Figure
Application Security Engineer
engineeringfull-timeRemote
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
fintech
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more
About the role
About the Role
As an Application Security Engineer at Figure, you will be pivotal in the security of our software from the first line of code through deployment. You'll build and scale our vulnerability management program, embed secure coding practices into engineering workflows, and help ensure security standards are met at every stage of the software development lifecycle. We’re looking for a collaborative, hands-on engineer with a strong background in reading and writing code. You’ll partner closely with Engineering, DevOps, and IT to ensure our security processes are resilient, scalable, and seamlessly integrated into our workflows.
What You’ll Do
- Architect, design, and implement end-to-end security solutions, including firewalls, intrusion detection, encryption protocols, security event management, and cloud security controls.
- Collaborate with DevOps to integrate security into CI/CD pipelines, ensuring automation and repeatability of secure deployments.
- Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.
- Lead cross-team initiatives that significantly improve our security posture while balancing speed and innovation.
- Mentor engineers on security best practices and build a culture of security by design.
- Actively participate in incident response, on-call rotations, and post-incident reviews to continuously improve defenses.
- Leverage AI to augment threat hunting, vulnerability scanning, and triage, using it to surface signal faster and reduce manual review load.
- Design and build AI agents to perform in-depth testing and analysis of our infrastructure and code.
What We Look For
- Improve and run Figure's vulnerability management program including triage, prioritization, tracking remediation, and reporting on risk reduction over time.
- Collaborate with DevOps to integrate security gates at various points throughout the software development lifecycle, ensuring automation and repeatability of secure deployments.
- Manage third-party penetration tests, including scoping, vendor coordination, and tracking remediation of findings.
- Automate sources of toil, such as routine patching or dependency upgrades.
- Conduct threat modeling and security reviews for new features and services, partnering with engineering teams early in the design process.
- Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.
- Lead cross-team initiatives that significantly improve our security posture
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply