Application Security Engineer
United States - Remote
Full Time Senior-level / Expert USD 150K - 175K
The Motley Fool
The Motley Fool has been providing investing insights and personal finance to millions of people for over 25 years. Learn how we make the world Smarter, Happier & Richer.Who are we?Â
The Motley Fool is a purpose-driven financial services company on a mission to make the world smarter, happier, and richer. For 30 years weâve been helping people make better investment decisions through transparency, education, and Foolish fun. Weâre a fast-moving, collaborative team that values high-quality work, curiosity, and initiative. We care deeply about what we do, and weâre driven by the impact our work has on real peopleâs financial futures.
Â
About the Role:
Weâre seeking a mid to senior-level Application Security Engineer with strong technical instincts, a bias for action, and the ability to own complex projects end-to-end. Youâll be part of a high-impact team responsible for identifying, validating, and remediating security risks across a multi-language environment (Python, C#, PHP). This is not a checkbox roleâsuccess here means taking initiative, verifying deeply, and driving security outcomes without waiting to be told.
A growing focus of this role will be securing AI and LLM-based applications. This is an emerging and rapidly evolving area of security, and weâre looking for someone excited to help define best practices, assess novel risks, and build safeguards into how we use generative AI. You donât need to be an expert yetâbut curiosity, initiative, and a willingness to learn fast are essential.
Â
Key Responsibilities:
Project Ownership
- Own and deliver application security initiatives end-to-end.
- Define clear quarterly SMART goals and drive toward their completion.
- Engage stakeholders proactively and escalate blockers before they become issues.
- Take full responsibility for the delivery of project ownership.
Technical Depth
- Validate findings through hands-on testing; never assume without verification.
- Produce detailed, technically accurate risk assessments and remediation advice.
- Investigate deeply using tools like Semgrep, Feroot, Source Defense, and Noname.
- Understand the context of the applications youâre securingâbusiness logic, threat model, and operational constraints.
- Stay current on insecure practices (e.g. eval, shell injection, unsafe deserialization) and ensure theyâre recognized and flagged appropriately.
Active Participation and Autonomy
- Speak up early when you see risk, blockers, or better ways to solve problems.
- Share context, findings, and decisions proactively in meetings and documentation.
- Follow through on action items; own gaps and next steps.
- Operate with transparencyâacknowledge unknowns and follow up with answers.
Â
Qualifications:
3â7 years in Application Security, Penetration Testing, or Secure Software Development.
- Strong background in Python or other backend languages (C#, PHP).
- Experience with security testing methodologies and tools, including SAST, DAST, IAST, RASP, SCA, API Security tools (e.g., Noname, Traceable, Levo), Client-side Security tools (e.g., Feroot, Source Defense), and CNAPP.
- Working familiarity with cloud-based technologies, particularly AWS (e.g., IAM, VPCs, S3, Lambda, CloudFront, Security Groups).
- Deep understanding of OWASP Top 10, CWE Top 25, and secure SDLC principles.
- Comfortable working directly with developers and cross-functional stakeholders.
We also welcome candidates with non-traditional security backgrounds. If you come from software development, infrastructure, or a related technical field and are passionate about building a long-term career in security, weâd love to hear from you.
Bonus Points
- Contributions to open-source, bug bounty programs, or security communities.
- Familiarity with compliance standards like PCI-DSS, SOC 2, or ISO 27001.
- Prior experience in environments with distributed teams or high agility.
We value people who take initiative, challenge the status quo, and consistently raise the bar. If thatâs how you work, youâll thrive here.
Â
**Please note, no sponsorship is available for this position. You must reside in, or be willing to relocate to, one of these states for employment: Alabama, California, Colorado, Florida, Louisiana, Maryland, Massachusetts, New Jersey, New York, North Carolina, Oregon, Pennsylvania, South Carolina, Tennessee, Texas, Virginia, Washington DC, and Wisconsin.
Below youâll see a few of our perks, but check out our Careers Site for the complete list:Â
- Flexible, remote work environment (*see our open states above)
- No âvacation policyâ (not to be confused with a âNo vacationâ policy)
- Generous fully-paid parental leave
- $1,000 annually to invest in stocks of your choice
- Super low premiums for medical, dental, and vision coverage
Comprehensive compensation package, including company equity
Â
Compensation:Â
Below is our target compensation range. While we are budget conscious, weâre also eager to find the right person for this role, so if your target is outside of this range, please donât hesitate to apply and weâd be happy to have a conversation.Â
Annual Pay Range$150,000â$175,000 USDBy applying on this site, you acknowledge that The Motley Fool will be collecting the personal data you provide for our recruiting purposes. Please see our Applicant Privacy Notice for additional information about how we process, transfer, and store your data, including where that data is stored, and about any additional privacy rights you may have based on your jurisdiction.
Tags: APIs Application security AWS C Cloud CloudFront CNAPP Compliance DAST Generative AI IAM IAST ISO 27001 Lambda LLMs OWASP Pentesting PHP Privacy Python Risk assessment S3 SAST SDLC SOC SOC 2
Perks/benefits: Career development Equity / stock options Flex hours Flex vacation Health care Medical leave Parental leave Salary bonus
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.