SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Application Security Engineer (Red Team)

Altruist - San Francisco, CA, USA - Hybrid - posted 2026-09-09

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Altruist is transforming the wealth management industry with an AI platform for financial advisors. The company is seeking a Senior Application Security Engineer to join its growing Security team and lead offensive security efforts. In this role, you will conduct comprehensive penetration testing across Altruist's web applications, APIs, infrastructure, and mobile applications (Android and iOS). Your primary responsibilities include continuously attacking security controls to identify weaknesses before adversaries do, performing focused authorization and exploitability assessments on high-risk attack paths, and conducting cloud pentests and identity-focused offensive testing. You will collaborate with the Detection & Response team to run purple-team exercises, helping build detections based on your offensive tradecraft. You'll develop and maintain offensive tooling and repeatable testing playbooks, contribute to phishing and social-engineering assessments, and document all findings with reproducible proofs-of-concept, clear risk ratings, and actionable remediation guidance. The ideal candidate brings 4+ years of experience as an Application or Product Security Engineer, with extensive pentesting experience across web, API, and mobile targets. You should be proficient with tools like Burp Suite and possess strong technical aptitude for modern tech stacks (Java, Spring, Terraform, Kubernetes). A B.A./B.S. in Computer Science, Computer Engineering, Information Security, or equivalent experience is required. Bonus qualifications include experience in regulated fintech/financial services environments, mobile application pentesting (OWASP MASVS), cloud/red-team and adversary emulation experience, and relevant certifications such as OSCP, OSWE, or GXPN. This is a hybrid role requiring three days per week onsite in either the San Francisco FiDi or Culver City office.

Similar roles