chime
San Francisco Office · On-site · Full-time
<h2><span style="font-family: helvetica, arial, sans-serif;"><strong>About the role</strong></span></h2> <p><span style="font-family: helvetica, arial, sans-serif;">We are looking for a Sr. Full Stack Application Security Engineer with deep expertise in mobile application security to join our Product Security team. This role is hands-on and impact driven. You will work directly with mobile, backend, and platform engineering teams to identify, prevent, and remediate security issues across our iOS, Android, API, and backend systems.</span></p> <p><span style="font-family: helvetica, arial, sans-serif;">You will operate close to the code and close to the product. That means reviewing architectures across the stack, influencing secure design decisions early, and helping teams ship features safely without slowing delivery. This role is for someone who understands how modern distributed systems and mobile apps are built, deployed, and attacked in real-world environments.</span></p> <p><span style="font-family: helvetica, arial, sans-serif;">While mobile application security is a core focus, you will be part of a team that owns security posture across the full application stack including APIs, backend services, identity and authentication flows, and CI/CD pipelines.</span></p> <p><span style="font-family: helvetica, arial, sans-serif;">The base salary offered for this role and level of experience will begin at $213,000 and up to $295,000. Full-time employees are also eligible for a bonus, competitive equity package, and benefits. The actual base salary offered may be higher, depending on your location, skills, qualifications, and experience. </span></p> <h2><span style="font-family: helvetica, arial, sans-serif;"><strong>In this role, you can expect to</strong></span></h2> <ul> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Build and improve security capabilities, automation, and guardrails for mobile applications and backend/API services</span></li> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Perform application or API/backend penetration testing </span></li> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Identify, triage, and help remediate vulnerabilities across Chime products</span></li> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Partner closely with engineering and product teams to embed security into the development lifecycle across mobile apps, APIs, and backend services</span></li> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Perform architecture and code reviews across the stack (iOS/Android, APIs, backend) with a focus on secure data storage, authentication, authorization, secure communication, and session/token handling</span></li> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Leverage AI to accelerate security workflows (e.g., code review support, triage, threat modeling), and partner with teams building AI-enabled features to define and implement production-grade AI security controls </span></li> </ul> <h2><span style="font-family: helvetica, arial, sans-serif;"><strong>To thrive in this role, you have</strong></span></h2> <ul> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">5+ years of experience in application security, with strong hands-on experience across both mobile and backend systems </span></li> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Hands on experience securing iOS and Android applications in production environments</span></li> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Strong understanding of mobile threat models and common attack techniques</span></li> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;&
chime
Posted via Greenhouse_public
Apply Now takes you to Rozgoo, where auto-apply can submit your application for this role. Updated 4 days ago.
Apply Now