SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Altruist is transforming the wealth management industry with an AI platform for financial advisors. The company partners with advisors nationwide to help them grow, optimize resources, and deliver superior outcomes for clients.
As a Senior Application Security Engineer on the Blue Team, you will be a key member of the growing Security team, ensuring products are secure from design through the CI/CD pipeline. This is a hybrid role requiring three days per week onsite in San Francisco or Culver City.
Your responsibilities include:
- Educate and train development teams on secure coding practices and emerging security threats
- Perform technical security assessments and code reviews across Java/Spring services
- Engage in threat modeling to anticipate and mitigate potential security threats
- Assist teams in building libraries, repeatable patterns, and paved-road components that embed security into every new feature
- Own and tune SAST, DAST, software composition analysis (SCA), and security tooling in CI/CD pipelines; triage findings and drive remediation with clear prioritization
- Partner with engineering to close service-to-service authentication/authorization gaps and other systemic issues
- Work with Detection & Response and offensive security engineers to turn findings into durable detections and prevention
- Contribute to secure SDLC standards and developer security guardrails
You bring 4+ years of experience as an Application/Product Security Engineer with extensive hands-on expertise in security assessments, security design reviews, threat modeling, and secure code review (Java/Spring or similar). You have demonstrated experience operating SAST/DAST/SCA and secrets-scanning tooling in CI/CD pipelines, and the ability to work independently. A B.A./B.S. in Computer Science, Computer Engineering, Information Security, or equivalent experience is required. You are technologically savvy, able to quickly master modern tech stacks (Java, Spring, Terraform, Kubernetes), and possess superb communication skills. Bonus experience includes work in regulated fintech/financial services environments and building AppSec automation.