Staff Security Engineer, Application Security

FOMO Labs Inc

$150K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in security engineering with a focus on application security.
  • Hands-on expertise in secure code review and threat modeling.
  • Strong understanding of common vulnerability risks (e.g., OWASP Top 10).
  • Proficient in building AppSec tooling and processes in a growth-focused environment.
  • Excellent communication skills to convey security risks effectively.
  • Experience in cloud-native environments and container security.
  • Prior experience in a technical lead role with a high level of autonomy.

Responsibilities

  • Lead security architecture reviews and threat modeling for new features.
  • Own the secure SDLC program including SAST, DAST, and CI/CD security gates.
  • Conduct deep-dive code reviews and manual penetration testing of high-risk services.
  • Design and create internal security tooling to facilitate rapid engineering.
  • Manage vulnerability remediation and ensure durable fixes from external vendors.
  • Define and establish best practices for authentication, authorization, and API security.
  • Mentor engineering teams on secure coding practices and serve as a security advisor.

Benefits

  • Comprehensive health insurance for you and your dependents.
  • 401(k) plan with matching contributions.
  • Group term life insurance.
  • Flexible time off policy.
  • Annual company offsites.
Full Job Description
About the role
  • We're hiring a Staff Security Engineer to own and elevate our application security program. This is a hands-on, high-leverage role for someone who wants to be the technical authority on how we build secure software, not just someone who reviews tickets after the fact. You'll work directly with the engineering team to find and fix vulnerabilities, build tooling that scales security across the org, and shape how fomo thinks about security at the architecture and code level.
  • This role skews heavily toward product and application security. You won't be spending your time on corporate IT, endpoint management, or employee-facing security operations. Instead, you'll be embedded in how our product is designed, built, and shipped.


What you'll do
  • Lead security architecture reviews and threat modeling for new features and major system changes, partnering directly with engineering and product teams from design through launch
  • Own our secure SDLC program: static and dynamic analysis (SAST/DAST), dependency and software composition analysis, secrets scanning, and CI/CD security gates
  • Perform deep-dive code reviews and manual penetration testing of high-risk services, APIs, and web applications
  • Design and build internal security tooling and guardrails that let engineers move fast without introducing risk
  • Run and mature our vulnerability management program, including triage, severity scoring, and driving remediation with engineering owners
  • Manage relationships with external pentest vendors and bug bounty programs, and turn findings into durable fixes rather than one-off patches
  • Set technical direction on authentication, authorization, API security, and data protection patterns used across the product
  • Mentor engineers on secure coding practices and act as a go-to resource for security questions across the org
  • Contribute to incident response when application-layer issues arise
  • Help define and evolve fomo's overall AppSec roadmap and metrics
What we're looking for
  • 7+ years in security engineering, with a substantial and recent focus on application security (not primarily corporate/IT security)
  • Deep hands-on experience with secure code review, threat modeling, and common vulnerability classes (OWASP Top 10, auth/session flaws, SSRF, injection, business logic flaws, etc.)
  • Strong software engineering background; comfortable reading and writing production code, not just running scanners
  • Experience building and scaling AppSec tooling and processes (SAST/DAST, SCA, CI/CD security integration) at a growing company
  • Track record of driving security into engineering culture through influence, not just gatekeeping
  • Familiarity with cloud-native environments (AWS/GCP/Azure), container security, and modern API architectures
  • Excellent communication skills; able to explain risk to both engineers and non-technical stakeholders
  • Prior experience as a technical lead or staff-level IC who can operate with high autonomy
Nice to Have
  • Experience with bug bounty program management
  • Background in a high-growth consumer or marketplace product
Why fomo

You'll be the first dedicated AppSec hire shaping the security foundation of a company at real scale, with the autonomy to set standards rather than inherit them.

Compensation and benefits

fomo offers:
  • Competitive cash compensation and equity
  • Comprehensive health insurance including medical, dental, and vision for you and your dependents; including tax savings benefits such as HSAs and FSAs
  • 401(k) with match
  • Group term life insurance
  • Flexible time off
  • Annual company offsites

Similar Jobs

More Jobs at FOMO Labs Inc

  • Staff Distributed Systems Engineer
    $150K — $180K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • Staff Backend Engineer
    $150K — $180K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • Controller
    $125K — $150K *
    Remote
    Finance & Insurance
    Remote in New York City, NY
  • Controller
    $150K — $180K *
    New York, NY 10025 (New York County)
    Finance & Insurance
    In-Person
  • Brand Marketing Designer
    $80K — $95K *
    New York, NY 10025 (New York County)
    Media
    In-Person

More Information Technology Jobs

Find similar Staff Security Engineer, Application Security jobs: