About the roleWe are looking for a Sr. Full Stack Application Security Engineer with deep expertise in mobile application security to join our Product Security team. This role is hands-on and impact driven. You will work directly with mobile, backend, and platform engineering teams to identify, prevent, and remediate security issues across our iOS, Android, API, and backend systems.
You will operate close to the code and close to the product. That means reviewing architectures across the stack, influencing secure design decisions early, and helping teams ship features safely without slowing delivery. This role is for someone who understands how modern distributed systems and mobile apps are built, deployed, and attacked in real-world environments.
While mobile application security is a core focus, you will be part of a team that owns security posture across the full application stack including APIs, backend services, identity and authentication flows, and CI/CD pipelines.
The base salary offered for this role and level of experience will begin at $213,000 and up to $295,000. Full-time employees are also eligible for a bonus, competitive equity package, and benefits. The actual base salary offered may be higher, depending on your location, skills, qualifications, and experience.
In this role, you can expect to- Build and improve security capabilities, automation, and guardrails for mobile applications and backend/API services
- Perform application or API/backend penetration testing
- Identify, triage, and help remediate vulnerabilities across Chime products
- Partner closely with engineering and product teams to embed security into the development lifecycle across mobile apps, APIs, and backend services
- Perform architecture and code reviews across the stack (iOS/Android, APIs, backend) with a focus on secure data storage, authentication, authorization, secure communication, and session/token handling
- Leverage AI to accelerate security workflows (e.g., code review support, triage, threat modeling), and partner with teams building AI-enabled features to define and implement production-grade AI security controls
To thrive in this role, you have- 5+ years of experience in application security, with strong hands-on experience across both mobile and backend systems
- Hands on experience securing iOS and Android applications in production environments
- Strong understanding of mobile threat models and common attack techniques
- Experience with mobile security testing techniques, including static and dynamic analysis
- Familiarity with iOS and Android platform security features and limitations
- Practical coding experience, preferably in Ruby, Go, Python languages
- Ability to clearly communicate security risks, tradeoffs, and remediation guidance to engineering partners
#LI-Hybrid #LI-JL1
What we offer for our full-time, regular employees- Our in-office work policy is designed to keep you connected - with four days a week in the office and Fridays from home for those near one of our offices, plus team and company-wide events depending on location. Whether you're coming in regularly or are part of our fully remote program, you'll stay engaged with your work and teammates.
- Benefits that support your work and life, including backup child, elder, and pet care and subsidized commuter benefits for eligible employees.
- Comprehensive health, financial, and wellbeing benefits designed to support you at every stage of life.
- Generous vacation policy and company-wide paid days off
- 1% of your time off to support local community organizations of your choice
- Annual wellness stipend to use towards eligible wellness related expenses
- Up to 22 weeks of paid parental leave for birthing parents and 12 weeks of paid parental leave for non-birthing parents
- Access to family planning reimbursement
- ♥ A challenging and fulfilling opportunity to join one of the most experienced teams in FinTech and help millions unlock financial progress
We know that great work can't be done without a diverse team and inclusive environment. That's why we specifically look for individuals of varying strengths, skills, backgrounds, and ideas to join our team. We believe this gives us a competitive advantage to better serve our members and helps us all grow as Chimers and individuals.