Application Security Engineer (X Money)
AI in this role
Protect the security of payments platforms and financial systems while incorporating LLM-based solutions for security problem detection.
SpaceXAIβs mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge.Β Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the companyβs mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.
ABOUT THE ROLE:
We are seeking a skilled and innovative Application Security Engineer to join π Money. In this role, you will protect the security and integrity of our payments and financial products throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and systems that move and hold customer funds. Experience securing fintech, payments, digital wallet, ledger, or similar high-value platforms, where fraud, abuse, and unauthorized transfers are a constant concern, is strongly preferred.Β
RESPONSIBILITIES:
- Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in financial applications
- Design and implement secure coding guidelines and best practices for development teams
- Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline
- Perform threat modeling and risk assessments for payments, wallets, ledgers, and related product surfaces, and develop mitigation strategies for fraud, abuse, and unauthorized movement of funds or credits
- Manage vulnerability tracking and remediation efforts, providing guidance to development teams
- Manage the bug bounty program, including intake, triage, researcher communication, and coordinated disclosure
- Support incident response activities related to application security
- Stay current on emerging threats against financial and cloud-native systems, and continuously strengthen our controls
- Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs)
- Design and implement agentic and LLM-based solutions that help detect, investigate, or prevent security problems
BASIC QUALIFICATIONS:
- Bachelor's degree in Computer Science, Cybersecurity, or a related field
- 3-5 years of experience in application security, with a strong focus on code security practices
- Experience in payments, money transmission, digital wallets, or related financial platforms
- Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10)
- Proficiency in Python or Rust and experience with secure coding practices in these languages
- Experience securing CI/CD pipelines and implementing DevSecOps practices
- Familiarity with software supply chain security and SBOM generation tools
- Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis
- Experience securing payments, wallets, ledgers, or other high-value transaction systems, including controls against fraud, abuse, and integrity issues
- Experience designing and implementing agentic and LLM-based solutions for security problems
- Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences
PREFERRED SKILLS AND EXPERIENCE:
- Hands-on experience securing applications on AWS; familiarity with other cloud platforms is a plus
- Relevant security certifications (e.g., BSCP, OSCP, OSWE)
- Experience managing bug bounty programs
- Background in data privacy and compliance relevant to financial products and cloud-native applications
- Experience with GitOps and infrastructure-as-code security
- Experience building custom security tooling to enhance and automate security processes
- Contributions to open-source security projects or tools
COMPENSATION AND BENEFITS:
$100,000 - $258,000 USD
Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.
ITAR REQUIREMENTS:
- To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. Β§ 1157, or (iv) Asylee under 8 U.S.C. Β§ 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITARΒ here.Β
SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
How we rate this
Application Security Engineer (X Money) at xAI rates 45 out of 100 for how much of the daily work is AI. That makes it Uses AI (AI Level 2 of 4). The level is about AI in the job, not seniority.
Uses AI. An ordinary role that requires AI tools.
- ββββ Builds AI80 to 100
- ββββ Works on AI60 to 79
- ββββ Uses AI40 to 59
- ββββ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a project where application security was part of your work. What did you do?
- Tell me about a project where code review was part of your work. What did you do?
- Tell me about a project where threat modeling was part of your work. What did you do?
- Tell me about a project where penetration testing was part of your work. What did you do?
- Walk me through how you've used LLM in your day-to-day work.
Adapt your resume
- List these exact terms on your resume: Application Security, Code Review, Threat Modeling, Penetration Testing, and LLM. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them β a tool named with nothing behind it rarely survives a human read.
- Put the AI tool in a bullet point about what you did, not just in a skills list β this role treats it as a required part of the job.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new cybersecurity jobs (Uses AI ββββ or higher) by email
One email a week with the new cybersecurity jobs (Uses AI ββββ or higher), each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that use AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step