SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
fomo is a high-growth crypto/Web3 trading platform that has onboarded 2.5M+ users and processed $14B+ in trading volume since launching in May 2025. The company has raised ~$100M from top-tier investors including Benchmark, Index Ventures, and Union Square Ventures, and has generated ~$68M in revenue.
You will be fomo's first dedicated application security hire, owning and building the company's AppSec program from the ground up. This is a hands-on, high-leverage role focused entirely on product and application security—not corporate IT or endpoint management. You'll be embedded directly in how the product is designed, built, and shipped, working with engineering and product teams to embed security at the architecture and code level.
Key responsibilities include:
- Lead security architecture reviews and threat modeling for new features and major system changes, partnering with engineering and product from design through launch
- Own the secure SDLC program: SAST/DAST, dependency and software composition analysis, secrets scanning, and CI/CD security gates
- Perform deep-dive code reviews and manual penetration testing of high-risk services, APIs, and web applications
- Design and build internal security tooling and guardrails that enable engineers to move fast without introducing risk
- Run and mature the vulnerability management program, including triage, severity scoring, and driving remediation
- Manage relationships with external pentest vendors and bug bounty programs, turning findings into durable fixes
- Set technical direction on authentication, authorization, API security, and data protection patterns
- Mentor engineers on secure coding practices and serve as a go-to security resource across the organization
- Contribute to incident response for application-layer issues
- Help define and evolve fomo's AppSec roadmap and metrics
Requirements:
- 7+ years in security engineering with substantial, recent focus on application security (not primarily corporate/IT security)
- Deep hands-on experience with secure code review, threat modeling, and common vulnerability classes (OWASP Top 10, auth/session flaws, SSRF, injection, business logic flaws, etc.)
- Strong software engineering background; comfortable reading and writing production code, not just running scanners
- Experience building and scaling AppSec tooling and processes (SAST/DAST, SCA, CI/CD security integration) at a growing company
- Track record of driving security into engineering culture through influence, not gatekeeping
- Familiarity with cloud-native environments (AWS/GCP/Azure), container security, and modern API architectures
- Excellent communication skills; able to explain risk to both engineers and non-technical stakeholders
- Prior experience as a technical lead or staff-level IC who can operate with high autonomy
Nice to have:
- Experience with bug bounty program management
- Background in a high-growth consumer or marketplace product