Altruist

Senior Application Security Engineer (Blue Team)

Altruist$170K — $225K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years of experience in Application/Product Security Engineering.
  • Extensive experience with security assessments and threat modeling.
  • Hands-on secure code review experience with Java/Spring.
  • Experience with SAST/DAST/SCA tools in CI/CD pipelines.
  • Technologically savvy with modern tech stacks like Terraform and Kubernetes.
  • Excellent communication skills with a focus on intentional dialogue.
  • Strong problem-solving capabilities and resilience.

Responsibilities

  • Educate development teams on secure coding practices.
  • Conduct technical security assessments and code reviews.
  • Engage in threat modeling to identify potential security threats.
  • Help build secure libraries and standardized components for new features.
  • Manage and optimize security tools within CI/CD pipelines.
  • Collaborate with engineering on authentication and authorization issues.
  • Work with security teams to translate findings into actionable solutions.

Benefits

  • Stunning, amenity-filled office spaces designed for comfort and productivity.
  • Premium healthcare, dental, and vision insurance plans.
  • 401k savings plan with a 4% match and immediate vesting.
  • 16-week paid parental leave after one year of employment.
  • Professional development opportunities with an employee mobility program.
  • Company perks program, including discounts on various services and products.
  • One month work from anywhere policy (subject to some country restrictions).
Full Job Description
About the position

Altruist is in the midst of an exciting phase and we're excited to hire a Senior Application Security Engineer to join our growing Security team. Your expertise will ensure our products are secure - from design and code through the CI/CD pipeline.

This role follows a hybrid schedule, with three days per week onsite in our San Francisco FiDi or Culver City office.

Your impact
  • Educate and train development teams on secure coding practices and emerging security threats.
  • Perform technical security assessments and code reviews across our Java/Spring services
  • Engage in threat modeling to anticipate potential security threats and develop strategies to mitigate them.
  • Assist teams in building libraries, repeatable patterns, and paved-road components that ensure security is a part of every new feature.
  • Own and tune SAST, DAST, software composition analysis (SCA), and security tooling in CI/CD pipelines; triage findings and drive them to remediation with clear prioritization.
  • Partner with engineering to close service-to-service authentication/authorization gaps and other systemic issues.
  • Work with Detection & Response and our offensive security engineers to turn findings into durable detections and prevention.
  • Contribute to our secure SDLC standards and developer security guardrails.

What you'll bring
  • Experience - 4+ years of experience working as an Application/Product Security Engineer:
    • Extensive experience with security assessments, security design reviews, or threat modeling
    • Hands-on secure code review (Java/Spring or similar)
    • Experience operating SAST/DAST/SCA and secrets-scanning tooling in a CI/CD pipeline
    • Strong ability to work independently
  • Education - A B.A. / B.S. degree in relevant fields such as Computer Science or Computer Engineering or Information Security or relevant experience
  • Technical aptitude - You're technologically savvy and can easily get up to speed on modern tech stacks (i.e., Java, Spring, Terraform, Kubernetes, etc.)
  • Ownership - The pride you put into every aspect of your work is unparalleled and undeniable
  • Superb communication - Intentional dialogue is a superpower. You listen as well as you share your perspective with others.
  • Resilience - We're inspired by your unwavering determination to achieve success, no matter the adversity you face along the way.
  • Assurance - Your confidence is brilliant, yet ego-less. You possess a strong knowledge base, the ability to discover the unknown, and are open to differing perspectives.
  • Creative problem solving - Identifying the problem is simply not enough. You're instinctually creative with your approach in finding solutions to roadblocks.

Bonus points if you bring
  • Experience working in regulated environments (fintech / financial services)
  • Experience building AppSec automation or a "paved road" for developers
  • Cloud (AWS) and API security experience
  • Relevant certifications (e.g., CSSLP, GWAPT, OSCP)


Los Angeles, CA salary range

$170,000-$225,000 USD

What we bring

Attracting and retaining top-tier talent is a priority. We are proud of the culture we've built and are cognizant of the ever-changing professional landscape. Our dynamic offering of perks and benefits are tailored for you to feel your best while doing your best.
  • Stunning, amenity-filled office spaces in Culver City, CA, San Francisco, CA, and Dallas, TX. Our offices are intentionally designed for comfort, collaboration, and productivity.
  • Competitive total compensation.
  • Premium healthcare, dental, and vision insurance plans (HMO and PPO).
  • 401k savings plan with a 4% match and immediate vesting.
  • 16 week paid parental leave after one year of employment.
  • Professional growth and development opportunities including an employee mobility program and an annual L&D budget allocation for each employee.
  • Company perks program (includes discounts on pet insurance, fitness, cell phone plans, and travel, etc.).
  • Financial guidance program (includes counseling on navigating debt, tracking personal spend, saving and planning goals, home-purchasing preparedness, etc.).
  • One month work from anywhere policy (with the exception of a few countries).

Total compensation includes a competitive benefits package, along with a bonus program for eligible roles. For salaried positions, a salary offer will be determined by a number of factors including experience, skill level, internal pay equity, geographic location, and other relevant business considerations. We review all employee pay and compensation programs regularly to ensure fair, equitable, and competitive pay. At Altruist, we are committed to providing fair, equitable, and competitive compensation by leveraging market data to inform our pay bands. Base salaries will be reviewed at regular intervals throughout the year, typically in conjunction with performance review cycles. By evaluating compensation on a regular basis, we are able to reward high performance and ensure all employees have opportunities for growth.

About Altruist

Altruist is a financial services company that provides a digital platform for independent registered investment advisors (RIAs). The platform offers a range of services, including custodial services, trading, and portfolio management. Altruist's mission is to make financial advice more accessible and affordable for everyone. The company was founded in 2018 and is headquartered in Los Angeles, California.
Learn more about Altruist
Size
200 employees
Industry
Founded
2018

Similar Jobs

More Jobs at Altruist

More Information Technology Jobs

Find similar Senior Application Security Engineer (Blue Team) jobs: