SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 100,000 - 258,000 / annual
xAI (X Money division) is seeking an Application Security Engineer to protect the security and integrity of payments and financial products throughout the software development lifecycle. You will focus on code security, CI/CD pipeline hardening, and systems that move and hold customer funds, with particular emphasis on preventing fraud, abuse, and unauthorized transfers.
Key responsibilities include conducting in-depth code reviews and static analysis to identify security vulnerabilities in financial applications; designing and implementing secure coding guidelines and best practices for development teams; collaborating with engineers to integrate security throughout CI/CD pipelines; performing threat modeling and risk assessments for payments, wallets, ledgers, and related surfaces; managing vulnerability tracking and remediation; overseeing the bug bounty program including intake, triage, researcher communication, and coordinated disclosure; supporting incident response activities; staying current on emerging threats to financial and cloud-native systems; evaluating and securing software supply chains including SBOM production and maintenance; and designing agentic and LLM-based solutions to detect, investigate, or prevent security problems.
The company operates with a flat organizational structure, emphasizing hands-on contribution, engineering excellence, strong work ethic, and excellent communication skills. You will work in a small, highly motivated team focused on building AI systems that understand the universe and aid humanity's pursuit of knowledge.
REQUIREMENTS:
- Bachelor's degree in Computer Science, Cybersecurity, or related field
- 3–5 years of application security experience with strong focus on code security practices
- Experience in payments, money transmission, digital wallets, or related financial platforms
- Deep understanding of secure coding practices, application security frameworks, and OWASP Top 10
- Proficiency in Python or Rust with secure coding practice experience
- Experience securing CI/CD pipelines and implementing DevSecOps practices
- Familiarity with software supply chain security and SBOM generation tools
- Experience with security testing tools (Burp Suite, OWASP ZAP) and static/dynamic code analysis
- Experience securing payments, wallets, ledgers, or high-value transaction systems including fraud and abuse controls
- Experience designing and implementing agentic and LLM-based solutions for security problems
- Excellent communication skills explaining complex security issues to technical and non-technical audiences
PREFERRED:
- Hands-on AWS application security experience; familiarity with other cloud platforms
- Security certifications (BSCP, OSCP, OSWE)
- Bug bounty program management experience
- Data privacy and compliance background relevant to financial products and cloud-native applications
- GitOps and infrastructure-as-code security experience
- Custom security tooling development
- Open-source security project contributions
Note: ITAR compliance required—applicant must be U.S. citizen, national, lawful permanent resident, Refugee, or Asylee, or eligible to obtain required authorizations from U.S. Department of State.