Staff Application Security Engineer

Brex · United States · Engineering · listed June 25, 2026

The shape of it

Seniority
Staff
Experience asked
8+ years
Where
Not stated
Requirements listed
6
Length
663 words

In the posting’s own words

Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It’s an environment where engineering is a craft, and builders become leaders.

What it asks for · 6

  • 8+ years of experience in Application Security, Product Security, or software engineering with a primary focus on offensive and defensive application security.
  • Proven track record of technical leadership and team mentorship on complex, multi-quarter security engineering initiatives in a fast-paced environment.
  • Deep proficiency and technical expertise in AI security, including hands-on experience securing agentic architectures, LLM gateways, and evaluating adversarial AI vectors.
  • Strong systems-thinking capabilities with extensive experience defining secure product development lifecycles, threat modeling complex topologies, and cloud-native container security (AWS, Kubernetes).
  • Proficiency in Python, Go, or similar languages to architect internal tooling, pipeline automation, and advanced detection/scanning engines.
  • Exceptional written and verbal communication skills, with a demonstrated ability to navigate ambiguity, influence technical leaders, and manage up and out across EPD organizations.

Also a plus

  • Experience with Kotlin, gRPC, GraphQL, Kubernetes
  • Previous experience in building and scaling security teams
  • Experience with securing distributed systems in AWS and cloud environments
  • Contributions to the wider technical community — open source, public research, CTF participation, blogging, CVEs, or presentations
  • Experience submitting to bug bounty or responsible disclosure programs
  • Published AI security research or contributions to AI security frameworks

What the job covers

  • Lead the technical vision and strategic roadmap for the Application Security team, aligning security objectives with Brex's enterprise growth and high-velocity engineering metrics.
  • Establish technical standards and secure defaults across the entire engineering organization, fostering a culture of collaborative security excellence and bridging product platforms, infra, and trust.
  • Architect and secure novel AI/ML and agentic workflows, applying cutting-edge practices to mitigate risks such as prompt injection, model manipulation, and data poisoning.
  • Mentor and coach engineers within the team and across the broader organization, guiding technical growth, helping individuals level up their security expertise, and accelerating team delivery.
  • Drive proactive vulnerability discovery and offensive security testing strategies, executing complex attack chains to demonstrate business impact and prioritize cross-functional remediation.
  • Partner with Product Platform, Cloud Infrastructure, and Data engineering teams to ensure core primitives, APIs, and microservices are secure by default from design to deployment.

Tools and skills named

Security & compliance
  • Security15×
  • Threat modeling
Cloud & infra
  • AWS2×
  • Kubernetes2×
  • Distributed systems
  • Microservices
Languages
  • Go
  • Kotlin
  • Python
Ways of working
  • Cross-functional
  • Mentorship
  • Testing
Frameworks
  • GraphQL
  • gRPC
Models & research
  • LLM
  • Machine learning
Product & design
  • Roadmap

Words the posting leans on

  • security15×
  • engineering8×
  • technical8×
  • experience7×
  • product4×
  • secure4×
  • complex3×
  • data3×
  • organization3×
  • agentic2×
  • architect2×
  • architecture2×
  • aws2×
  • building2×
  • cloud2×
  • contributions2×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Brex

every open role at Brex

How this page was made

An automated read of a public job posting, fetched August 25, 2026 and last changed by Brex on August 19, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.