Senior Application Security Engineer
Remote
Full Time
#Technology
#Information Security
#Application Security
#Penetration Testing
#Secure Coding
#Java
#Python
#SQL
#JavaScript
#SAST
#DAST
#DevSecOps
We are looking for a Senior Application Security Engineer to join our security team and help us protect the financial well-being of our customers. Since our founding in 2005 as the first peer-to-peer lending platform in the United States, we have helped over 2 million people access affordable credit. Today, we continue to innovate across our suite of financial products, including personal loans and home equity lines of credit. As a member of our team, you will work in a fast-paced, remote environment, collaborating with engineering and product groups to embed security into every stage of our software development lifecycle. Please note that the working hours for this position are based in Pacific Time.
Key outcomes
- Collaborate with product and engineering teams to define security requirements for microservices, APIs, and applications during the design phase.
- Perform threat modeling, secure code reviews, and internal penetration testing on our most critical features.
- Manage application vulnerabilities by triaging findings from SAST, DAST, SCA, and penetration tests, while driving remediation efforts to completion.
- Provide expert guidance to cross-functional teams on secure coding practices and security architecture.
- Develop and maintain security standards that align with industry frameworks like OWASP, NIST, and ISO.
- Partner with our DevSecOps team to integrate security tooling directly into our CI/CD pipelines.
- Track security metrics and provide leadership with clear reporting on our overall security posture.
Requirements
- A Bachelor’s degree in Computer Science, Information Security, or a related field with at least 8 years of experience, or a Master’s degree with 6 years of experience.
- Strong technical expertise in application security, secure coding, and penetration testing.
- A background in software development with proficiency in Java, Python, SQL, and JavaScript.
- Experience reviewing modern application architectures and working with web frameworks like Spring Boot or REST and SOAP services.
- Deep understanding of web and API security vulnerabilities, including the OWASP Top 10.
- Familiarity with authentication protocols such as OAuth2, OIDC, and SAML.
- Proven experience working within Agile and DevSecOps environments.
- Knowledge of vulnerability management processes and regulatory requirements like PCI DSS, GDPR, and SOC 2.
Preferred qualifications
- Industry certifications such as OSCP, CSSLP, GWAPT, CEH, GPEN, or CISSP.
- Experience with cloud security in AWS, GCP, or Azure, as well as container security using Docker and Kubernetes.
- Proficiency with mobile application security testing and tools like Burp Suite, Postman, or ZAP.
- Experience driving secure SDLC initiatives and providing security education to developers.
Compensation
We provide a comprehensive benefits package designed to support your health, well-being, and professional growth. Our offerings include:
- Flexible time off and paid parental leave.
- Comprehensive medical insurance coverage.
- A dedicated mental wellness budget and access to virtual fitness resources.
- Additional perks such as Udemy access, pet insurance discounts, legal assistance, and childcare support.
How to apply
If you are passionate about security and want to help us democratize finance, we would love to hear from you. Please submit your application through our careers portal. We value diverse perspectives and encourage you to apply even if your background does not perfectly match every requirement listed above.







