OnePay Logo

OnePay

AppSec Engineer

Posted 9 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
170K-210K Annually
Senior level
Remote
Hiring Remotely in United States
170K-210K Annually
Senior level
Design and enforce application security across AWS and Kubernetes environments: perform secure code reviews, threat modeling, automate AppSec workflows, embed security into CI/CD and IaC, build tooling, support compliance (PCI/CCPA/GLBA), and partner with product and detection teams to operationalize AppSec standards.
The summary above was generated by AI
About OnePay

OnePay is the consumer fintech trusted by millions of Americans to make money better.

Our financial system is broken. High fees, low rates, and too few ways to actually grow your money. We’re fixing it. And we’re moving fast.

We’re an all-in-one financial services platform that brings together banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto in one place. We also partner with employers, HCM providers, gig platforms, and others to deliver embedded financial services to millions of employees and frontline workers.

We’re backed by Walmart, the world’s largest retailer, and Ribbit Capital, one of fintech’s most respected investors, giving us rare scale, distribution, and the opportunity to build something truly category-defining.

But what really sets OnePay apart is how we move. Our customers don’t have time to wait… and neither do we. This place moves fast, and we’re looking for people who are:

  • Ready to run

  • Hungry and driven by urgency

  • Exceptional at what they do, with low ego

  • Comfortable operating in motion

The Role

Our Application Security Engineers play a pivotal role in safeguarding our platform, driving everything from designing secure AWS architectures to embedding automated threat detection that protects customer transactions. Your work will ensure we meet rigorous compliance standards (PCI, CCPA, GLBA) and maintain the highest levels of trust and reliability for our users.

  • Perform secure code reviews and static/dynamic analysis; oversee remediation with dev teams

  • Conduct threat modeling sessions and risk‑driven design reviews early in development

  • Automate repetitive security tasks—vulnerability triage, code scanning, tool orchestration

  • Build and extend in-house AppSec automation frameworks or pentest tooling

  • Architect and implement secure AWS configurations (IAM roles/policies, encryption keys, VPC segmentation)

  • Embed security into CI/CD pipelines and repos using policy-as-code tools (pre-commit hooks, SAST/SCA, IDE tool integrations)

  • Secure container and orchestration environments (EKS, Kubernetes, Docker) per best practices

  • Partner with security architecture and detection teams (SIEM tuning, logging, telemetry alignment)

  • Develop and enforce AppSec standards and patterns across product teams; iterate through feedback loops

  • Support regulatory or compliance assessments (PCI, CCPA, GLBA) as needed

You Bring
  • 8–12 years’ experience in application security engineering, DevSecOps, or security platform engineering

  • Solid threat modeling and secure code review skills; SAST/SCA tool proficiency

  • Experience scripting automation (e.g. Python, Bash, PowerShell) to streamline AppSec tasks

  • Capability to lead in-house AppSec frameworks or tooling development

    Deep familiarity with CVSS, MITRE ATT&CK frameworks, OWASP Top 10 and CWE taxonomy

  • Proven experience with AWS core services: IAM, KMS, VPC, EC2, RDS, EKS

  • Hands-on expertise in securing IaC and CI/CD pipelines; strong knowledge of policy-as-code tooling

  • Container security experience: Docker, Kubernetes, EKS-related threat surfaces

  • Strong communicator, able to translate technical findings to non-technical stakeholders

  • Track record of defining and institutionalizing security architecture patterns

Tools We Use

We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. While you don’t need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly.

What We Offer
  • Competitive base salary, stock options, and health benefits from Day 1

  • 401(k) plan with company match

  • Remote-friendly (US), flexible time off (FTO), and opportunities for growth

  • A high-growth, mission-driven, inclusive culture where your work has real impact

Standard Interview Process
  • Initial Interview with Talent Partner

  • Technical or Hiring Manager Interview

  • Team Interview

  • Executive Interview

  • Offer!

Equal Employment Opportunity

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at [email protected].

Top Skills

Python,Bash,Powershell,Node,Typescript,Nestjs,React Native,Aws,Iam,Kms,Vpc,Ec2,Rds,Eks,Kubernetes,Docker,Sast,Sca,Dast,Iac,Ci/Cd,Policy-As-Code,Pre-Commit,Siem,Mitre Att&Ck,Owasp Top 10,Cwe,Cvss

Similar Jobs

An Hour Ago
Remote or Hybrid
United States
93K-135K Annually
Junior
93K-135K Annually
Junior
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
The Product Owner drives feature development for Disability Solutions, collaborating with teams to prioritize user stories and manage stakeholder relations, ensuring alignment with business goals.
Top Skills: Ai ToolsAPIsData Management
An Hour Ago
Remote or Hybrid
United States
85K-136K Annually
Senior level
85K-136K Annually
Senior level
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
The Senior Product Consultant II will drive Disability & Leave strategies at MetLife, collaborating with teams to enhance messaging and position MetLife as a market leader. The role requires a deep understanding of processes, creating communication materials, and leading market storytelling.
An Hour Ago
Remote or Hybrid
United States
90K-130K Annually
Mid level
90K-130K Annually
Mid level
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
The Lead Communications Consultant develops high-impact communications for Sales, Service & Operations, aligning messaging and enhancing employee engagement.
Top Skills: Ai-Enabled ToolsGraphic Design ToolsMicrosoft CopilotMS OfficeVideo Editing Tools

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account