{"id":841839,"url":"https://alion.io/job/brex-staff-application-security-engineer","title":"Staff Application Security Engineer","company":{"id":18232,"name":"Brex","domain":"brex.com","url":"https://alion.io/company/brex","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"B","score":82,"open_postings":79,"ghost_share":0,"stale_share":0.709,"repost_share":0,"time_to_fill_p50_days":58,"computed_at":"2026-10-05T05:45:15Z"}},"role":"Security","role_family":"Security","seniority":"staff","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":240000,"max":300000,"currency":"USD","period":"year","gross":null,"usd_annual":300000},"salary_estimate":null,"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agentic Workflows","optional":false},{"name":"AI Agents","optional":false},{"name":"AWS","optional":false},{"name":"Kubernetes","optional":false},{"name":"LLM","optional":false},{"name":"Python","optional":false},{"name":"Threat Modeling","optional":false},{"name":"GraphQL","optional":true},{"name":"gRPC","optional":true},{"name":"Kotlin","optional":true}],"status":"live","first_seen_at":"2026-06-25T18:42:35Z","employer_posted_date":"2026-08-19","last_verified_at":"2026-10-06T00:10:00Z","board_verified":true,"closed_at":null,"days_open":102,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":102},"description":"Why join us\nBrex is the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets. By combining global corporate cards and banking with intuitive spend management, bill pay, and travel software, Brex enables founders and finance teams to accelerate operations, gain real-time visibility, and control spend effortlessly. Brex’s AI-native automation and world-class service eliminate manual expense and accounting tasks for customers so they can focus on what matters most. Tens of thousands of the world's best companies run on Brex, including DoorDash, Coinbase, Robinhood, Zoom, Plaid, Reddit, and SeatGeek.\nWorking at Brex allows you to push your limits, challenge the status quo, and collaborate with some of the brightest minds in the industry. We’re committed to building a diverse team and inclusive culture and believe your potential should only be limited by how big you can dream. We make this a reality by empowering you with the tools, resources, and support you need to grow your career.\nEngineering at Brex\nEngineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level - from architecture to deployment. It’s an environment where engineering is a craft, and builders become leaders.\nResponsibilities:\nLead the technical vision and strategic roadmap for the Application Security team, aligning security objectives with Brex's enterprise growth and high-velocity engineering metrics.\nEstablish technical standards and secure defaults across the entire engineering organization, fostering a culture of collaborative security excellence and bridging product platforms, infra, and trust.\nArchitect and secure novel AI/ML and agentic workflows, applying cutting-edge practices to mitigate risks such as prompt injection, model manipulation, and data poisoning.\nMentor and coach engineers within the team and across the broader organization, guiding technical growth, helping individuals level up their security expertise, and accelerating team delivery.\nDrive proactive vulnerability discovery and offensive security testing strategies, executing complex attack chains to demonstrate business impact and prioritize cross-functional remediation.\nPartner with Product Platform, Cloud Infrastructure, and Data engineering teams to ensure core primitives, APIs, and microservices are secure by default from design to deployment.\nRequirements:\n8+ years of experience in Application Security, Product Security, or software engineering with a primary focus on offensive and defensive application security.\nProven track record of technical leadership and team mentorship on complex, multi-quarter security engineering initiatives in a fast-paced environment.\nDeep proficiency and technical expertise in AI security, including hands-on experience securing agentic architectures, LLM gateways, and evaluating adversarial AI vectors.\nStrong systems-thinking capabilities with extensive experience defining secure product development lifecycles, threat modeling complex topologies, and cloud-native container security (AWS, Kubernetes).\nProficiency in Python, Go, or similar languages to architect internal tooling, pipeline automation, and advanced detection/scanning engines.\nExceptional written and verbal communication skills, with a demonstrated ability to navigate ambiguity, influence technical leaders, and manage up and out across EPD organizations.\nBonus Points:\nExperience with Kotlin, gRPC, GraphQL, Kubernetes\nPrevious experience in building and scaling security teams\nExperience with securing distributed systems in AWS and cloud environments\nContributions to the wider technical community - open source, public research, CTF participation, blogging, CVEs, or presentations\nExperience submitting to bug bounty or responsible disclosure programs\nPublished AI security research or contributions to AI security frameworks\nCompensation:\nThe expected salary range for this role is $240,000 USD - $300,000 USD. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.\nPlease be aware, job-seekers may be at risk of targeting by malicious actors looking for personal data. Brex recruiters will only reach out via LinkedIn or email with a brex.com domain. Any outreach claiming to be from Brex via other sources should be ignored.","description_format":"text","description_chars":4737,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Equity"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Cards & Card Issuing","Procurement & Spend Management","Digital Banks & Neobanks"],"lifecycle":[{"event":"open","at":"2026-09-12T22:11:39Z"}],"visa":[{"country":"US","licensed_sponsor":true,"evidence":"H-1B filings in 12 months: 25 · green card filings: 2","filings_12m":25,"filings_prev_12m":31,"green_card_filings_12m":2,"median_offered_wage_usd":179352,"route":null,"cap_exempt":false,"checked_at":"2026-10-03T21:08:04+00:00","sources":["US Department of Labor: LCA disclosure data (H-1B, H-1B1, E-3)","US Department of Labor: PERM disclosure data (green cards)"],"filings_for_role_12m":1}],"liveness":{"score":16,"band":"cold","label":"Long shot","p_open":1,"p_active":0.452,"p_room":0.36,"age_days":101,"expected_fill_days":58,"reasons":["conf:1","stale_co","velocity","win:tail","crowd:brand"],"computed_at":"2026-10-05T05:45:15Z"},"pay":{"stated_usd_annual":300000,"is_top_pay":true},"html_url":"https://alion.io/job/brex-staff-application-security-engineer","json_url":"https://alion.io/job/brex-staff-application-security-engineer.json","meta":{"generated_at":"2026-10-06T00:20:22Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":402,"day_limit":5000,"remaining_today":4598,"minute_limit":60,"resets_at":"2026-10-07T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":18232},"rest":"https://alion.io/mcp/rest/get_company?id=18232"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fbrex-staff-application-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fbrex-staff-application-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fbrex-staff-application-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/brex-staff-application-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fbrex-staff-application-security-engineer"}]}