Skip to content

Open nowPosted 30 hours ago

Application Security Engineer (X Money)

xAI297 open roles

Where
Palo Alto, CA; Austin, TX; New York, NY; Washington, DC
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowApplication Security Engineer (X Money)xAI · Palo Alto, CA; Austin, TX; New York, NY; Washington, DC
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on xAI's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. xAI postings stay open a median of 32 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 30 hours ago

xAI median: 32 days open

The posting

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE:

We are seeking a skilled and innovative Application Security Engineer to join 𝕏 Money. In this role, you will protect the security and integrity of our payments and financial products throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and systems that move and hold customer funds. Experience securing fintech, payments, digital wallet, ledger, or similar high-value platforms, where fraud, abuse, and unauthorized transfers are a constant concern, is strongly preferred.

RESPONSIBILITIES:

  • Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in financial applications
  • Design and implement secure coding guidelines and best practices for development teams
  • Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline
  • Perform threat modeling and risk assessments for payments, wallets, ledgers, and related product surfaces, and develop mitigation strategies for fraud, abuse, and unauthorized movement of funds or credits
  • Manage vulnerability tracking and remediation efforts, providing guidance to development teams
  • Manage the bug bounty program, including intake, triage, researcher communication, and coordinated disclosure
  • Support incident response activities related to application security
  • Stay current on emerging threats against financial and cloud-native systems, and continuously strengthen our controls
  • Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs)
  • Design and implement agentic and LLM-based solutions that help detect, investigate, or prevent security problems

BASIC QUALIFICATIONS:

  • Bachelor's degree in Computer Science, Cybersecurity, or a related field
  • 3-5 years of experience in application security, with a strong focus on code security practices
  • Experience in payments, money transmission, digital wallets, or related financial platforms
  • Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10)
  • Proficiency in Python or Rust and experience with secure coding practices in these languages
  • Experience securing CI/CD pipelines and implementing DevSecOps practices
  • Familiarity with software supply chain security and SBOM generation tools
  • Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis
  • Experience securing payments, wallets, ledgers, or other high-value transaction systems, including controls against fraud, abuse, and integrity issues
  • Experience designing and implementing agentic and LLM-based solutions for security problems
  • Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences

PREFERRED SKILLS AND EXPERIENCE:

  • Hands-on experience securing applications on AWS; familiarity with other cloud platforms is a plus
  • Relevant security certifications (e.g., BSCP, OSCP, OSWE)
  • Experience managing bug bounty programs
  • Background in data privacy and compliance relevant to financial products and cloud-native applications
  • Experience with GitOps and infrastructure-as-code security
  • Experience building custom security tooling to enhance and automate security processes
  • Contributions to open-source security projects or tools

COMPENSATION AND BENEFITS:

$100,000 - $258,000 USD

Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

ITAR REQUIREMENTS:

  • To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.

SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against xAI's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on xAI's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    xAI's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.