Senior Application Security Engineer

June 24

Apply Now
Logo of TRM Labs

TRM Labs

Blockchain • Cybersecurity • Finance

TRM Labs is a company that delivers blockchain intelligence to detect crypto-facilitated crime and ensure compliance and safety worldwide. Their services include forensics, tactical transaction monitoring, wallet screening, and know-your-entity solutions. TRM Labs supports government agencies, financial institutions, and crypto businesses globally by providing blockchain investigations and risk management solutions to combat fraud and financial crime. They are trusted by leading organizations to help prove crypto cases in court and build safer financial systems.

51 - 200 employees

🔒 Cybersecurity

💸 Finance

💰 $70M Series B on 2022-11

📋 Description

• TRM Labs is a blockchain intelligence company committed to fighting crime and creating a safer world. • The Security team is responsible for and committed to securing all things at TRM. • We are looking for an Application Security Engineer to build mission-critical infrastructure that ensures the highest levels of availability, performance, and application security at TRM for products as built and deployed. • Lead application security reviews and threat modeling, including secure code review, architectural design, and testing. • Develop automated testing and mature our Secure SDLC. • Own and perform application security vulnerability management. • Coordinate penetration testing engagements. • Support software engineers and product teams by developing application security best practices. • Develop and maintain the bug bounty program. • Bootstrap platform security initiatives that help protect TRM data. • Inspire a culture of security across the engineering organization by fostering security champions within engineering teams and coordinating secure code training.

🎯 Requirements

• Minimum 8 years of experience in Software Development and testing. • BS (or equivalent) in Computer Science, Computer Engineering, or related field. • Proficiency in software development languages: Python, NodeJS, React • Strong understanding of encryption, authentication, and authorization protocols • Deep experience with common software flaws (e.g., OWASP and CWE), testing methodologies , and using common security tooling for testing. • Professional experience with open source, commercial, or native security solutions for cloud providers such as GCP and AWS. Experience with modern secure software development lifecycles, threat modeling, and best practices. • Experience with conducting efficient and comprehensive code security reviews on a daily or weekly basis • Experience triaging and remediating vulnerabilities in software packages or libraries • Experience with Software Security tools such as Github advanced security or other SAST, DAST, and SCA tools • Experience with Web application testing frameworks such as BurpSuite, OWASP ZAP, etc. • Experience with Threat modeling tools such as OWASP Threat Dragon, etc. • Experience working in a previous agile-based software development role required • Experience Red Teaming or penetration testing applications and infrastructure • Professional experience with cloud providers (e.g., GCP and AWS), modern secure software development lifecycles, and best practices. • Strong written and verbal communication skills. • Security certifications such as OSCP, CEH, GWAPT are a plus. • Familiarity with security frameworks (e.g., NIST SP 800-171 SSDF) is a plus

🏖️ Benefits

• PTO • Holidays • Parental Leave for full-time employees

Apply Now

Similar Jobs

May 27

As a senior application security engineer, you'll secure Confluent's data streaming platform and product offerings.

Cloud

Java

Python

May 13

Lead application security efforts focusing on automated scanning and remediation within SDLC at Caesars.

AWS

Azure

Cloud

Cyber Security

Google Cloud Platform

Jenkins

Python

SDLC

Terraform

Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or support@remoterocketship.com