About the Role

We are seeking an Application Security Engineer to join our team at MoonPay. This remote position offers an exciting opportunity to contribute to the security of our digital payment platform. As an Application Security Engineer, you will play a crucial role in ensuring the safety and integrity of our systems, making financial freedom accessible to everyone.

What You'll Do

  • Conduct threat modeling reviews of Technical Design Documents (TDDs) for new and existing features, providing clear, actionable security recommendations early in the design process.
  • Perform and support application security assessments, including penetration testing, vulnerability assessments, and proof-of-concept (PoC) development where appropriate.
  • Investigate, triage, and respond to Bug Bounty program submissions, validating findings and working with engineering teams to drive timely remediation.
  • Own and continuously improve application-layer protections, including managing and tuning Cloudflare WAF and related security controls.
  • Partner closely with engineering teams to embed security best practices throughout the SDLC, from design and development through deployment and maintenance.
  • Research and track emerging threats and vulnerabilities, translating findings into practical mitigation strategies relevant to our technology stack.
  • Develop and deliver security guidance, training, and awareness for engineering teams to raise the overall security maturity of the organization.
  • Participate in and eventually lead incident response activities, supporting investigation, containment, remediation, and post-incident improvements.

Requirements

  • Experience across multiple security domains, including web and mobile application security, infrastructure and cloud security.
  • Hands-on experience performing white-box, source code-assisted web and mobile application penetration testing.
  • Ability to read, understand, and review source code, particularly in JavaScript and TypeScript.
  • Strong understanding of Threat Modeling principles and their practical application to the secure software development lifecycle (SDLC).
  • Experience working with web application firewalls to help protect applications and assess coverage.
  • Experience embedding application security practices into CI/CD pipelines.
  • Ability to communicate security findings clearly to both technical and non-technical audiences.
  • Self-motivated and proactive, with a collaborative mindset.

Nice to Have

  • Experience with Cloudflare, including its hosting and Web Application Firewall (WAF) capabilities.
  • Experience testing and securing GraphQL and REST APIs.
  • Interest in Web3 security testing, including assessing smart contracts and blockchain-based applications.

What We Offer

  • Competitive salary package.
  • Equity package for all employees.
  • Pay for performance equity bonus.
  • Unlimited holidays for work-life balance.
  • Hybrid working schedule - fully remote or at your nearest Moonbase.
  • Private healthcare benefits.
  • Annual training budget for professional development.
  • Home office setup allowance.
  • Remote working allowance for utilities.
  • Employee referral program with rewards.

Join us as an Application Security Engineer and help shape the future of payments in the decentralized economy. This remote role is your chance to make a significant impact in a fast-growing company.

Language Requirements
EnglishC1
BasicIntermediateAdvancedNative
Why This Job8.5 of 10

This role offers a unique opportunity to work remotely as an Application Security Engineer at MoonPay, a leader in the crypto space. With a competitive salary and equity options, you can make a significant impact on the security of digital payments.

Salary Range
Required
0/1
Optional
0/1
Bonus
0/1

Who Will Succeed Here

Proficient in Application Security best practices, with hands-on experience in Penetration Testing and Vulnerability Assessment using tools like OWASP ZAP and Burp Suite, specifically in JavaScript and TypeScript environments.

Self-motivated and disciplined in a remote work setting, demonstrating the ability to manage time effectively and collaborate asynchronously with cross-functional teams to address security challenges.

Analytical mindset with experience in conducting threat modeling sessions, capable of identifying potential security risks in applications and implementing mitigations in cloud environments, particularly with Cloudflare and Web Application Firewalls.

Learning Resources

OWASP Application Security Verification Standardguide

Career Path

Application Security Engineer(Now)Senior Application Security Engineer(2-4 years)Lead Security Architect(5-7 years)

Market Overview

Market Size 2024
$17.5B
Annual Growth
12.4%
AI Adoption
35%
Investment in Application Security
+50%
Labour Demand for Application Security Roles
+28%
Avg Salary for Application Security Engineer
$120K

Skills & Requirements

Required
Application SecurityPenetration TestingVulnerability Assessment
Growing in Demand
DevSecOps PracticesCloud Security ArchitectureContainer Security (e.g., Docker, Kubernetes)
Declining
Static Application Security Testing (SAST) tools with limited integrationManual Penetration Testing techniques without automation

Domain Trends

Increased Adoption of DevSecOps
Organizations are integrating security practices into the DevOps pipeline, leading to a 40% increase in demand for professionals skilled in DevSecOps.
Rise in Cloud Security Concerns
With over 70% of enterprises migrating to the cloud, there is a significant focus on securing cloud applications, resulting in a 60% increase in investment in cloud security solutions.
Emergence of AI-Driven Security Tools
AI-driven security solutions are projected to grow by 25% in the next two years, as organizations seek to automate threat detection and response.

Industry News

Loading latest industry news...

Finding relevant articles from the last 6 months

All job postings are automatically gathered by algorithms. We do not review or verify listings, be careful when applying and do not sign-in with iCloud or Google services.