NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in United States of America
3 days ago
Apply with autofill
Apply with autofill
Fomo-labs·3 days ago
3 days ago

Staff Security Engineer, Application Security

New York City, United States of AmericaFull-timeOn-siteSenior · 7+ years₹2.2Cr – ₹2.7Cr/yr · est.Security Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at fomo-labs

How you compare FREE

?
Your scoreYour score: not yet known
→
49
Top 10%Top 10%: 49 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in United States.

Must-have skills for this role

  • application security
  • threat modeling
  • secure SDLC
  • sast

PDF or DOCX · no account needed

Apply faster with autofill FREEfomo-labs uses Ashby - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Lead security architecture reviews and threat modeling for new features and major system changes, partnering directly with engineering and product teams from design through launch
  • Own our secure SDLC program: static and dynamic analysis (SAST/DAST), dependency and software composition analysis, secrets scanning, and CI/CD security gates
  • Perform deep-dive code reviews and manual penetration testing of high-risk services, APIs, and web applications
  • Design and build internal security tooling and guardrails that let engineers move fast without introducing risk
  • Run and mature our vulnerability management program, including triage, severity scoring, and driving remediation with engineering owners
  • Manage relationships with external pentest vendors and bug bounty programs, and turn findings into durable fixes rather than one-off patches
  • Set technical direction on authentication, authorization, API security, and data protection patterns used across the product
  • Mentor engineers on secure coding practices and act as a go-to resource for security questions across the org
  • Contribute to incident response when application-layer issues arise
  • Help define and evolve fomo's overall AppSec roadmap and metrics

What they're looking for

  • 7+ years in security engineering, with a substantial and recent focus on application security (not primarily corporate/IT security)
  • Deep hands-on experience with secure code review, threat modeling, and common vulnerability classes (OWASP Top 10, auth/session flaws, SSRF, injection, business logic flaws, etc.)
  • Strong software engineering background; comfortable reading and writing production code, not just running scanners
  • Experience building and scaling AppSec tooling and processes (SAST/DAST, SCA, CI/CD security integration) at a growing company
  • Track record of driving security into engineering culture through influence, not just gatekeeping
  • Familiarity with cloud-native environments (AWS/GCP/Azure), container security, and modern API architectures
  • Excellent communication skills; able to explain risk to both engineers and non-technical stakeholders
  • Prior experience as a technical lead or staff-level IC who can operate with high autonomy

Nice to have

  • Experience with bug bounty program management
  • Background in a high-growth consumer or marketplace product

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

About fomo

  • fomo is a trading app for the rest of us. With fomo you can sign up in seconds and have instant access to any asset on-chain without the need for external wallets, bridges or prior knowledge. fomo has social features that are actually useful - follow top traders (with full access to their portfolio and trades) and find tokens early. fomo does all of this while providing the best-in-class execution and data for experienced traders.

  • In just over a year, fomo has onboarded over 2.5 million plus users who have collectively done over $14 billion dollars in trading volume.

  • fomo has made ~$68M of revenue since launching in May 2025, and has raised a total of ~$100M in addition from T1 investors. Investors include Benchmark, Index Ventures, and Union Square Ventures.

  • https://fomo.family/

  • https://x.com/fomo

About the role

  • We're hiring a Staff Security Engineer to own and elevate our application security program. This is a hands-on, high-leverage role for someone who wants to be the technical authority on how we build secure software, not just someone who reviews tickets after the fact. You'll work directly with the engineering team to find and fix vulnerabilities, build tooling that scales security across the org, and shape how fomo thinks about security at the architecture and code level.

  • This role skews heavily toward product and application security. You won't be spending your time on corporate IT, endpoint management, or employee-facing security operations. Instead, you'll be embedded in how our product is designed, built, and shipped.

What you'll do

  • Lead security architecture reviews and threat modeling for new features and major system changes, partnering directly with engineering and product teams from design through launch

  • Own our secure SDLC program: static and dynamic analysis (SAST/DAST), dependency and software composition analysis, secrets scanning, and CI/CD security gates

  • Perform deep-dive code reviews and manual penetration testing of high-risk services, APIs, and web applications

  • Design and build internal security tooling and guardrails that let engineers move fast without introducing risk

  • Run and mature our vulnerability management program, including triage, severity scoring, and driving remediation with engineering owners

  • Manage relationships with external pentest vendors and bug bounty programs, and turn findings into durable fixes rather than one-off patches

  • Set technical direction on authentication, authorization, API security, and data protection patterns used across the product

  • Mentor engineers on secure coding practices and act as a go-to resource for security questions across the org

  • Contribute to incident response when application-layer issues arise

  • Help define and evolve fomo's overall AppSec roadmap and metrics

What we're looking for

  • 7+ years in security engineering, with a substantial and recent focus on application security (not primarily corporate/IT security)

  • Deep hands-on experience with secure code review, threat modeling, and common vulnerability classes (OWASP Top 10, auth/session flaws, SSRF, injection, business logic flaws, etc.)

  • Strong software engineering background; comfortable reading and writing production code, not just running scanners

  • Experience building and scaling AppSec tooling and processes (SAST/DAST, SCA, CI/CD security integration) at a growing company

  • Track record of driving security into engineering culture through influence, not just gatekeeping

  • Familiarity with cloud-native environments (AWS/GCP/Azure), container security, and modern API architectures

  • Excellent communication skills; able to explain risk to both engineers and non-technical stakeholders

  • Prior experience as a technical lead or staff-level IC who can operate with high autonomy

Nice to Have

  • Experience with bug bounty program management

  • Background in a high-growth consumer or marketplace product

Why fomo

You'll be the first dedicated AppSec hire shaping the security foundation of a company at real scale, with the autonomy to set standards rather than inherit them.

Compensation and benefits

fomo offers:

  • Competitive cash compensation and equity

  • Comprehensive health insurance including medical, dental, and vision for you and your dependents; including tax savings benefits such as HSAs and FSAs

  • 401(k) with match

  • Group term life insurance

  • Flexible time off

  • Annual company offsites

Equal opportunity

fomo is an equal opportunity employer. We consider qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other characteristic protected by applicable law. If you need a reasonable accommodation during the hiring process, please let us know.

Company

Fomo-labs
New York City, United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Fomo Labs's careers site·first seen 17 Sept 2026·last verified 17 Sept 2026·How we source jobs

Similar jobs

  • Staff Security Engineer at robotsandpencilsUS - Remote–match not yet calculated
  • IT Security Engineer at zollChelmsford, United States of America–match not yet calculated
  • Cybersecurity Summer 2027 Intern (Undergraduate) at centeneRemote-MO–match not yet calculated
  • AI Security Engineer at trimbleUS - Remote, CO–match not yet calculated
  • Medical Device Cybersecurity Co-Op at Johnson & JohnsonDanvers, United States of America–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United States
  • Security Analyst jobs in United States
  • Cloud Security Engineer jobs in United States
  • Penetration Tester jobs in United States
  • Security Engineer jobs in India
  • Security Engineer jobs in United Kingdom