Lumin Digital
Sr. Application Security Engineer
Remote- United States · Senior
Sponsorship not specified$155k-$175kDetected 65 days ago
JavaScriptTypeScriptPythonJavaC#SwiftBashCode ReviewAWSCloud PlatformsKubernetesCI/CDOAuthLLMsCybersecurityPenetration TestingSIEMProject ManagementZero TrustResearchLeadershipCollaborationMentoring
About the role
- Travel: - Minimal, generally 12 days or less per year, ~2X team get-togethers a year.
- LIFE AT LUMIN DIGITAL Lumin Digital is a trailblazer in digital banking solutions, driven by a unique approach to technology, service, and people.
- These values shape a workplace where collaboration thrives, ideas flourish, and new possibilities are discovered every day.
Responsibilities
- Lead security architecture reviews for new and existing applications, ensuring secure-by-design principles are embedded from initial design through deployment and ongoing operation.
- Develop, enforce, and continuously refine secure coding standards across engineering teams through a combination of automated security scans (SAST, DAST, SCA), AI-assisted code review using tools such as Claude Code, periodic manual code audits, and targeted secure development training.
- Own the design, implementation, and evolution of Application Security Posture Management (ASPM) capabilities, integrating signals from static analysis, dynamic testing, software composition analysis, and runtime telemetry to build risk-scoring models that balance exploitability, data sensitivity, and business impact.
- Develop custom security automation tools and scripts to improve detection and response capabilities across cloud environments, including AI-assisted vulnerability auto-fix workflows and integration of AI-powered security tooling into CI/CD pipelines.
- Own and operate the company's bug bounty program end-to-end: define program strategy and scope, triage and validate external researcher submissions, assess severity, and maintain productive engagement with the security research community.
- Manage vulnerability triage and prioritization processes, ensuring vulnerabilities are assessed based on exploitability, business impact, and compliance requirements, and that remediation timelines align with organizational risk tolerance.
- Perform other duties as assigned.
- Extensive hands-on experience in secure software development, DevSecOps pipeline design, and security testing methodologies (SAST, DAST, SCA, penetration testing).
Requirements
- While performing the duties of this job, the employee is regularly required to sit
- Ability to occasionally lift/move up to 25 pounds.
- Strong programming proficiency with the ability to review and assess security risks in one or more of: Java, C#, JavaScript/TypeScript, Python, Swift, or Kotlin.
- While performing the duties of this job, the employee is regularly required to sit; use hands to type, handle, or feel and talk or hear.
Nice to have
- CSSLP, OSCP, GWEB, or GWAPT.
- Experience evaluating the security posture of AI providers (API security reviews, data residency assessments, vendor risk questionnaires, and contractual security requirements).
- Preferred certifications: CSSLP, OSCP, GWEB, or GWAPT.
Skills
- Demonstrated experience securing large-scale cloud-native applications, APIs, and microservices architectures.
- Knowledge, Skills, & Abilities:
- Deep expertise in AWS security, Kubernetes security, and cloud-native application security best practices.
Compensation
- Travel: - Minimal, generally 12 days or less per year, ~2X team get-togethers a year.
Benefits
- Include We take care of our people with medical, dental, and vision insurance, a 401(k) with company match, flexible PTO plus 12 paid holidays, paid sick leave, and paid parental and family leave.
- We also offer a lifestyle spending account, tuition reimbursement, and a cell phone stipend.
Company info
- define program strategy and scope, triage and validate external researcher submissions, assess severity, and maintain productive engagement with the security research community.
- Influence product roadmaps by identifying and advocating for security enhancements aligned with evolving regulatory requirements, industry best practices, and the emerging threat landscape for AI-integrated applications.
- Mentor security engineers and developers through hands-on guidance in secure coding, vulnerability remediation, and effective use of AI-augmented security workflows.
- Present security findings, risk assessments, and program metrics to senior leadership, clients, auditors, and regulators in a clear, actionable manner.
- At Lumin, we thrive on curiosity and innovation.
- Our culture is built on trust in our expertise and decisions, respect for diverse perspectives and talents, and boldness in pursuing new ideas.
Equal opportunity
- Individuals with a disability who are otherwise able to perform the essential functions of the job may request reasonable accommodation through the Human Resources department.
- equal opportunity employer.
- We consider all qualified applicants without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender identity, or any other legally protected basis.
Apply directly at Lumin Digital →Create a free account for alerts like thisView Lumin Digital immigration profile
This listing is sourced directly from Lumin Digital's careers page and normalized into a canonical job model.