Senior Application Security Engineer @Branch
Software Development
Salary usd 180,000 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Job Type full-time
Posted YDay

[Hiring] Senior Application Security Engineer @Branch

YDay - Branch is hiring a remote Senior Application Security Engineer. πŸ’Έ Salary: usd 180,000 - 190,000 per year πŸ“Location: USA

Role Description

Branch is seeking an experienced Security professional to join our team. This position will work in all aspects of security, so broad security knowledge is preferred. The ideal candidate will have a background in securing applications, networks, cloud environments, and corporate devices.

  • Embed security into the SDLC by partnering with Engineering to implement secure design patterns, conduct threat modeling, and deliver developer-focused AppSec training
  • Lead and perform application security assessments including SAST, DAST, SCA, and manual code review across web, mobile, and API surfaces
  • Drive API security across internal and external services β€” including authentication, authorization, rate limiting, and abuse prevention controls
  • Own and mature the vulnerability management program, including prioritization frameworks, SLA tracking, and cross-functional remediation coordination
  • Champion software supply chain security initiatives, including SBOM generation, dependency risk analysis, and third-party component vetting
  • Assist GRC with technical third-party risk reviews and vendor security assessments
  • Respond to and lead security incidents in a measured, programmatic, and timely manner β€” from identification through post-incident review
  • Implement and iterate on security automation and orchestration to improve detection, response, and coverage at scale
  • Implement, monitor, and continuously improve security controls across cloud infrastructure, endpoints, and the product
  • Assess and mitigate AI-specific security risks across Branch's use of LLMs and AI-powered features, including prompt injection, model abuse, and insecure output handling

Qualifications

  • 5–7 years of experience in a security engineering or application security role, ideally within a fintech or high-growth startup environment
  • Strong communication skills β€” able to translate technical risk clearly for both engineering audiences and senior leadership
  • Hands-on SAST/DAST experience; familiarity with tools such as Semgrep, Snyk, Checkmarx, Burp Suite Pro, or equivalents
  • Demonstrated ability to independently work security incidents end-to-end β€” including malware, phishing, DLP events, and API abuse
  • Experience securing cloud-native environments, including IAM, container/Kubernetes workloads, and serverless functions
  • Solid working knowledge of API security standards (OWASP API Top 10, OAuth 2.0/OIDC, JWT hardening)
  • Experience with mobile application security testing (iOS/Android) is a plus
  • Familiarity with security frameworks including SOC 2, PCI-DSS, NIST CSF, and OWASP SAMM
  • Scripting proficiency in Python and/or Bash for automation and tooling; experience with security orchestration platforms (e.g., Tines, XSOAR, Torq) is a plus
  • Strong ethics and discretion β€” this role regularly handles confidential and sensitive information
  • Familiarity with AI/LLM security risks and emerging standards (OWASP LLM Top 10, MITRE ATLAS) β€” including prompt injection, data leakage through model outputs, and supply chain risks introduced by third-party AI services
  • Security certifications a plus (OSCP, GWEB, CISSP, SANS GWAPT, etc.)

Requirements

  • The base salary range for this role is $180-190k.
  • The salary range displayed reflects an average base salary range for the position across all the U.S. The base salary offered to an applicant could be higher or lower based on each applicant's specific skill set, depth of experience, relevant education or training, etc.
  • This position is classified as REMOTE within the United States of America.
  • We are unable to hire candidates located outside of the domestic U.S.

Benefits

  • Market-leading medical, dental, and vision insurance
  • Stock options
  • Free Premium-Tier Origin Financial Wellness subscription
  • Monthly home-office stipend
  • 401k (TransAmerica)
  • 12-weeks paid parental leave for birthing and non-birthing parents
  • Flexible time off + sick and safe time
  • 11 paid company holidays
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Application Security Engineer @Branch
Software Development
Salary usd 180,000 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Job Type full-time
Posted YDay
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Unlock 152,720 Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Unlock 152,720 Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 152,720+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later