Branch
Branch15d ago

Senior Application Security Engineer

United StatesUnited StatesRemotesenior
EngineeringSecuritySecurity EngineerApplication Security EngineerCybersecurity
0 views0 saves0 applied

Quick Summary

Key Responsibilities

Embed security into the SDLC by partnering with Engineering to implement secure design patterns, conduct threat modeling,

Requirements Summary

5–7 years of experience in a security engineering or application security role,

Technical Tools
EngineeringSecuritySecurity EngineerApplication Security EngineerCybersecurity

Branch is on a mission to empower workers with financial freedom. We do this by helping companies accelerate payments and providing working Americans with accessible, free financial services. We’re committed to building and delivering more inclusive, transparent, and frictionless financial products.

Our goal of empowerment extends to our own employees, too. Have a great idea? Share it today and it might just get implemented tomorrow. As a member of our team, your voice and creativity matter—and they can directly impact our products, company, and culture. 

We not only focus on attracting great talent from across the country, but also on building teams that help that talent thrive. That means valuing a diversity of opinions and working styles, while creating a shared belief in innovation, initiative, and winning together.

Come join our team as we develop new ways to improve the lives of working Americans.

About the Role

~1 min read

Branch is seeking an experienced Security professional to join our team.  This position will work in all aspects of security, so broad security knowledge is preferred.  The ideal candidate will have a background in securing applications, networks, cloud environments, and corporate devices.

Responsibilities

~1 min read
  • Embed security into the SDLC by partnering with Engineering to implement secure design patterns, conduct threat modeling, and deliver developer-focused AppSec training
  • Lead and perform application security assessments including SAST, DAST, SCA, and manual code review across web, mobile, and API surfaces
  • Drive API security across internal and external services — including authentication, authorization, rate limiting, and abuse prevention controls
  • Own and mature the vulnerability management program, including prioritization frameworks, SLA tracking, and cross-functional remediation coordination
  • Champion software supply chain security initiatives, including SBOM generation, dependency risk analysis, and third-party component vetting
  • Assist GRC with technical third-party risk reviews and vendor security assessments
  • Respond to and lead security incidents in a measured, programmatic, and timely manner — from identification through post-incident review
  • Implement and iterate on security automation and orchestration to improve detection, response, and coverage at scale
  • Implement, monitor, and continuously improve security controls across cloud infrastructure, endpoints, and the product
  • Assess and mitigate AI-specific security risks across Branch's use of LLMs and AI-powered features, including prompt injection, model abuse, and insecure output handling

Requirements

~1 min read
  • 5–7 years of experience in a security engineering or application security role, ideally within a fintech or high-growth startup environment
  • Strong communication skills — able to translate technical risk clearly for both engineering audiences and senior leadership
  • Hands-on SAST/DAST experience; familiarity with tools such as Semgrep, Snyk, Checkmarx, Burp Suite Pro, or equivalents
  • Demonstrated ability to independently work security incidents end-to-end — including malware, phishing, DLP events, and API abuse
  • Experience securing cloud-native environments, including IAM, container/Kubernetes workloads, and serverless functions
  • Solid working knowledge of API security standards (OWASP API Top 10, OAuth 2.0/OIDC, JWT hardening)
  • Experience with mobile application security testing (iOS/Android) is a plus
  • Familiarity with security frameworks including SOC 2, PCI-DSS, NIST CSF, and OWASP SAMM
  • Scripting proficiency in Python and/or Bash for automation and tooling; experience with security orchestration platforms (e.g., Tines, XSOAR, Torq) is a plus
  • Strong ethics and discretion — this role regularly handles confidential and sensitive information
  • Familiarity with AI/LLM security risks and emerging standards (OWASP LLM Top 10, MITRE ATLAS) — including prompt injection, data leakage through model outputs, and supply chain risks introduced by third-party AI services
  • Security certifications a plus (OSCP, GWEB, CISSP, SANS GWAPT, etc.)

What We Offer

~1 min read

The base salary range for this role is $180-190k. The salary range displayed reflects an average base salary range for the position across all the U.S. The base salary offered to an applicant could be higher or lower based on each applicant's specific skill set, depth of experience, relevant education or training, etc. 

This position is classified as REMOTE within the United States of America.

We are unable to hire candidates located outside of the domestic U.S.

What We Offer

~1 min read
Market-leading medical, dental, and vision insurance
Stock options
Free Premium-Tier Origin Financial Wellness subscription
Monthly home-office stipend
401k (TransAmerica)
12-weeks paid parental leave for birthing and non-birthing parents
Flexible time off + sick and safe time
11 paid company holidays

A remote-first company with employees located throughout the U.S., Branch emphasizes transparency, accountability, and trust to create a collaborative environment where our product, engineering, marketing, customer support, customer success, and sales teams can all thrive together.  Learn more about what we do in this video!

Our collaborative spirit has helped us become an award-winning FinTech company, with Branch’s innovation and workplace recognized across industries. Branch has been honored by Inc., the Webby Awards, Benzinga FinTech Awards, FinTech Breakthrough Awards, Top Workplaces USA, Great Places to Work, and EY Entrepreneur of the Year, Heartland, among others.  

Learn more about our culture, approach, technology, and people here: https://www.branchapp.com/about

 

Branch is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Must be currently authorized to work in the USA without sponsorship or transfer.

No third-parties, please.

View how Branch collects your personal data here.

Location & Eligibility

Where is the job
United States
Remote within one country
Who can apply
US
Listed under
United States

Listing Details

Posted
April 15, 2026
First seen
April 15, 2026
Last seen
April 30, 2026

Posting Health

Days active
15
Repost count
0
Trust Level
37%
Scored at
April 30, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Branch
Branch
greenhouse

Branch makes instant payments possible for any workforce.

Employees
125
Founded
2015
View company profile
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

BranchSenior Application Security Engineer