Senior Application Security Engineer

Brex Brex · Fintech · New York, NY +3 · Remote · Engineering

Senior Application Security Engineer at Brex, focusing on finding and responding to security vulnerabilities across the Brex platform, with a specific emphasis on securing AI and agentic-powered features. Responsibilities include code reviews, design reviews, penetration testing, vulnerability management, and developing security tooling. The role requires experience in application security, penetration testing, scripting languages, and knowledge of AI/agentic workflows.

What you'd actually do

  1. Identifying vulnerabilities, demonstrating business impact, and articulating the risk of specific vulnerabilities to drive prioritization efforts
  2. Perform penetration testing and design reviews, looking for vulnerabilities and insecure designs, work with engineering and product to design secure product features
  3. Maintain and build internal tools to automate security efforts, perform SAST and DAST testing of the Brex platform, and support secure development practices
  4. Build and contribute to a culture of collaborative security excellence through technical leadership, learning sessions, and mentorship within the team and wider organization

Skills

Required

  • 5+ years work experience in an Application Security or related role
  • Ability to find vulnerabilities in complex systems, demonstrating business impact through custom attack chains
  • Experience with a wide range of secure development activities including— threat modeling, developer education, and incident response
  • Knowledge of Python, scripting languages, and AI/agentic workflows to automate tasks, build tools and improve productivity
  • Collaborative mindset paired with strong written and verbal communication skills

Nice to have

  • Proficiency with Kotlin, gRPC, GraphQL, Kubernetes
  • Previous experience as a software engineer
  • Consultancy experience performing web application security reviews
  • Experience with securing distributed systems in AWS and cloud environments
  • Experience with pentesting and securing agentic features and systems
  • Contributions to the wider technical community— open source, public research, mentorship, community organizing, blogging, CVEs, presentations, etc
  • Experience submitting to bug bounty programs or responsible disclosure programs

What the JD emphasized

  • strong background and interest in penetration testing
  • demonstrated ability to find vulnerabilities in complex systems and craft exploits to demonstrate business impact
  • securing our novel AI implementations
  • identifying attack vectors in agentic-powered features
  • partnering with product and engineering teams to build AI capabilities that our customers can trust

Other signals

  • securing novel AI implementations
  • identifying attack vectors in agentic-powered features
  • partnering with product and engineering teams to build AI capabilities that our customers can trust