Senior Application Security Engineer (Red Team)
Altruist
- Location
- San Francsico, CA
- Work model
- On-Site
- Level
- Senior
- Salary
- $200k/yr
- Posted
- 1h ago
Skills
About this role
About Altruist
Altruist is transforming the multi-trillion dollar wealth management industry by building an AI platform for wealth professionals. We partner with financial advisors nationwide, empowering them to grow, optimize time and resources, and deliver superior outcomes for their clients.
We're looking for exceptional talent to help us achieve our mission of making financial advice better, more affordable, and accessible to all. If you're passionate about challenging the status quo and want to do the most important work of your life, we'd love to meet you!
But first, our values
Kindness - Kindness doesn’t just equal niceness. We listen to understand. We embrace, and encourage healthy debate and diverse perspectives. We approach conflict openly, honestly, and respectfully.
Brilliance - Humility is the skill we’re most proud of and possessing a growth mindset is always top of mind. We take ownership in everything we touch; regularly using our unique superpowers to reach a common goal as a team. We succeed and fail as one.
Grit - When challenges arise, we stay laser focused on achieving our mission and finding a way forward, even when it’s hard. We are nimble and maintain a sense of urgency, swiftly adapting to change and overcoming obstacles.
About the position
Altruist is in the midst of an exciting phase and we’re excited to hire a Senior Application Security Engineer to join our growing Security team. Your expertise will ensure our products are secure — by continuously attacking them the way a real adversary would.
This role follows a hybrid schedule, with three days per week onsite in our San Francisco FiDi or Culver City office.
Your impact
• Pentest the Altruist web application, APIs, infrastructure, Android application, and iOS application.
• Break security controls continuously so we can build them better each time.
• Perform focused authorization and exploitability assessments on high-risk attack paths
• Conduct cloud pentests and identity-focused offensive testing.
• Run purple-team exercises with Detection & Response and help build detections from your tradecraft.
• Develop and maintain offensive tooling and repeatable testing playbooks; contribute to phishing and social-engineering assessments.
• Document findings with reproducible proofs-of-concept, clear risk ratings, and actionable remediation guidance.
What you'll bring
• Experience - 4+ years of experience working as an Application/Product Security Engineer:
• Experience as a pentester across web, API, and mobile targets
• Extensive experience with security assessments
• Experience with tools such as Burp Suite
• Strong ability to work independently
• Education - A B.A. / B.S. degree in relevant fields such as Computer Science or Computer Engineering or Information Security or relevant experience
• Technical aptitude - You’re technologically savvy and can easily get up to speed on modern tech stacks (i.e., Java, Spring, Terraform, Kubernetes, etc.)
• Ownership - The pride you put into every aspect of your work is unparalleled and undeniable
• Superb communication - Intentional dialogue is a superpower. You listen as well as you share