Brex

Staff Application Security Engineer

Lead · Удалённо · Сан-Франциско, США · Английский B2

Навыки

  • AWS
  • Коммуникация
  • Распределённые системы
  • GraphQL
  • gRPC
  • Kotlin
  • Kubernetes
Ещё 9
  • Лидерство
  • LLM
  • Микросервисы
  • Machine Learning
  • Пентест
  • Python
  • Роадмап
  • SOLID и паттерны
  • Управление уязвимостями

О компании и продукте

  • We make this a reality by empowering you with the tools, resources, and support you need to grow your career. Engineering at Brex. Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It’s an environment where engineering is a craft, and builders become leaders

Задачи

  • As a Staff Application Security Engineer, you will define the technical vision and long-term security architecture for the Brex platform
  • You will serve as the technical leader for the Application Security team, driving the strategic direction of our secure product lifecycle and vulnerability management programs
  • This role is highly cross-functional, requiring you to establish deep, collaborative connections across the broader engineering organization to embed security seamlessly into high-velocity development pipelines
  • We're looking for individuals with a solid foundation in penetration testing and a curiosity for finding vulnerabilities in complex systems
  • Brex is pioneering the next wave of AI-driven financial services for dynamic, high-impact companies like Coinbase, Robinhood, and Anthropic
  • As we integrate AI across our product suite, you will be at the forefront of securing our novel AI implementations, identifying emerging attack vectors in agentic-powered features, and hardening distributed LLM architectures
  • You will mentor team members, raise the technical bar for the organization, and partner with product and engineering leaders to build AI capabilities our customers can trust with their critical financial operations
  • Where you’ll work
  • This role will be based in our San Francisco office
  • We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home
  • We currently require 3 days per week in the office - Monday, Wednesday and Thursday
  • As a perk, we also have up to four weeks per year of fully remote work!
  • Lead the technical vision and strategic roadmap for the Application Security team, aligning security objectives with Brex's enterprise growth and high-velocity engineering metrics
  • Establish technical standards and secure defaults across the entire engineering organization, fostering a culture of collaborative security excellence and bridging product platforms, infra, and trust
  • Architect and secure novel AI/ML and agentic workflows, applying cutting-edge practices to mitigate risks such as prompt injection, model manipulation, and data poisoning
  • Mentor and coach engineers within the team and across the broader organization, guiding technical growth, helping individuals level up their security expertise, and accelerating team delivery
  • Drive proactive vulnerability discovery and offensive security testing strategies, executing complex attack chains to demonstrate business impact and prioritize cross-functional remediation
  • Partner with Product Platform, Cloud Infrastructure, and Data engineering teams to ensure core primitives, APIs, and microservices are secure by default from design to deployment
  • Why join us
  • Brex is the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets
  • By combining global corporate cards and banking with intuitive spend management, bill pay, and travel software, Brex enables founders and finance teams to accelerate operations, gain real-time visibility, and control spend effortlessly
  • Brex’s AI-native automation and world-class service eliminate manual expense and accounting tasks for customers so they can focus on what matters most
  • Tens of thousands of the world's best companies run on Brex, including DoorDash, Coinbase, Robinhood, Zoom, Plaid, Reddit, and SeatGeek
  • Working at Brex allows you to push your limits, challenge the status quo, and collaborate with some of the brightest minds in the industry

Требования

  • 8+ years of experience in Application Security, Product Security, or software engineering with a primary focus on offensive and defensive application security
  • Proven track record of technical leadership and team mentorship on complex, multi-quarter security engineering initiatives in a fast-paced environment
  • Deep proficiency and technical expertise in AI security, including hands-on experience securing agentic architectures, LLM gateways, and evaluating adversarial AI vectors
  • Strong systems-thinking capabilities with extensive experience defining secure product development lifecycles, threat modeling complex topologies, and cloud-native container security (AWS, Kubernetes)
  • Proficiency in Python, Go, or similar languages to architect internal tooling, pipeline automation, and advanced detection/scanning engines
  • Exceptional written and verbal communication skills, with a demonstrated ability to navigate ambiguity, influence technical leaders, and manage up and out across EPD organizations
  • You should have experience identifying and documenting vulnerabilities across common vulnerability classes and be able to communicate their risk clearly to engineering and product teams

Будет плюсом

  • Experience with Kotlin, gRPC, GraphQL, Kubernetes
  • Previous experience in building and scaling security teams
  • Experience with securing distributed systems in AWS and cloud environments
  • Contributions to the wider technical community — open source, public research, CTF participation, blogging, CVEs, or presentations
  • Experience submitting to bug bounty or responsible disclosure programs
  • Published AI security research or contributions to AI security frameworks
  • Compensation
  • However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity
  • Please be aware, job-seekers may be at risk of targeting by malicious actors looking for personal data
  • Brex recruiters will only reach out via LinkedIn or email with a brex.com domain
  • Any outreach claiming to be from Brex via other sources should be ignored

Условия

  • The expected salary range for this role is $240,000 USD - $300,000 USD
  • Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package

Паспорт вакансии

История публикации

Появилась в Вакандии30 дней
Перепубликациинетпубликовалась один раз
Проверяли на источникеВидели 25 дней назад
Среди похожихНет данных22 из 30 · похожих вакансий слишком мало для сравнения

Откуда что взялось

Отмечено то, что вывели мы. Без пометки — значение назвал работодатель.

ГрейдLeadвычитано из текста вакансии
Формат работыУдалённовычитано из текста вакансии
ГеографияСан-Франциско, СШАвычитано из текста вакансии
Зарплата≈ 18 833 USD в месяцнаша оценка, в вакансии не названа

Почему на этом месте в выдаче

Порядок выдачи объявлен контрактом: свежесть решает между днями, полнота и зарплата — внутри дня.

Полнота карточки1004 из 4 полей: грейд, формат, география, зарплата
Зарплата названа0вилки работодателя нет, показана наша оценка

Проверка Вакандии

Источники и свежесть

Тип источника
Карьерный сайт работодателя
Найдено публикаций
1
Посмотреть публикации и даты
  • greenhouseОсновная публикация · 2026-06-25

Работодатель

Brex

50 активных вакансий · вилка работодателя указана в 61%

Открыть профиль компании

Безопасность

Отклик уходит на сайт источника

Вакандия показывает вакансию, но не отправляет отклик и не проверяет работодателя. Сам отклик вы оставляете на внешнем сайтеbrex.com.

Признаки мошенничества
  • Просят предоплату, «залог» или деньги за обучение и оборудование.
  • Требуют код из SMS, данные банковской карты или доступ к «Госуслугам».
  • Быстро уводят в мессенджер и торопят с решением.
  • Обещают большой доход без опыта и без деталей задач.

Настоящий работодатель не просит денег и платёжных данных до трудоустройства.

Продолжить поиск

Похожие вакансии

Причина сходства указана на каждой карточке

  1. Почему похожа: похожая специализация · тот же формат

    Spendesk

    Senior Security Engineer

    • Senior
    • Удалённо
    • Париж, Франция
    Подробнее