About the Role

We are seeking a Senior Application Security Engineer to join our mission-driven team at the Stellar Development Foundation (SDF). This remote position offers an exciting opportunity to work on cutting-edge blockchain technology and contribute to creating equitable access to the global financial system. You will be instrumental in shaping and scaling the security program across the Stellar ecosystem, ensuring the safety of our network and its users.

What You'll Do

  • Vulnerability Management & AppSec: Own the end-to-end lifecycle of our security stack, managing schedules and partnering with engineering to drive remediation.
  • Manual Assessments: Conduct deep-dive security reviews of SDF codebases, APIs, and infrastructure configurations regularly.
  • Third-Party Audits: Manage external audits from scoping to final report, ensuring effective communication and remediation.
  • Incident Leadership: Act as the lead for security incidents, managing triage, containment, forensics, and stakeholder communication.
  • Detection Engineering: Write, tune, and maintain detection rules to ensure our alert library remains relevant and actionable.
  • Bug Bounty Orchestration: Manage SDF’s programs on HackerOne and Immunefi, triaging submissions and coordinating with engineering.
  • Community Engagement: Represent SDF in community forums and at conferences, sharing insights derived from real operational work.
  • Developer Enablement: Write and maintain security guidance for Stellar and Soroban developers, including secure coding standards.

Requirements

  • 10+ years of experience in SecOps, AppSec, or Detection Engineering.
  • Proficient in writing complex detection logic and managing alert fatigue in platforms like Splunk or Elastic.
  • Experience leading high-pressure incidents through the entire lifecycle.
  • Comfortable auditing AWS environments using tools like Prowler or Steampipe.
  • Hands-on experience with modern security tools: Wiz, Semgrep, CodeQL, tfsec.

Nice to Have

  • Experience with the Stellar protocol or advanced smart contract auditing.
  • Deep knowledge of eBPF-based runtime detection.
  • Active contributions to open-source security projects.

What We Offer

  • Competitive salary range of $140,000 - $170,000 based on experience.
  • Comprehensive health, dental & vision coverage for employees and dependents.
  • Flexible time off + 15 company holidays.
  • Up to 12 weeks of paid parental leave.
  • Gym reimbursement and wellness benefits.
  • Learning & Development budget of $1,500/year.
  • Daily lunch and snacks in the office.
  • Company retreats and team-building activities.
Why This Job8.5 of 10

This Senior Application Security Engineer role offers a unique opportunity to work remotely on impactful blockchain technology. Enjoy competitive pay and excellent benefits.

Salary Range
Required
0/1
Optional
0/1
Bonus
0/1

Who Will Succeed Here

Proficient in AWS and Splunk, with hands-on experience in cloud security frameworks and incident response protocols, enabling rapid identification and remediation of vulnerabilities in a dynamic environment.

Strong understanding of detection engineering techniques and vulnerability management tools, demonstrating the ability to proactively identify security flaws in applications and implement effective bug bounty programs.

Experience in leading security audits and assessments within a remote work environment, showcasing self-motivation and the ability to manage multiple security projects while collaborating with cross-functional teams.

Learning Resources

OWASP Application Security Verification Standardguide

Career Path

Senior Application Security Engineer(Now)Lead Application Security Architect(1-2 years)Director of Security Operations(3-5 years)

Market Overview

Market Size 2024
$18.5B
Annual Growth
12.5%
AI Adoption in Security
45%
Investment in Application Security
+35%
Labour Demand for Security Roles
+28%
Avg Salary for Senior Application Security Engineer
$145K

Skills & Requirements

Required
Application SecurityVulnerability ManagementIncident Response
Growing in Demand
Cloud Security ArchitectureDevSecOpsThreat Intelligence Analysis
Declining
Static Application Security Testing (SAST)Manual Penetration Testing

Domain Trends

Increased Focus on Cloud Security
With 94% of enterprises using cloud services, the demand for cloud security expertise has surged, making it a priority for application security professionals.
Integration of AI in Vulnerability Management
AI technologies in vulnerability management are projected to enhance detection rates by 60%, leading to a significant shift in how security teams operate.
Rise of Bug Bounty Programs
Bug bounty programs are expected to grow by 25% in 2024, reflecting a shift towards community-driven security testing as organizations seek to bolster their defenses.

Industry News

Loading latest industry news...

Finding relevant articles from the last 6 months

All job postings are automatically gathered by algorithms. We do not review or verify listings, be careful when applying and do not sign-in with iCloud or Google services.