Staff Security Engineer, Application Security
Senior
Application Security
Cloud Platforms
Cloud Security
Data Security
DevSecOps
Dynamic Application Security Testing
Facilities Management
Information Security
InfoSec
Management
Project Management
Risk Governance
Risk Management
Secure Software Development Lifecycle
Security
Security Assurance
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Software Security
Solution Architecture
Job Description
fomo Labs is looking for a hands-on Staff Security Engineer focused on Application Security to own and elevate its AppSec program. This is a high-leverage role that combines secure SDLC leadership with deep technical work across threat modeling, code review, penetration testing, and the security tooling that helps engineering ship confidently.
What you’ll do
- Lead security architecture reviews and threat modeling for new features and major system changes, collaborating with engineering and product teams from design through launch
- Own and run a secure SDLC program including SAST and DAST, dependency and software composition analysis, secrets scanning, and CI/CD security gates
- Conduct deep-dive code reviews and perform manual penetration testing for high-risk services, APIs, and web applications
- Design and build internal security tooling and guardrails that reduce risk while enabling engineers to move quickly
- Operate and mature vulnerability management, including triage, severity scoring, and driving remediation with engineering owners
- Manage relationships with external pentest vendors and bug bounty programs, ensuring findings translate into durable fixes
- Set technical direction for authentication, authorization, API security, and data protection patterns used across the product
- Mentor engineers on secure coding practices and serve as a go-to resource for security questions throughout the organization
- Support incident response when application-layer issues arise
- Help define and evolve the AppSec roadmap and associated metrics
What you bring
- 7+ years in security engineering with substantial and recent application security focus (not primarily corporate or IT security)
- Strong hands-on experience in secure code review, threat modeling, and common vulnerability classes such as OWASP Top 10, auth or session flaws, SSRF, injection, and business logic flaws
- Solid software engineering foundation, comfortable reading and writing production code rather than only running scanners
- Experience building and scaling AppSec tooling and processes including SAST/DAST, SCA, and CI/CD security integration in a growing environment
- A record of driving security into engineering culture through influence rather than gatekeeping
- Familiarity with cloud-native environments (AWS, GCP, Azure), container security, and modern API architectures
- Excellent communication skills, able to explain risk clearly to engineers and non-technical stakeholders
- Prior experience as a technical lead or staff-level IC with high autonomy
Technologies
- SAST, DAST, SCA, CI/CD
- OWASP Top 10
- AWS, GCP, Azure
- Containers
- API architectures
Compensation and location
- Location: New York, NY (onsite)
- Salary: USD 270,000 - 330,000 per year
Benefits
- Competitive cash compensation and equity
- Comprehensive health insurance (medical, dental, vision) for you and your dependents, including tax savings benefits such as HSAs and FSAs
- 401(k) with match
- Group term life insurance
- Flexible time off
- Annual company offsites
Nice to have
- Experience with bug bounty program management
- Background in a high-growth consumer or marketplace product