Senior Application Security Engineer

Chime Chime · Fintech · San Francisco, CA · Security

Senior Application Security Engineer with expertise in mobile application security to join the Product Security team. This role involves working with engineering teams to identify, prevent, and remediate security issues across iOS, Android, API, and backend systems. The role will also leverage AI to accelerate security workflows and partner with teams building AI-enabled features to implement AI security controls.

What you'd actually do

  1. Build and improve security capabilities, automation, and guardrails for mobile applications and backend/API services
  2. Perform application or API/backend penetration testing
  3. Identify, triage, and help remediate vulnerabilities across Chime products
  4. Partner closely with engineering and product teams to embed security into the development lifecycle across mobile apps, APIs, and backend services
  5. Perform architecture and code reviews across the stack (iOS/Android, APIs, backend) with a focus on secure data storage, authentication, authorization, secure communication, and session/token handling

Skills

Required

  • 5+ years of experience in application security
  • strong hands-on experience across both mobile and backend systems
  • Hands on experience securing iOS and Android applications in production environments
  • Strong understanding of mobile threat models and common attack techniques
  • Experience with mobile security testing techniques, including static and dynamic analysis
  • Familiarity with iOS and Android platform security features and limitations
  • Practical coding experience, preferably in Ruby, Go, Python languages
  • Ability to clearly communicate security risks, tradeoffs, and remediation guidance to engineering partners

Nice to have

  • AI to accelerate security workflows
  • AI security controls

What the JD emphasized

  • deep expertise in mobile application security
  • hands-on experience across both mobile and backend systems
  • Hands on experience securing iOS and Android applications in production environments
  • Strong understanding of mobile threat models and common attack techniques
  • Experience with mobile security testing techniques, including static and dynamic analysis
  • Leverage AI to accelerate security workflows
  • partner with teams building AI-enabled features to define and implement production-grade AI security controls