Senior Application Security Engineer (Remote)

Brex · Canada · Engineering · listed February 17, 2026

The shape of it

Seniority
Senior
Experience asked
5+ years
Where
Not stated
Stated pay
$192,000 – $240,000
Requirements listed
5
Length
812 words

In the posting’s own words

As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will perform code reviews, design reviews, penetration testing, and vulnerability management. You will develop and maintain tooling to perform static and dynamic testing of the Brex platform and tooling which supports secure developer workflows. Application Security is part of our wider Financial Scale organization, which means you will work closely with Security Operations, GRC, Product Security, Front End Platform, IT Infrastructure teams.

What it asks for · 5

  • 5+ years work experience in an Application Security or related role
  • Ability to find vulnerabilities in complex systems, demonstrating business impact through custom attack chains
  • Experience with a wide range of secure development activities including— threat modeling, developer education, and incident response
  • Knowledge of Python, scripting languages, and AI/agentic workflows to automate tasks, build tools and improve productivity
  • Collaborative mindset paired with strong written and verbal communication skills

Also a plus

  • Proficiency with Kotlin, gRPC, GraphQL, Kubernetes
  • Previous experience as a software engineer
  • Consultancy experience performing web application security reviews
  • Experience with securing distributed systems in AWS and cloud environments
  • Experience with pentesting and securing agentic features and systems
  • Contributions to the wider technical community— open source, public research, mentorship, community organizing, blogging, CVEs, presentations, etc
  • Experience submitting to bug bounty programs or responsible disclosure programs

What the job covers

  • Identifying vulnerabilities, demonstrating business impact, and articulating the risk of specific vulnerabilities to drive prioritization efforts
  • Perform penetration testing and design reviews, looking for vulnerabilities and insecure designs, work with engineering and product to design secure product features
  • Maintain and build internal tools to automate security efforts, perform SAST and DAST testing of the Brex platform, and support secure development practices
  • Build and contribute to a culture of collaborative security excellence through technical leadership, learning sessions, and mentorship within the team and wider organization

Tools and skills named

Security & compliance
  • Security12×
  • Penetration testing3×
  • Threat modeling
Ways of working
  • Testing5×
  • Mentorship2×
  • Code review
  • Cross-functional
Cloud & infra
  • AWS
  • Distributed systems
  • Kubernetes
Frameworks
  • GraphQL
  • gRPC
Languages
  • Kotlin
  • Python

Words the posting leans on

  • security12×
  • experience7×
  • engineering6×
  • vulnerabilities6×
  • product5×
  • secure5×
  • systems5×
  • build4×
  • design4×
  • financial4×
  • perform4×
  • platform4×
  • reviews4×
  • business impact3×
  • collaborative3×
  • features3×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Brex

every open role at Brex

How this page was made

An automated read of a public job posting, fetched August 24, 2026 and last changed by Brex on July 16, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.