Full-Time Senior or Staff Software Engineer, Application Security
TRM Labs is hiring a remote Full-Time Senior or Staff Software Engineer, Application Security. The career level for this job opening is Expert and is accepting USA based applicants remotely. Read complete job description before applying.
TRM Labs
Job Title
Posted
Career Level
Career Level
Locations Accepted
Salary
Share
Job Details
TRM is on a mission to build a safer financial system for billions of people. We deliver a blockchain intelligence data platform to financial institutions, crypto companies, and governments to fight cryptocurrency fraud and financial crime. We consider our business — and our profit — as a way to move towards our mission sustainably and at scale.
The Security team is responsible for and committed to securing all things at TRM. From our customers to our code, and everything in between, the security team is involved in all aspects of the business. We are looking for an Application Security Engineer to build mission-critical infrastructure that ensures the highest levels of availability, performance, and application security at TRM for products as built and deployed. From designing the technical strategy to company-wide best practices and implementation, you’ll work closely with engineering and engineering leadership to ensure TRM’s products are safe and secure.
The impact you will have here:
- Lead application security reviews and threat modeling, including secure code review, architectural design, and testing
- Develop automated testing and mature our Secure SDLC
- Own and perform application security vulnerability management
- Coordinate penetration testing engagements
- Support software engineers and product teams by developing application security best practices
- Develop and maintain the bug bounty program
- Bootstrap platform security initiatives that help protect TRM data
- Inspire a culture of security across the engineering organization by fostering security champions within engineering teams and coordinating secure code training.
What we’re looking for:
- Minimum 8 years of experience in Software Development and testing.
- BS (or equivalent) in Computer Science, Computer Engineering, or related field.
- Proficiency in software development languages: Python, NodeJS, React
- Strong understanding of encryption, authentication, and authorization protocols
- Deep experience with common software flaws (e.g., OWASP and CWE), testing methodologies , and using common security tooling for testing.
- Professional experience with open source, commercial, or native security solutions for cloud providers such as GCP and AWS. Experience with modern secure software development lifecycles, threat modeling, and best practices.
- Experience with conducting efficient and comprehensive code security reviews on a daily or weekly basis
- Experience triaging and remediating vulnerabilities in software packages or libraries
- Experience with Software Security tools such as Github advanced security or other SAST, DAST, and SCA tools
- Experience with Web application testing frameworks such as BurpSuite, OWASP ZAP, etc.
- Experience with Threat modeling tools such as OWASP Threat Dragon, etc.
- Experience working in a previous agile-based software development role required
- Experience Red Teaming or penetration testing applications and infrastructure
- Professional experience with cloud providers (e.g., GCP and AWS), modern secure software development lifecycles, and best practices.
- Strong written and verbal communication skills.
- Security certifications such as OSCP, CEH, GWAPT are a plus.
- Familiarity with security frameworks (e.g., NIST SP 800-171 SSDF) is a plus
About TRM's Engineering Levels:
Engineer: Responsible for helping to define project milestones and executing small decision decisions independently with the appropriate tradeoffs between simplicity, readability, and performance. Provides mentorship to junior engineers, and enhances operational excellence through tech debt reduction and knowledge sharing.
Senior Engineer: Successfully designs and documents system improvements and features for an OKR/project from the ground up. Consistently delivers efficient and reusable systems, optimizes team throughput with appropriate tradeoffs, mentors team members, and enhances cross-team collaboration through documentation and knowledge sharing.
Staff Engineer: Drives scoping and execution of one or more OKRs/projects that impact multiple teams. Partners with stakeholders to set the team vision and technical roadmaps for one or more products. Is a role model and mentor to the entire engineering organization. Ensures system health and quality with operational reviews, testing strategies, and monitoring rigor.
The following represents the expected range of compensation for this role:
- Additionally, this role may be eligible to participate in TRM’s equity plan.