Find your dream job faster with JobLogr
AI-powered job search, resume help, and more.
Try for Free
OnePay

OnePay

via Ashby

Apply Now
All our jobs are verified from trusted employers and sources. We connect to legitimate platforms only.

Application Security Engineer

Anywhere
full-time
Posted 8/11/2025
Direct Apply
Key Skills:
Application Security Engineering
DevSecOps
Security Platform Engineering
AWS
IAM
KMS
VPC
EC2
RDS
EKS
Docker
Kubernetes
Threat Modeling
Secure Code Review
Scripting Automation
Communication

Compensation

Salary Range

$Not specified

Responsibilities

The Application Security Engineer will safeguard the platform by designing secure AWS architectures and embedding automated threat detection. They will ensure compliance with standards like PCI, CCPA, and GLBA while maintaining trust and reliability for users.

Requirements

Candidates should have 8-12 years of experience in application security engineering and be familiar with frameworks like CVSS and OWASP Top 10. Proven experience with AWS services and securing CI/CD pipelines is essential.

Full Description

About OnePay OnePay is a consumer financial services app with an exceedingly simple mission: to help people achieve financial progress. Tens of millions of Americans today are unbanked or underbanked, meaning they don’t have enough money in savings to cover a minor emergency. They pay too much in fees, don’t have access to credit at affordable rates, and have little ability to grow their wealth. OnePay’s vision is to create a single app for consumers to save, spend, borrow, and grow their money, bringing our mission to life with simple and accessible banking, credit, and payments products that deliver a best-in-class experience to millions of customers. Our products include: Checking and high-yield savings accounts Domestic and international peer-to-peer payments Credit Builder and credit score monitoring Digital wallet / contactless payment solutions Buy-now-pay-later installment loans at Walmart Why do we have a right to win? We have the backing of Walmart (a Fortune 1) and Ribbit Capital (a preeminent fintech investor), are deeply embedded with the distribution of the world’s largest omnichannel retailer, and have an industry-leading multi-product value proposition — all in addition to having some of the best people and talent in the industry. There’s never been a better time to build a category-defining business and there has rarely been a team better positioned for the opportunity. Join us! Our Application Security Engineers play a pivotal role in safeguarding our platform, driving everything from designing secure AWS architectures to embedding automated threat detection that protects customer transactions. Your work will ensure we meet rigorous compliance standards (PCI, CCPA, GLBA) and maintain the highest levels of trust and reliability for our users. Architect and implement secure AWS configurations (IAM roles/policies, encryption keys, VPC segmentation) Embed security into CI/CD pipelines and repos using policy-as-code tools (pre-commit hooks, SAST/SCA, IDE tool integrations) Secure container and orchestration environments (EKS, Kubernetes, Docker) per best practices Conduct threat modeling sessions and risk‑driven design reviews early in development Perform secure code reviews and static/dynamic analysis; oversee remediation with dev teams Automate repetitive security tasks—vulnerability triage, code scanning, tool orchestration Build and extend in-house AppSec automation frameworks or pentest tooling Partner with security architecture and detection teams (SIEM tuning, logging, telemetry alignment) Develop and enforce AppSec standards and patterns across product teams; iterate through feedback loops Support regulatory or compliance assessments (PCI, CCPA, GLBA) as needed You Bring: 8–12 years’ experience in application security engineering, DevSecOps, or security platform engineering Deep familiarity with CVSS, MITRE ATT&CK frameworks, OWASP Top 10 and CWE taxonomy Proven experience with AWS core services: IAM, KMS, VPC, EC2, RDS, EKS Hands-on expertise in securing IaC and CI/CD pipelines; strong knowledge of policy-as-code tooling Container security experience: Docker, Kubernetes, EKS-related threat surfaces Solid threat modeling and secure code review skills; SAST/SCA tool proficiency Experience scripting automation (e.g. Python, Bash, PowerShell) to streamline AppSec tasks Capability to lead in-house AppSec frameworks or tooling development Strong communicator, able to translate technical findings to non-technical stakeholders Track record of defining and institutionalizing security architecture patterns Standard Interview Process Initial Interview with Talent Partner Technical or Hiring Manager Interview Team Interview Executive Interview Offer! Equal Employment Opportunity To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.

This job posting was last updated on 8/12/2025

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt