4 hours ago
Washington, DC, USA +3 moreMid Level / Senior
H1B sponsor
Base Salary
$100k - $258k/yr
Responsibilities
- Conduct code reviews and static analysis to identify and mitigate vulnerabilities in financial applications.
- Design secure coding guidelines and integrate security practices into development workflows and CI/CD pipelines.
- Perform threat modeling and risk assessments for payments, wallets, ledgers, and related product surfaces.
- Develop mitigations for fraud, abuse, and unauthorized movement of funds or credits.
- Manage vulnerability tracking, remediation efforts, and guidance for development teams.
- Manage the bug bounty program, including intake, triage, researcher communication, and coordinated disclosure.
- Support application-security incident response activities.
- Monitor emerging threats against financial and cloud-native systems and strengthen security controls.
- Evaluate and secure software supply chains, including producing and maintaining SBOMs.
- Design and implement agentic and LLM-based solutions for detecting, investigating, or preventing security problems.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
- 3–5 years of application-security experience with a strong focus on code security practices.
- Experience securing payments, money transmission, digital wallets, ledgers, or related high-value financial platforms.
- Deep understanding of secure coding practices, application-security frameworks, and common vulnerabilities such as the OWASP Top 10.
- Proficiency in Python or Rust and experience applying secure coding practices in those languages.
- Experience securing CI/CD pipelines and implementing DevSecOps practices.
- Familiarity with software supply-chain security and SBOM generation tools.
- Experience with security-testing tools such as Burp Suite and OWASP ZAP, plus static and dynamic code analysis.
- Experience designing and implementing agentic and LLM-based solutions for security problems.
- Excellent communication skills for explaining complex security issues to technical and non-technical audiences.
- Preferred experience securing applications on AWS and familiarity with other cloud platforms.
- Preferred security certifications such as BSCP, OSCP, or OSWE.
- Preferred experience managing bug bounty programs and knowledge of data privacy and financial-product compliance.
- Preferred experience with GitOps, infrastructure-as-code security, custom security tooling, and open-source security contributions.
Benefits
- Equity and comprehensive medical, vision, and dental coverage.
- Access to a 401(k) retirement plan, short- and long-term disability insurance, life insurance, discounts, and other perks.
About xAI
Understand the Universe. We are a team of AI technologists and business leaders on a mission to build AI systems that can help humanity understand the world better. https://x.ai/careers