SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Application Security Engineer

Chime - San Francisco, CA, United States - Hybrid - posted 2026-10-02

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 213,000 - 295,000 / annual

Chime, a fintech company, is seeking a Senior Application Security Engineer to join the Product Security team. This is a hands-on, impact-driven role focused on mobile application security across iOS, Android, APIs, and backend systems. You will work directly with mobile, backend, and platform engineering teams to identify, prevent, and remediate security issues. Operating close to the code and product, you will review architectures across the stack, influence secure design decisions early, and help teams ship features safely without slowing delivery. The role requires understanding how modern distributed systems and mobile apps are built, deployed, and attacked in real-world environments. Key responsibilities include: - Building and improving security capabilities, automation, and guardrails for mobile applications and backend/API services - Performing application and API/backend penetration testing - Identifying, triaging, and helping remediate vulnerabilities across Chime products - Partnering closely with engineering and product teams to embed security into the development lifecycle - Performing architecture and code reviews across the stack (iOS/Android, APIs, backend) with focus on secure data storage, authentication, authorization, secure communication, and session/token handling - Leveraging AI to accelerate security workflows (code review support, triage, threat modeling) and partnering with teams building AI-enabled features to define and implement production-grade AI security controls While mobile application security is the core focus, you will be part of a team that owns security posture across the full application stack including APIs, backend services, identity and authentication flows, and CI/CD pipelines. Chime is a financial technology company (not a bank) that empowers members to take control of their finances through user-friendly tools and intuitive platforms. The company operates with an entrepreneurial culture, emphasizing problem-solving, execution, and an owner's mindset. REQUIREMENTS: - 5+ years of experience in application security, with strong hands-on experience across both mobile and backend systems - Hands-on experience securing iOS and Android applications in production environments - Strong understanding of mobile threat models and common attack techniques - Experience with mobile security testing techniques, including static and dynamic analysis - Familiarity with iOS and Android platform security features and limitations - Practical coding experience, preferably in Ruby, Go, or Python - Ability to clearly communicate security risks, tradeoffs, and remediation guidance to engineering partners

Similar roles