Application Security Engineer
Polymarket
AI Summary
The vacancy is well-defined with clear responsibilities but lacks compensation details.
Check Match โ Just drop your CV
See your fit for Application Security Engineer in seconds.
Description
About Polymarket
Polymarket is the world's largest prediction market platform. We enable individuals to express views on real-world events by trading on outcomes across politics, economics, sports, culture, and current affairs. Built as a peer-to-peer marketplace with no centralized "house," Polymarket aggregates diverse opinions into transparent, market-based probabilities that reflect collective expectations about the future. We're growing fast โ both in terms of volume ($21B traded in 2025) and adoption as an alternative news source. Our ambition is to become a ubiquitous beacon of truth in global media and we need your help adding fuel to the fire.
What You'll Do
- โขOwn the application security program across the SDLC โ from design review through deployment โ ensuring security is addressed early and consistently
- โขConduct threat modeling on new features and architectural changes; perform security design reviews and code reviews on high-risk changes with specific, actionable findings
- โขOwn the SAST, DAST, and SCA toolchain โ selection, deployment, tuning, and CI/CD integration so findings surface at commit time, not post-deployment
- โขTriage and prioritize automated scanner output, delivering a risk-ranked backlog rather than raw tool output to engineering teams
- โขConduct manual penetration testing and security assessments of web applications, APIs, and internal services โ with particular focus on authentication, authorization, and financial transaction flows
- โขManage the external penetration testing program and own the bug bounty program end-to-end: triage, severity calibration, researcher communication, and payout coordination
- โขTrack and drive remediation of application-layer vulnerabilities across the product portfolio; monitor CVEs and escalate exploitable issues requiring immediate action
- โขDevelop and maintain secure coding guidelines and developer-facing security education tailored to the team's stack and threat model
Benefits
- โขCompetitive salary & equity
- โขUnlimited PTO
- โขFull Health, Vision, & Dental coverage
- โข401k match
- โขHardware setup: new MacBook Pro, big display, & accessories
Requirements
What We're Looking For
- โข3+ years of hands-on application security experience โ penetration testing, secure code review, or a dedicated AppSec engineering role
- โขStrong proficiency identifying and exploiting OWASP Top 10 vulnerabilities; experience assessing modern web applications and API architectures
- โขExperience deploying and operating SAST, DAST, and SCA tooling (Semgrep, Snyk, Burp Suite, or equivalent)
- โขAbility to read and write code in at least one common backend language (Python, Go, TypeScript, or similar) to conduct meaningful code review
- โขExperience conducting or managing penetration tests against web applications and REST/GraphQL APIs
- โขSolid understanding of authentication and authorization patterns: OAuth 2.0, JWT, session management, RBAC, and common weaknesses in each
- โขClear written communication โ able to write findings that developers actually read and act on
- โข(Plus) Experience with a bug bounty platform (HackerOne, Bugcrowd, or equivalent) as an operator
- โข(Plus) Familiarity with smart contract security, blockchain transaction flows, or Web3 threat models
- โข(Plus) Experience securing financial transaction systems โ payment flows, fraud vectors, double-spend risks
- โข(Plus) Security certifications: OSCP, GWAPT, GWEB, or equivalent
- โข(Plus) Exposure to AWS application-layer security services: WAF, API Gateway, Cognito, Shield
- โข(Plus) Prior experience building or scaling a security champions program inside an engineering organization