Summary
What you’ll impact
The Staff Application Security Engineer at the organization will define and execute technical strategies to secure critical attack surfaces, including on-chain platforms, exchanges, and credit card integrations. Working autonomously, the engineer will collaborate with senior engineering leadership to embed security best practices throughout the development lifecycle and lead the design of AI-driven security tools.
Responsibilities
What you'll do
- Own and evolve the Gemini Secure Software Development Lifecycle (SDLC) guardrails as an application security subject matter expert
- Lead architecture reviews, threat modeling sessions, code reviews, and penetration tests for high-risk applications and services
- Design and develop AI agents integrated throughout the SDLC to automate threat modeling, secure code review, and reduce AppSec toil
- Create and deliver hands-on application security training programs to empower engineering teams at scale
- Participate in the Application Security on-call rotation, leading post-incident analysis and security hardening efforts
- Collaborate with cross-functional teams to embed security considerations into all phases of product development
- Continuously evaluate emerging security threats and develop strategies to mitigate potential risks
Requirements
What you’ll bring
- Proven experience in performing design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset
- Strong understanding of application security best practices and familiarity with common vulnerabilities such as SSRF, race conditions, privilege escalations, etc.
- Deep code review proficiency in languages like Scala, Java, Go, and hands-on experience with Python, Go, or similar for building security tools
- Experience implementing custom detection and prevention controls to address security issues beyond OWASP Top 10
- Familiarity with highly regulated environments such as financial services, fintech, or crypto, with the ability to understand business objectives and security risks
- Excellent cross-functional communication and collaboration skills spanning security, engineering, and product teams
- Typically 7-10+ years of experience or equivalent impact in application security or product security roles