SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Clear Street is a fintech platform providing sophisticated investors unified access to assets across markets through a modern, cloud-native capital markets infrastructure. The Security team is seeking an experienced Application Security Engineer to lead DevSecOps and application security initiatives across the product ecosystem.
You will own security controls within CI/CD pipelines, including SAST, DAST, SCA, and secrets detection tooling. Key responsibilities include working with engineering teams to identify and remediate vulnerabilities in source code, managing the full vulnerability lifecycle from triage through remediation tracking, and leading cloud security efforts to enforce best practices around IAM, network controls, storage, and workload protection.
You'll maintain and tune security scanning tools, build automation and AI-based solutions to scale DevSecOps operations, and partner with infrastructure teams to define and enforce secure infrastructure-as-code standards via policy-as-code frameworks. The role also involves participating in threat modeling and security design reviews, supporting incident response for application and cloud security events, and contributing to security documentation and developer guidance.
Required: 7+ years in DevSecOps, application security, or cloud security engineering. Hands-on experience with CI/CD platforms (GitHub Actions, GitLab CI, Jenkins), proficiency with AWS/Azure/GCP and native security services, experience with SAST/SCA tools (Semgrep, Snyk, Checkmarx, Veracode), and working knowledge of container and Kubernetes security. Strong scripting skills in Python or Bash, familiarity with IaC tools (Terraform, CloudFormation, Pulumi) and policy frameworks (OPA/Rego, Checkov) required.