Lead the Application Security team at Brex, defining security architecture and mentoring engineers in a hybrid work environment.
Posted by employer 3 months ago
First seen on Joblaze 3 months ago
Last verified on the company career page 20 hours ago
Joblaze summary
In the role of Staff Application Security Engineer at Brex, the individual will lead the technical vision and security architecture for the company's platform, focusing on embedding security into fast-paced development processes. Key skills include a strong background in penetration testing, AI security, and proficiency in programming languages like Python or Go. This position is ideal for seasoned professionals with extensive experience in application security and a track record of mentoring teams in complex environments. Brex's commitment to innovation in AI-driven financial services adds a unique dimension to the role.
Quick facts
- Is the Staff Application Security Engineer role remote?
- It's hybrid — Brex expects some on-site time in United States.
- What's the salary range?
- Brex lists $240,000–$300,000 for this role.
- How much experience is required?
- At least 8 years of relevant experience for this Staff Application Security Engineer role.
- Where is the role based?
- Brex is hiring for this position in United States.
- What's the tech stack?
- Joblaze extracted these technologies from the posting: AI/ML, AWS, Go, Kubernetes, Python.
- What seniority level is this role?
- Brex targets staff-level candidates for this position.
- Is this full-time or contract?
- Full-time for this Staff Application Security Engineer role at Brex.
From the original posting
Engineering at Brex
Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It’s an environment where engineering is a craft, and builders become leaders.
Responsibilities:
- Lead the technical vision and strategic roadmap for the Application Security team, aligning security objectives with Brex's enterprise growth and high-velocity engineering metrics.
- Establish technical standards and secure defaults across the entire engineering organization, fostering a culture of collaborative security excellence and bridging product platforms, infra, and trust.
- Architect and secure novel AI/ML and agentic workflows, applying cutting-edge practices to mitigate risks such as prompt injection, model manipulation, and data poisoning.
- Mentor and coach engineers within the team and across the broader organization, guiding technical growth, helping individuals level up their security expertise, and accelerating team delivery.
- Drive proactive vulnerability discovery and offensive security testing strategies, executing complex attack chains to demonstrate business impact and prioritize cross-functional remediation.
- Partner with Product Platform, Cloud Infrastructure, and Data engineering teams to ensure core primitives, APIs, and microservices are secure by default from design to deployment.
Requirements:
- 8+ years of experience in Application Security, Product Security, or software engineering with a primary focus on offensive and defensive application security.
- Proven track record of technical leadership and team mentorship on complex, multi-quarter security engineering initiatives in a fast-paced environment.
- Deep proficiency and technical expertise in AI security, including hands-on experience securing agentic architectures, LLM gateways, and evaluating adversarial AI vectors.
- Strong systems-thinking capabilities with extensive experience defining secure product development lifecycles, threat modeling complex topologies, and cloud-native container security (AWS, Kubernetes).
- Proficiency in Python, Go, or similar languages to architect internal tooling, pipeline automation, and advanced detection/scanning engines.
- Exceptional written and verbal communication skills, with a demonstrated ability to navigate ambiguity, influence technical leaders, and manage up and out across EPD organizations.
Bonus Points:
- Experience with Kotlin, gRPC, GraphQL, Kubernetes
- Previous experience in building and scaling security teams
- Experience with securing distributed systems in AWS and cloud environments
- Contributions to the wider technical community — open source, public research, CTF participation, blogging, CVEs, or presentations
- Experience submitting to bug bounty or responsible disclosure programs
- Published AI security research or contributions to AI security frameworks
Compensation:
The expected salary range for this role is $240,000 USD - $300,000 USD. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.
Please be aware, job-seekers may be at risk of targeting by malicious actors looking for personal data. Brex recruiters will only reach out via LinkedIn or email with a brex.com domain. Any outreach claiming to be from Brex via other sources should be ignored.
Standard company text repeated across Brex's postings is omitted here.