Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Application Security Engineer image - Rise Careers
Job details

Application Security Engineer


About MoonPay 🌖💸


Hi, we’re MoonPay. We’re here to onboard the world to Web3.


Why? Because we think Web3 is a unique and democratising technology. It gives people back control of their money, digital identity, data, and property like nothing else before it.


What we do

We’re the leading infrastructure company in Web3. This means we offer our partners everything from payment solutions (we call them 'Ramps') to minting software for digital collectibles, like NFTs. And over 20 million people around the world now trust our products — just take a look on Trustpilot.


We’re also big on collaborations. And we've worked on stunts, drops, and partnerships with some of the world's most prestigious and forward-thinking brands.


But that’s not all. We have also built our own consumer app because we wanted to see if we could build a better Web3 account. It’s taken off in a big way, and we're working hard to continually improve it and to strive for perfection.


So whatever your background, we’re sure there’s something for you here. Come help us build the future of Web3 and digital ownership.



About the Opportunity ✍️ 


Our Product Security team is a dynamic blend of proactive defenders and inquisitive problem-solvers. We're dedicated to fortifying our systems through rigorous security reviews and hands-on penetration testing. We actively manage our Bug Bounty program, ensuring swift response and remediation. We leverage cutting-edge tools like Cloudflare's WAF to build robust defenses. Collaboration is key, as we embed security best practices throughout the SDLC. We are constantly researching emerging threats, crafting effective mitigation strategies, and empowering our engineering teams with comprehensive training. We maintain up-to-date security standards and lead incident response with precision. We are passionate about fostering a secure environment and contributing to the wider security community.


🚀 What you will do

* Conduct thorough threat modelling of Technical Design Documents (TDD) practices and provide actionable recommendations for improvement.

* Contribute to and support penetration testing activities, including vulnerability assessments and PoC development.

* Triage, respond and investigate Bug Bounty program reports.

* Implement and manage Web Application Firewalls (WAFs) and other security tools, preferably with experience in Cloudflare.

* Collaborate with development teams to integrate security best practices throughout the software development lifecycle (SDLC).

* Research and evaluate emerging security threats and vulnerabilities, and develop mitigation strategies.

* Develop and deliver security training and awareness programs to engineering teams. 

* Contribute to the development and maintenance of security standards and keeping documentation up to date.

* Lead and participate in incident response activities, including investigation and remediation.


🧑‍🚀 About You

* You developed a breadth of experience across multiple security domains, including application security, infrastructure security, cloud security, and mobile security, with a proven ability to connect and integrate these areas for a holistic security approach.

* You have a strong understanding of Threat Modelling principles and their application to secure software development.

* You have hands-on experience with penetration testing methodologies and tools.

* You had previous experience with WAF configuration and management, ideally including Cloudflare.

* You performed mobile penetration testing and acquired techniques and tools.

* You have proficiency in Javascript and Typescript programming languages.

* You are comfortable explaining technical concepts like vulnerabilities and discussing effective mitigations.

* You are self-motivated, can work effectively in a remote setting while maintaining a team-focused mindset.

* Your background experience includes working in a disruptive technology, successfully launching products, ideally, within FinTech, SaaS, Crypto.

* If you hold relevant security certifications (e.g., CISSP, OSCP, CEH) are a plus but not required.

* You have a good understanding of cryptography and its applications.

* You contribute to the security community in open source, by participating in CTFs, or giving talks at local information security conferences.


💻 What you will be working with/on

As part of our Product  Security team, you'll be instrumental in safeguarding our digital assets. You'll conduct in-depth security reviews of technical designs, ensuring robust defenses from the outset. You'll actively participate in penetration testing, identifying and mitigating vulnerabilities. You'll triage and respond to Bug Bounty reports, maintaining a proactive security posture. You'll configure and manage our Web Application Firewalls, particularly Cloudflare, to thwart attacks. You'll collaborate closely with development teams, integrating security seamlessly into the SDLC. You'll research emerging threats, developing strategies to stay ahead of adversaries. You'll contribute to and deliver security training, fostering a security-conscious culture. You'll help maintain and improve our security standards and documentation. You'll participate in incident response, ensuring swift and effective remediation. You'll also have opportunities to engage with the wider security community.


Most importantly, though, you will embody the core principles that everyone here at the MoonPay lives by. Our “BLOCK Values” are at the heart of everything we do - and they are…


B - Be Hungry

L - Level Up

O - Own It

C - Crypto Curious

K - Kaizen


MoonPay Perks

Equity package 📈

Unlimited holidays 🏝

Paid parental leave 🍼

Annual training budget 💻

Home office setup allowance 🪑

Monthly budget to spend on our products 💰

Working in a disruptive and fast-growing industry where the possibilities are endless 🚀

Freedom, autonomy and responsibility 💪


Research has shown that women are less likely than men to apply for this role if they do not have experience in 100% of these areas. Please know that this list is indicative, and that we would still love to hear from you even if you feel that you are only a 75% match. Skills can be learnt, diversity cannot.


Please let us know if you require any accommodations for the interview process, and we’ll do our best to provide assistance.


Commitment To Diversity

At MoonPay we believe that every voice matters. We strive to create a mindful and respectful environment where everyone can bring their authentic self to work, and experience a culture that is free of harassment, racism, and discrimination. That’s why we are committed to diversity and inclusion in the workplace and are a proud equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status or any other characteristic protected by law. This policy applies to all employment practices within our organization, including, but not limited to, hiring, recruiting, promotion, termination, layoff, and leave of absence.

MoonPay is also committed to providing reasonable accommodations in our job application procedures for qualified individuals with disabilities. Please inform our Talent Team if you need any assistance completing any forms or to otherwise participate in the application process.


Please be aware that MoonPay does not request an AI-led interview without seeing a recruiter or team member from MoonPay on video call. We won't ask for your personal identification documents or any money from you during your interview process with us. Be fraud smart! If you receive an email - claiming to be from MoonPay - but from an email address ending in anything other than @moonpay.com, please be aware that this is not us.

Average salary estimate

$100000 / YEARLY (est.)
min
max
$80000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Application Security Engineer, MoonPay

At MoonPay, we’re excited to introduce the role of Application Security Engineer to help fortify our Web3 infrastructure! Every day, millions of people trust us to provide them with safe and innovative payment solutions. As an Application Security Engineer in our passionate Product Security team, you will have the chance to dive deep into the world of security reviews, conduct penetration testing, and lead our proactive Bug Bounty program. Collaborating closely with our development teams, you will embed security best practices throughout the software development lifecycle to shield our users from emerging threats. Your responsibilities will include conducting thorough threat modeling, managing Web Application Firewalls like Cloudflare, and implementing effective security measures. If you have a blend of experience in application, infrastructure, and mobile security, and a knack for problem-solving, we want to hear from you! Your contributions will not only enhance our security posture but also empower engineers across the company with vital training. As part of your journey with us, you’ll enjoy a culture that fosters innovation and embraces continuous learning, while being supported by perks such as unlimited holidays and a solid equity package. So, if you are ready to make a meaningful impact in the exciting realm of Web3 at MoonPay, don’t hesitate to apply!

Frequently Asked Questions (FAQs) for Application Security Engineer Role at MoonPay
What are the main responsibilities of an Application Security Engineer at MoonPay?

As an Application Security Engineer at MoonPay, you'll conduct thorough threat modeling on Technical Design Documents (TDD), support penetration testing efforts, and manage our Bug Bounty program. Your role will also involve configuring Web Application Firewalls, conducting vulnerability assessments, and delivering security training to empower our engineering teams. These critical tasks will ensure that security is integrated throughout the software development lifecycle, making a substantial contribution to our secure environment.

Join Rise to see the full answer
What qualifications should I have to apply for the Application Security Engineer position at MoonPay?

To be a strong candidate for the Application Security Engineer role at MoonPay, you should have hands-on experience in application security, cloud security, and penetration testing methodologies. Familiarity with configuring WAFs, particularly Cloudflare, is essential. Additionally, a good understanding of cryptography and proficiency in programming languages like Javascript and Typescript will be advantageous. Relevant certifications such as CISSP, OSCP, or CEH are a plus but not mandatory.

Join Rise to see the full answer
What tools and technologies does an Application Security Engineer at MoonPay work with?

In the role of Application Security Engineer at MoonPay, you will work with a variety of cutting-edge tools to enhance security measures, including Cloudflare's Web Application Firewalls. You will conduct vulnerability assessments, perform penetration testing, and utilize various security tools to keep our systems secure. Your role will also involve continuously researching emerging security threats to develop effective mitigation strategies.

Join Rise to see the full answer
How does MoonPay's Application Security Engineer role contribute to the company’s objectives?

The Application Security Engineer role at MoonPay plays a pivotal part in safeguarding our users by ensuring robust security is embedded throughout our services. By conducting thorough security reviews, managing vulnerability assessments, and providing essential training to engineering teams, you will help maintain and improve our security standards. This proactive approach contributes significantly to fostering a secure environment, which aligns perfectly with MoonPay's mission to provide trust and transparency in Web3.

Join Rise to see the full answer
What is the culture like for an Application Security Engineer at MoonPay?

At MoonPay, the culture for an Application Security Engineer is vibrant, collaborative, and deeply committed to innovation and self-development. You'll find a team of professionals who are passionate about security and are eager to contribute to the wider security community. MoonPay values diversity and inclusion, ensuring that every individual has a voice. With perks like unlimited holidays and a supportive work environment, you’ll feel energized and motivated to take on challenges together.

Join Rise to see the full answer
Common Interview Questions for Application Security Engineer
What experience do you have with penetration testing methodologies?

When answering this question, discuss specific methodologies you've employed (such as OWASP or NIST) and any relevant tools (like Burp Suite or Metasploit). Provide examples of past testing scenarios you've successfully navigated, and illustrate how your findings impacted the overall security posture.

Join Rise to see the full answer
Can you explain your process for conducting threat modeling?

It's essential to outline a structured approach when answering this question. Discuss the frameworks you utilize, such as STRIDE or PASTA, and detail how you identify assets, threats, and vulnerabilities in a system. Highlight an experience where your threat modeling led to actionable improvements.

Join Rise to see the full answer
How do you stay updated on the latest security threats?

Express your commitment to continuous learning by discussing the blogs, forums, and conferences you follow. Mention specific security organizations, podcasts, or newsletters you engage with regularly, and how you leverage this knowledge to inform your work as an Application Security Engineer.

Join Rise to see the full answer
Describe your experience with Bug Bounty programs.

Share specific experiences where you've managed or participated in Bug Bounty programs. Highlight how you triaged reports, collaborated with external researchers, and implemented fixes based on feedback. Illustrate how these experiences helped improve your organization's security stance.

Join Rise to see the full answer
What programming languages are you proficient in, and how do they help you in security?

Discuss your experience with programming languages relevant to the role, such as Javascript and Typescript. Explain how your coding knowledge helps you understand vulnerabilities and develop efficient fixes, making you an effective Application Security Engineer.

Join Rise to see the full answer
Can you discuss a time when you had to remediate a significant security vulnerability?

Provide a detailed account of a specific vulnerability you identified and remediated. Describe how you discovered it, the steps taken to address it, and any changes made to processes or training as a result. Make sure to emphasize the positive outcomes of your efforts.

Join Rise to see the full answer
How would you integrate security best practices into the software development lifecycle?

Outline a strategic approach where you identify key stages in the SDLC for embedding security practices, such as design reviews, code scans, and testing phases. Discuss ways you would collaborate with developers to ensure these practices are adopted effectively.

Join Rise to see the full answer
What challenges have you faced in your security career, and how did you address them?

Share a specific challenge you've encountered, such as resistance to security policies or a particularly tricky security bug. Discuss how you overcame this challenge, the lessons learned, and how it has improved your approach to security moving forward.

Join Rise to see the full answer
How would you educate a non-technical team about essential security practices?

Emphasize your communication and teaching skills by providing strategies for imparting security knowledge to non-technical teams. Discuss how you make complex concepts accessible and relatable, perhaps through engaging workshops or informative presentations.

Join Rise to see the full answer
What do you believe is the future of application security in the context of Web3?

Provide insights into your vision of application security's evolution, particularly in relation to Web3. Discuss emerging technologies and potential threats, along with the importance of continuous adaptation and education in safeguarding the digital economy.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 14 days ago

MoonPay is looking for a visionary Senior Director of Product to spearhead their stablecoin strategy and enhance product offerings.

Photo of the Rise User
MoonPay Remote United States - Remote
Posted 14 days ago

Join MoonPay as a Regulatory Counsel and help ensure the compliance of our innovative Web3 products.

Photo of the Rise User
Posted 10 days ago

Join CVS Health as a Clinical Informatics Specialist, where you'll support healthcare providers by enhancing clinical documentation and improving patient care.

Photo of the Rise User
Northstrat Remote No location specified
Posted 11 days ago

Seeking an experienced Linux System Administrator to enhance our technical support at Northstrat.

Photo of the Rise User

Join Aviva as a Cybersecurity Incident Response Analyst, where your expertise will play a crucial role in protecting digital assets in a collaborative environment.

Photo of the Rise User
Posted 3 days ago

Join Lockheed Martin as a Cyber Security Sr. to safeguard innovative solutions at Moody Air Force Base.

ngc Hybrid United States-Georgia-Warner Robins
Posted 10 hours ago

Join Northrop Grumman as a Cybersecurity Analyst to enhance system security and support critical missions in defense and technology.

Photo of the Rise User
SIXT Hybrid Fort Lauderdale
Posted 13 days ago

Join SIXT as a Senior Manager of IT to lead operational improvements and oversee innovative technology solutions.

Photo of the Rise User
CVS Health Remote MD - Work from home
Posted 13 days ago

As a Senior LDAP Engineer, you'll play a crucial role in supporting LDAP systems at CVS Health, a leader in health solutions.

Photo of the Rise User
Posted 14 days ago

Join Visa as a Systems Engineer - macOS and help shape solutions for a global leader in payments technology.

MoonPay is a financial technology company that builds payments infrastructure for crypto. Their on-and-off-ramp suite of products provides a seamless experience for converting between fiat currencies and cryptocurrencies using all major payment me...

48 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 17, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, North Royalton just viewed Remote AI Voice Trainer (High-Quality Microphone Required) at Datadog
C
Someone from OH, Akron just viewed Phlebotomy Technician - Outpatient at CCF
Photo of the Rise User
Someone from OH, Solon just viewed Graphic Designer at Applause
Photo of the Rise User
Someone from OH, North Canton just viewed NodeJs developer at BlackStone eIT
Photo of the Rise User
Someone from OH, North Canton just viewed Software Development Engineer - Recent Grads Welcome at Sonos
Photo of the Rise User
16 people applied to SOC Analyst I at CBIZ
Photo of the Rise User
Someone from OH, Dayton just viewed Data Entry and Word Processing at MoxieIT
Photo of the Rise User
Someone from OH, Dayton just viewed Content Developer - Intern at Big Ideas Learning
Photo of the Rise User
Someone from OH, Pickerington just viewed Salesforce Lead at Bounteous
Photo of the Rise User
Someone from OH, Pickerington just viewed Industry Lead - High Tech (Salesforce) at Thunder
D
Someone from OH, Akron just viewed Junior Motion Designer at DEPT®
R
Someone from OH, Akron just viewed 2D Graphic and Motion Designer at Ruby Labs