Create New Account
Sign up to continue searching for suitable jobs in Web 3.0

OR
Terms of Use
Already have an account?

Log In to Your Account
Log in to continue searching for suitable jobs in Web 3.0

OR
Don’t have an account?
MoonPay
Senior Application Security Engineer
atĀ MoonPay
about 16 hours ago | 15 views | Be the first one to apply

Senior Application Security Engineer

Full-time
Remote

About the company

MoonPay is the world’s leading web3 infrastructure company. We provide end-to-end solutions for payments, enterprise-scale smart contract development, and digital asset management. Many of the world’s most iconic brands rely on MoonPay to power their web3 strategies and ideas.

Job Summary

About the role:

MoonPay's Product Security team is a dynamic blend of proactive defenders and inquisitive problem-solvers, dedicated to strengthening systems through rigorous security reviews and hands-on penetration testing. As a Product Security Engineer, you will embed security best practices throughout the SDLC, manage the Bug Bounty program, research emerging threats, and help spread a secure-by-design culture across the organisation.

Responsibilities:

šŸ“Conduct threat modelling reviews of Technical Design Documents (TDDs) for new and existing features, providing clear, actionable security recommendations early in the design process. šŸ“Perform and support application security assessments, including penetration testing, vulnerability assessments, and proof-of-concept (PoC) development where appropriate. šŸ“Investigate, triage, and respond to Bug Bounty program submissions, validating findings and working with engineering teams to drive timely remediation. šŸ“Own and continuously improve application-layer protections, including managing and tuning Cloudflare WAF and related security controls. šŸ“Partner closely with engineering teams to embed security best practices throughout the SDLC, from design and development through deployment and maintenance. šŸ“Research and track emerging threats and vulnerabilities, translating findings into practical mitigation strategies relevant to our technology stack. šŸ“Develop and deliver security guidance, training, and awareness for engineering teams to raise the overall security maturity of the organization. šŸ“Contribute to the creation, maintenance, and evolution of security standards, processes, and documentation. šŸ“Participate in and eventually lead incident response activities, supporting investigation, containment, remediation, and post-incident improvements.

Requirements:

šŸ“Breadth of experience across multiple security domains, including web and mobile application security, infrastructure and cloud security. šŸ“Hands-on experience performing white-box, source code-assisted web and mobile application penetration testing, from vulnerability discovery through triage and exploitation. šŸ“Ability to read, understand, and review source code to identify security issues, with a particular focus on JavaScript and TypeScript codebases. šŸ“Strong understanding of Threat Modelling principles and their practical application to the secure SDLC. šŸ“Experience working with web application firewalls to help protect applications, assess coverage, and support tuning rules to mitigate common attack patterns. šŸ“Experience embedding application security practices into CI/CD pipelines, enabling early detection of vulnerabilities and close collaboration with engineering teams. šŸ“Demonstrated ability to clearly communicate security findings, explain vulnerabilities, attack paths, and mitigations to both technical and non-technical audiences. šŸ“Self-motivated, proactive, and takes strong ownership of work, operating effectively in a remote environment while maintaining a collaborative, team-focused mindset.

Nice-to-have: šŸ“Experience in JavaScript and TypeScript, including the ability to read, understand, and reason about modern web application codebases. šŸ“Experience working with Cloudflare, including its hosting and Web Application Firewall (WAF) capabilities. šŸ“Experience testing and securing GraphQL and REST APIs, including understanding common attack vectors and security considerations. šŸ“Experience or a strong interest in Web3 security testing, including assessing smart contracts, blockchain-based applications, or Web3 integrations. šŸ“Interest in agentic engineering, including emerging patterns in autonomous systems, tooling, or workflows, and their security implications. šŸ“Contributions to the security community through open source involvement, CTFs, or speaking at information security meetups and conferences. šŸ“Background working with disruptive technologies within FinTech, SaaS, or Crypto. šŸ“One or more security relevant certifications such as OSCP or OSWE.

If this role isn't the perfect fit, there are plenty of exciting opportunities in blockchain technology, cryptocurrency startups, and remote crypto jobs to explore. Check them on our Jobs Board.

Similar jobs

about 16 hours ago | 17 views | Be the first one to apply
Full-time
United States
$95,000 To $125,000 per year
about 16 hours ago | 18 views | 1 applications
Full-time
France
about 16 hours ago | 23 views | 1 applications
Full-time
Onsite, Switzerland
1 day ago | 36 views | 1 applications
Full-time
Remote