-paced, lean, remote-first company.

$160,000–$195,000/yr

  • Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
  • Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
  • Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.

Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.