Senior Application Security Engineer (Red Team)
Altruist Los Angeles, California, United States · $170K–$225K/yr
Financial Services · 201-500 employees
About the role
The Senior Application Security Engineer will conduct continuous penetration testing across web, API, mobile, and cloud infrastructure to identify and exploit security vulnerabilities. They will also collaborate with the Detection & Response team on purple-team exercises and develop offensive tooling to improve security controls.
What they look for
Requirements
Candidates must have 4+ years of experience in application or product security with a strong background in penetration testing and security assessments. A bachelor's degree in a relevant field such as Computer Science or Information Security is required, along with technical proficiency in modern tech stacks.
Benefits
Full description
About Altruist
Altruist is transforming the multi-trillion dollar wealth management industry by building an AI platform for wealth professionals. We partner with financial advisors nationwide, empowering them to grow, optimize time and resources, and deliver superior outcomes for their clients.
We're looking for exceptional talent to help us achieve our mission of making financial advice better, more affordable, and accessible to all. If you're passionate about challenging the status quo and want to do the most important work of your life, we'd love to meet you!
But first, our values
Kindness - Kindness doesn’t just equal niceness. We listen to understand. We embrace, and encourage healthy debate and diverse perspectives. We approach conflict openly, honestly, and respectfully.
Brilliance - Humility is the skill we’re most proud of and possessing a growth mindset is always top of mind. We take ownership in everything we touch; regularly using our unique superpowers to reach a common goal as a team. We succeed and fail as one.
Grit - When challenges arise, we stay laser focused on achieving our mission and finding a way forward, even when it’s hard. We are nimble and maintain a sense of urgency, swiftly adapting to change and overcoming obstacles.
• About the position
Altruist is in the midst of an exciting phase and we’re excited to hire a Senior Application Security Engineer to join our growing Security team. Your expertise will ensure our products are secure — by continuously attacking them the way a real adversary would.
This role follows a hybrid schedule, with three days per week onsite in our San Francisco FiDi or Culver City office.
Your impact
- Pentest the Altruist web application, APIs, infrastructure, Android application, and iOS application.
- Break security controls continuously so we can build them better each time.
- Perform focused authorization and exploitability assessments on high-risk attack paths
- Conduct cloud pentests and identity-focused offensive testing.
- Run purple-team exercises with Detection & Response and help build detections from your tradecraft.
- Develop and maintain offensive tooling and repeatable testing playbooks; contribute to phishing and social-engineering assessments.
- Document findings with reproducible proofs-of-concept, clear risk ratings, and actionable remediation guidance.
What you’ll bring
- Experience - 4+ years of experience working as an Application/Product Security Engineer:
- Experience as a pentester across web, API, and mobile targets
- Extensive experience with security assessments
- Experience with tools such as Burp Suite
- Strong ability to work independently
- Education - A B.A. / B.S. degree in relevant fields such as Computer Science or Computer Engineering or Information Security or relevant experience
- Technical aptitude - You’re technologically savvy and can easily get up to speed on modern tech stacks (i.e., Java, Spring, Terraform, Kubernetes, etc.)
- Ownership - The pride you put into every aspect of your work is unparalleled and undeniable
- Superb communication - Intentional dialogue is a superpower. You listen as well as you share your perspective with others.
- Resilience - We’re inspired by your unwavering determination to achieve success, no matter the adversity you face along the way.
- Assurance - Your confidence is brilliant, yet ego-less. You possess a strong knowledge base, the ability to discover the unknown, and are open to differing perspectives.
- Creative problem solving - Identifying the problem is simply not enough. You’re instinctually creative with your approach in finding solutions to roadblocks.
Bonus points if you bring
- Experience working in regulated environments (fintech / financial services)
- Mobile application pentesting (OWASP MASVS) and cloud/red-team / adversary emulation experience
- Relevant certifications (e.g., OSCP, OSWE, GXPN)
Los Angeles, CA salary range
$170,000—$225,000 USD
What we bring
Attracting and retaining top-tier talent is a priority. We are proud of the culture we’ve built and are cognizant of the ever-changing professional landscape. Our dynamic offering of perks and benefits are tailored for you to feel your best while doing your best.
- Stunning, amenity-filled office spaces in Culver City, CA, San Francisco, CA, and Dallas, TX. Our offices are intentionally designed for comfort, collaboration, and productivity.
- Competitive total compensation.
- Premium healthcare, dental, and vision insurance plans (HMO and PPO).
- 401k savings plan with a 4% match and immediate vesting.
- 16 week paid parental leave after one year of employment.
- Professional growth and development opportunities including an employee mobility program and an annual L&D budget allocation for each employee.
- Company perks program (includes discounts on pet insurance, fitness, cell phone plans, and travel, etc.).
- Financial guidance program (includes counseling on navigating debt, tracking personal spend, saving and planning goals, home-purchasing preparedness, etc.).
- One month work from anywhere policy (with the exception of a few countries).
Total compensation includes a competitive benefits package, along with a bonus program for eligible roles. For salaried positions, a salary offer will be determined by a number of factors including experience, skill level, internal pay equity, geographic location, and other relevant business considerations. We review all employee pay and compensation programs regularly to ensure fair, equitable, and competitive pay. At Altruist, we are committed to providing fair, equitable, and competitive compensation by leveraging market data to inform our pay bands. Base salaries will be reviewed at regular intervals throughout the year, typically in conjunction with performance review cycles. By evaluating compensation on a regular basis, we are able to reward high performance and ensure all employees have opportunities for growth.
Don’t meet every single requirement? Studies have shown that women and people of color are less likely to apply to jobs unless they meet every single qualification. At Altruist we are dedicated to building a diverse, inclusive, and authentic workplace, so if you’re excited about this role, but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.
Similar roles
-
Security Engineer, Offensive Security
Anthropic San Francisco, California, United States · $300K–$320K/yr
-
Cybersecurity Supply Chain Risk Management Analyst - Top Secret Clearance
Maania Consultancy Services Washington, District of Columbia, United States
-
Application Security Engineer II - Contract
Jobgether India
-
Senior Staff AI Security Engineer
ServiceNow Santa Clara, California, United States · $191K–$334K/yr
-
Copy of Senior Security Engineer
Pair Team United States · $170K–$190K/yr
-
Cybersecurity Manager
CIMMYT Texcoco, México, Mexico