Application Security Engineer
Job description
About the role
You will own the design and implementation of automated security testing to validate secure coding best practices across the application landscape at BitGo. You will own the creation and delivery of secure development training programs that raise the security awareness and capability of engineering teams. You will participate actively in application security reviews and threat modeling exercises covering secure code review, architectural design, and dynamic testing activities. You will perform application security vulnerability management including triage, tracking, and remediation support. You will facilitate and support the preparation of secure software releases through security gate reviews and guidance. You will support and consult with engineering teams in the area of application security and best practices on a regular basis. You will drive security projects from initial ideation through requirements definition to successful implementation and adoption. You will mature the security program through the application of the NIST Cybersecurity Framework and related standards. You will assist in any relevant incident response activities related to application security findings.
Key facts
What you'll do
- Drive the development of automated security testing suites that validate the consistent application of secure coding best practices across all engineering projects.
- Design and deliver targeted secure development training sessions that equip software engineers with the knowledge to build and maintain secure applications.
- Conduct proactive application security reviews and threat modeling sessions, including deep dives into secure code review, architectural design decisions, and dynamic testing methodologies.
- Execute comprehensive application security vulnerability management processes, from initial identification and prioritization through to remediation verification and closure.
- Act as a central point of contact and facilitator for the bug bounty program, triaging incoming reports and coordinating with engineering teams for timely resolution.
- Guide and support the preparation of secure software releases, ensuring that security gates and checklists are properly executed before production deployment.
- Provide expert consultation and hands-on support to engineering teams on application security topics, helping them integrate best practices into their daily workflows.
- Lead security initiatives from initial concept and requirements gathering through detailed design, implementation, and continuous improvement cycles.
- Evolve the maturity of the application security program by leveraging the NIST Cybersecurity Framework to set baselines, measure performance, and identify improvement opportunities.
- Participate in relevant incident response activities, contributing technical expertise to contain, eradicate, and remediate application-layer security incidents.
- Collaborate closely with cross-functional partners to ensure that security considerations are embedded throughout the full software development lifecycle.
- Champion the use of automation over manual processes, focusing efforts on high-impact areas that reduce risk at scale.
- Maintain a quality-first mindset, emphasizing thorough analysis and clear documentation of security findings and recommendations.
- Operate during regular business hours in alignment with the local team, while being available for occasional evening meetings as needed.
Requirements
- Bring a minimum of 5 years of hands-on experience in the field of application security, demonstrating a proven track record of identifying and mitigating security risks.
- Show at least 1-2 years of practical experience in software development and mobile security, with a clear understanding of the development lifecycle.
- Demonstrate familiarity with common security libraries, security controls, and prevalent security flaws found in modern applications.
- Provide evidence of experience with industry standards such as OWASP, along with hands-on use of static and dynamic analysis tools and common security testing tools.
- Show a basic understanding of network and web related protocols, including but not limited to TCP/IP, UDP, IPSEC, HTTP, and HTTPS.
- Illustrate direct experience with the vulnerability management lifecycle, from identification and assessment through prioritization, remediation, and closure.
- Exhibit familiarity with cloud security controls and best practices relevant to modern distributed systems and infrastructure.
- Highlight experience collaborating directly with software developers, including code reviews, pair programming, and knowledge transfer sessions.
- Communicate with excellent written and verbal skills, and demonstrate the ability to articulate complex security concepts in a clear and concise manner to both technical and non-technical audiences.
- Preference will be given to candidates who possess knowledge of at least some of the programming languages actively used at BitGo, including TypeScript, Go, Python, Java, and Kotlin.
Nice to have
No additional preferred items are specified in the source beyond the requirements listed above.
Practical notes
The engagement is based in India and is aligned with regular business hours, with occasional evening meetings necessary to support global collaboration. The role involves working closely with engineering teams to integrate security practices into the development workflow, leveraging automation to improve security posture at scale.