Senior Application Security Engineer
Job description
Senior Application Security Engineer at Clear Capital.
About the role
The Senior Application Security Engineer at Clear Capital is entrusted with the critical mission of safeguarding the integrity of all software services that power the business. This role requires a comprehensive, end-to-end perspective on security, analyzing applications in direct connection with their supporting middle-tier architectures and data storage systems. The engineer owns the resolution of both historical vulnerabilities and future design risks, establishing repeatable frameworks that prevent exploitable flaws from ever taking root. Acting as the primary security communicator, the position requires translating complex technical risk into clear language for both engineering teams and executive stakeholders to ensure remediation protects business continuity. A core function involves proactively hunting for weaknesses across current products and future roadmaps, resolving issues before they can be discovered and leveraged by malicious actors. The role demands a security mindset that thinks like a potential attacker while operating with the highest level of professional integrity and discretion. Privilege is never abused, and all findings are handled with extreme responsibility and care.
Key Responsibilities
The Senior Application Security Engineer is responsible for designing robust intake procedures that identify dangerous patterns in external offerings and internal tooling before they reach production. This involves crafting build-level checks that ensure authentication defects and logic flaws are never introduced into customer-facing environments. The engineer conducts in-depth review assessments that highlight business logic risks across complex API endpoints and intricate user journey flows. The role requires coordination of ship validations to confirm that all mitigations function correctly and effectively before features are released to customers or partners. This includes forging partner testing routines to verify that vendor integrations adhere to strict isolation and data handling rules mandated by the security posture. Additionally, the engineer establishes monitoring signals designed to detect abnormal activity across critical transaction pathways and sensitive data stores. To elevate the security posture of the entire organization, the engineer creates training templates that teach engineering squads how to avoid common architectural mistakes and insecure design patterns. A final key duty involves championing verification routines that confirm remediation efforts do not inadvertently introduce new attack surfaces or regressions.
Requirements
The candidate must possess a minimum of three years of hands-on experience protecting web applications in a production environment, demonstrating a consistent track record of identifying and mitigating real-world threats. A deep skill set regarding authentication mechanisms is required, including a thorough understanding of how broken access control leads to unauthorized data exposure and privilege escalation. The engineer must have a firm grasp of how SQL injection and similar injection methods violate system boundaries, compromise data integrity, and undermine application trust. Comprehensive knowledge of common API weaknesses, such as excessive data exposure and lack of resources rate limiting, and methods to reduce the threat impact on business flows is essential. Experience spotting logic issues that allow users to bypass intended restrictions, such as authorization flaws or workflow bypasses, is a mandatory competency that must be honed over time. The candidate must handle common web protocols with confidence and understand how browsers enforce same origin policies to prevent cross-site attacks. Mastery of modern authentication standards used in external partnerships, including token-based flows and secure session management, is required for success in this role. Finally, the ability to communicate technical risk to non-technical stakeholders in a clear, calm, and actionable manner is non-negotiable, as decisions often depend on the clarity of the security narrative.
Nice to Have
Prior experience with cloud provider services and container deployment methods is highly valued, as these technologies form a significant part of the modern attack surface.
Practical Notes
All candidates are advised to What you'll do
- Engage with business logic reviews and API testing methodologies as they arise during the development lifecycle.
- Participate in the design of intake procedures that identify dangerous patterns in external offerings and internal tooling.
- Execute build-level checks focused on authentication defects and logic flaws to protect production environments.
- Conduct in-depth review assessments that highlight business logic risks across API endpoints and complex user journeys.
- Coordinate ship validations to confirm that all mitigations function correctly before features are released to customers.
- Forge partner testing routines to verify that vendor integrations adhere to strict isolation and data handling rules.
- Establish monitoring signals designed to detect abnormal activity across critical transaction pathways.
- Create training templates that teach engineering squads how to avoid common architectural mistakes.
- Champion verification routines that confirm remediation efforts do not inadvertently introduce new attack surfaces.
- Maintain a deep skill set regarding authentication mechanisms, understanding how broken access control leads to data exposure.
- Apply comprehensive knowledge of SQL injection and similar injection methods to prevent violations of system boundaries.
- Utilize knowledge of common API weaknesses to reduce the threat impact on business flows.
- Recognize logic issues that allow users to bypass intended restrictions and enforce intended access controls.
- Handle common web protocols with confidence, understanding how browsers enforce same origin policies.
- Demonstrate mastery of modern authentication standards used in external partnerships.
- Communicate technical risk to non-technical stakeholders effectively to drive security initiatives.
- Leverage experience with cloud provider services and container deployment methods to secure modern infrastructure.
- Act as the central security communicator, ensuring that risk is articulated clearly to technical and executive audiences.
- Proactively hunt for weaknesses in current products and future roadmaps to resolve issues before exploitation.
Skills and Tools
- Application Security
- SQL
- API
- Authentication
- Cloud Providers
- Containers
The role requires a holistic view of security, analyzing applications in direct connection with their supporting services and dependencies. The engineer must think like an attacker to identify vulnerabilities but operate with the highest level of integrity. All findings are handled responsibly, and privilege is never abused. This position is dedicated to building secure-by-design principles into the fabric of the organization. The successful candidate will be a strong collaborator, working closely with development teams to embed security into the software development lifecycle. The position demands resilience and attention to detail, as the stakes involve protecting critical business logic and sensitive transaction data. Clear communication is paramount, as the engineer will translate complex findings into actionable steps for engineers and leadership. This is a strategic role that impacts the long-term security posture of the company.