Polymarket

Application Security Engineer

7.0/10

Polymarket

Not specified
Office / on-site
mid
8 days ago
cryptodevsecurityweb3application securitypenetration testingsecure code reviewSASTDASTSCAPythonGo

AI Summary

The vacancy is well-defined with clear responsibilities but lacks compensation details.

Check Match โ€” Just drop your CV

See your fit for Application Security Engineer in seconds.

Description

About Polymarket

Polymarket is the world's largest prediction market platform. We enable individuals to express views on real-world events by trading on outcomes across politics, economics, sports, culture, and current affairs. Built as a peer-to-peer marketplace with no centralized "house," Polymarket aggregates diverse opinions into transparent, market-based probabilities that reflect collective expectations about the future. We're growing fast โ€” both in terms of volume ($21B traded in 2025) and adoption as an alternative news source. Our ambition is to become a ubiquitous beacon of truth in global media and we need your help adding fuel to the fire.

What You'll Do

  • โ€ขOwn the application security program across the SDLC โ€” from design review through deployment โ€” ensuring security is addressed early and consistently
  • โ€ขConduct threat modeling on new features and architectural changes; perform security design reviews and code reviews on high-risk changes with specific, actionable findings
  • โ€ขOwn the SAST, DAST, and SCA toolchain โ€” selection, deployment, tuning, and CI/CD integration so findings surface at commit time, not post-deployment
  • โ€ขTriage and prioritize automated scanner output, delivering a risk-ranked backlog rather than raw tool output to engineering teams
  • โ€ขConduct manual penetration testing and security assessments of web applications, APIs, and internal services โ€” with particular focus on authentication, authorization, and financial transaction flows
  • โ€ขManage the external penetration testing program and own the bug bounty program end-to-end: triage, severity calibration, researcher communication, and payout coordination
  • โ€ขTrack and drive remediation of application-layer vulnerabilities across the product portfolio; monitor CVEs and escalate exploitable issues requiring immediate action
  • โ€ขDevelop and maintain secure coding guidelines and developer-facing security education tailored to the team's stack and threat model

Benefits

  • โ€ขCompetitive salary & equity
  • โ€ขUnlimited PTO
  • โ€ขFull Health, Vision, & Dental coverage
  • โ€ข401k match
  • โ€ขHardware setup: new MacBook Pro, big display, & accessories

Requirements

What We're Looking For

  • โ€ข3+ years of hands-on application security experience โ€” penetration testing, secure code review, or a dedicated AppSec engineering role
  • โ€ขStrong proficiency identifying and exploiting OWASP Top 10 vulnerabilities; experience assessing modern web applications and API architectures
  • โ€ขExperience deploying and operating SAST, DAST, and SCA tooling (Semgrep, Snyk, Burp Suite, or equivalent)
  • โ€ขAbility to read and write code in at least one common backend language (Python, Go, TypeScript, or similar) to conduct meaningful code review
  • โ€ขExperience conducting or managing penetration tests against web applications and REST/GraphQL APIs
  • โ€ขSolid understanding of authentication and authorization patterns: OAuth 2.0, JWT, session management, RBAC, and common weaknesses in each
  • โ€ขClear written communication โ€” able to write findings that developers actually read and act on
  • โ€ข(Plus) Experience with a bug bounty platform (HackerOne, Bugcrowd, or equivalent) as an operator
  • โ€ข(Plus) Familiarity with smart contract security, blockchain transaction flows, or Web3 threat models
  • โ€ข(Plus) Experience securing financial transaction systems โ€” payment flows, fraud vectors, double-spend risks
  • โ€ข(Plus) Security certifications: OSCP, GWAPT, GWEB, or equivalent
  • โ€ข(Plus) Exposure to AWS application-layer security services: WAF, API Gateway, Cognito, Shield
  • โ€ข(Plus) Prior experience building or scaling a security champions program inside an engineering organization
Loading similar jobs...