368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$124k – $229k per year (Estimated)
Location
Remote (United States)
Seniority
Senior · 7+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Beyond Finance is a financial technology company headquartered in Houston, Texas, and founded in 2016. The organization provides debt consolidation services, debt settlement programs, and financial wellness tools designed to help clients manage and reduce unsecured debt. It operates primarily within the United States, utilizing proprietary technology to offer personalized financial solutions and support to individuals struggling with high-interest credit card debt.

At Beyond Finance, we've made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care, a culture focused on compliance and ethics, supportive user-centric technology, and customized financial solutions, we've helped over 1 million clients on their path to a brighter future.

While we're proud of what we've already accomplished, we're searching for new collaborators to help us get to the next level! If you're looking to join a forward-thinking, rapidly growing organization with helping people as its number one goal, we want to hear from you.

Role Overview

As our Application Security Engineer, you will be the primary owner and driver of our application security program. You'll work hands-on with engineering teams to embed secure development practices, improve tooling and automation, and guide security considerations for new features, architectures, and services.

This is a high-impact role where you'll shape the future of AppSec at a company that values security as a core part of product quality.

What You'll Do

Application Security Ownership

  • Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
  • Serve as the primary AppSec partner for numerous dev teams working on Ruby on Rails web apps, React Native mobile apps, and various other projects including Python and Go.
  • Provide security guidance during design, development, and code review for new features and projects.
  • Drive adoption of secure coding practices and threat-modeling across engineering teams.

Tooling & Automation

  • Manage and optimize existing AppSec tooling, including:
  • GitHub Advanced Security (SAST, SCA, Secret Scanning)
  • Invicti (DAST)
  • Hadrian (ASM)
  • AppDome (mobile application security)
  • Cloudflare WAF
  • Improve automation and integration of security tools into CI/CD pipelines.
  • Identify and implement additional tools or processes to strengthen the security posture.

Secure SDLC & Developer Enablement

  • Build and maintain secure development standards, playbooks, and training materials.
  • Partner with engineering teams during sprint planning and feature design to proactively address risks.
  • Conduct security reviews, code assessments, and vulnerability triage with development teams.

Cloud & DevOps Collaboration

  • Work with DevOps to ensure secure AWS infrastructure deployments and configurations.
  • Contribute to hardening efforts across ECS, IAM, networking, and supporting cloud services.
  • Assist in designing and maintaining secure CI/CD workflows.

Incident & Vulnerability Management

  • Lead or support investigation and remediation of application-level vulnerabilities.
  • Monitor, prioritize, and track findings from SAST/DAST/ASM tools.
  • Collaborate with engineering to ensure timely and effective remediation.

What We're Looking For

Required Skills & Experience

  • 3-7+ years of experience in Application Security, Product Security, or related engineering roles.
  • Strong understanding of secure coding practices, common vulnerabilities (OWASP Top 10), and modern SDLC.
  • Experience working with cloud-native applications, ideally in AWS.
  • Understanding of SSL certificates & cryptographic key management.
  • Hands-on experience with SAST, DAST, WAFs, and/or mobile application security tools.
  • Ability to partner effectively with developers and influence secure design decisions.
  • Familiarity with GitHub-based workflows and CI/CD pipelines.

Nice to Have

  • Development experience with Ruby on Rails or similar dynamic languages.
  • Knowledge of AWS ECS/EKS, container security, secrets management and infrastructure-as-code (CloudFormation, Terraform).
  • Experience building or maturing an AppSec program from early stages.
  • SOAR Automation & Scripting experience.
  • Experience working in a PCI-compliant environment working with annual reporting needs.

The Ideal Candidate

The ideal candidate measures success by reduced risk, not tickets closed, and reaches for secure design and simple guardrails before another scanner or gate. They think like an attacker but bring a developer mindset to their partnership with engineering, connecting the dots across application code, cloud infrastructure, and the pipeline rather than treating each as a separate domain. Engineers trust their technical judgment, and when something is blocked, they come with a proposed path forward.

The base annual salary range is listed below. This role is eligible for additional incentives, including an annual bonus.

Base Salary Range

$140,000—$165,000 USD

Why Join Us?

While you make a difference for others, we’ll work to make a difference for you, providing an uplifting, collaborative work environment and benefits that reflect your value to us. For eligible full-time employees, we offer:

  • Considerable employer contributions for health, dental, and vision programs
  • Generous PTO, paid holidays, and paid parental leave
  • 401(k) matching program
  • Merit advancement opportunities
  • Career development & training

And finally, our team spirit and culture! Wecultivate an environment of community, connection, and belonging across our entire organization.

Beyond Finance does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job positions.  No fee will be paid to their parties who submit unsolicited candidates directly to Beyond Finance employees or the Beyond Finance HR team.  No placement fee will be paid to any third party unless such a request has been made by the Beyond HR team.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$105k – $252k per year • Remote • Full-Time • 18+ years exp • Bachelor's Degree
Python
Java
Java
Gradle
DevOps
Ansible
AWS
CI/CD
CloudFormation
Configuration Management
Docker
GitHub Actions
GitLab CI
Helm
Jenkins
Kubernetes
Platform Engineering
Terraform
GitHub
GitLab
Cybersecurity
Sonatype Nexus IQ
Management
Confluence
Jira
Apply
$54k – $175k per year (Estimated) • Remote • Full-Time
JavaScript
Node JS
TypeScript
Frontend
React.js
Sass
DevOps
AWS
CI/CD
Docker
Kubernetes
Rest API
Apply
$35k – $113k per year (Estimated) • Remote • Full-Time
JavaScript
Node JS
TypeScript
Frontend
React.js
Sass
DevOps
AWS
CI/CD
Docker
Kubernetes
Rest API
Apply
$35k – $116k per year (Estimated) • Remote • Full-Time
JavaScript
Node JS
TypeScript
Frontend
React.js
Sass
DevOps
AWS
CI/CD
Docker
Kubernetes
Rest API
Apply
$61k – $200k per year (Estimated) • Remote • Full-Time
JavaScript
Node JS
TypeScript
Frontend
React.js
Sass
DevOps
AWS
CI/CD
Docker
Kubernetes
Rest API
Apply
$123k – $272k per year (Estimated) • In office • Full-Time • 7+ years exp • Chicago
DevOps
AWS
CI/CD
Terraform
Apply
$141k – $277k per year (Estimated) • Remote • Full-Time • 8+ years exp
Assembly
Python
Ruby
Ruby
Ruby on Rails
AI/ML
LLM Guardrails
Red Teaming
DevOps
AWS
CI/CD
Terraform
IAM
Cybersecurity
Threat Modeling
Apply
$123k – $229k per year (Estimated) • Remote • Full-Time • 5+ years exp
Go
Python
Ruby
Ruby
Ruby on Rails
AI/ML
LLM Guardrails
DevOps
AWS
CI/CD
Cloudflare
SLI/SLO/SLA
Terraform
GitHub
IAM
Cybersecurity
OWASP Top 10
Threat Modeling
Wiz
Zero Trust
Apply
$74k – $212k per year (Estimated) • Remote/Hybrid • Full-Time • 7+ years exp • Chicago
AI/ML
Human-in-the-Loop
DevOps
AWS
Datadog
Cybersecurity
Datadog Cloud Security
PCI DSS
SOC 2
Apply
$134k – $240k per year (Estimated) • Remote • Full-Time • 8+ years exp • Bachelor's Degree
Ruby
SQL
Ruby
Ruby on Rails
Databases
Amazon Aurora
PostgreSQL
AI/ML
AI Agents
DevOps
AWS
Azure
GCP
Platform Engineering
Analytics
ETL/ELT
Marketing
Salesforce
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.