Senior Application Security Engineer
Quick Summary
Industry certifications (CISSP, CSSLP, OSCP, CEH)Experience with compliance frameworks (PCI DSS, SOC 2, ISO 27001). Exposure to fintech/payments environments Perks & Benefits Competitive compensation and equity packages Leading configured work…
Imprint is reimagining co-branded credit cards & financial products to be smarter, more rewarding, and truly brand-first. We partner with companies like Crate & Barrel, Rakuten, Booking.com, H-E-B, Fetch, and Brooks Brothers to launch modern credit programs that deepen loyalty, unlock savings, and drive growth. Our platform combines advanced payments infrastructure, intelligent underwriting, and seamless UX to help brands offer powerful financial products—without becoming a bank.
Co-branded cards account for over $300 billion in U.S. annual spend—but most are still powered by legacy banks. Imprint is the modern alternative: flexible, tech-forward, and built for today’s consumer. Backed by Kleiner Perkins, Thrive Capital, and Khosla Ventures, we’re building a world-class team to redefine how people pay—and how brands grow. If you want to work fast, solve hard problems, and make a real impact, we’d love to meet you.
Learn more about us on Imprint's Technology blog.
The Security Engineering team at Imprint is foundational to ensuring the safety and trust of our customers, partners, and products. We are committed to developing a robust and scalable security program that protects our infrastructure, applications, and data from threats, all while enabling the company to innovate quickly and safely. By joining this fast growing FinTech startup, you’ll have a major impact on shaping the future of payments and card technology.
Responsibilities
~2 min read- →
Conduct systematic threat modeling (e.g., leveraging the MITRE ATT&CK framework) to identify risks, define attack paths, and propose mitigations early in the development lifecycle.
- →
Perform in-depth security architecture reviews to ensure applications and microservices follow secure design principles.
- →
Collaborate with engineering teams to conduct code reviews, pinpoint vulnerabilities, and champion OWASP Top 10 best practices.
- →
Integrate SAST and DAST into CI/CD pipelines, ensuring continuous and automated detection of security flaws.
- →
Analyze testing reports and guide teams toward swift, effective remediation strategies.
- →
Perform or coordinate targeted penetration tests on critical applications and systems.
- →
Document findings and partner with engineers to implement sustainable fixes.
- →
Advise on symmetric and asymmetric encryption mechanisms to safeguard data at rest and in transit.
- →
Oversee secure key management, ensuring cryptographic libraries and protocols are properly utilized.
- →
Develop and deliver training on secure coding fundamentals and OWASP principles.
- →
Lead the “shift-left” security movement by embedding security considerations in early stages of development—a strong development background is required to effectively collaborate and coach.
- →
Investigate and document application-focused security incidents.
- →
Maintain and refine incident response playbooks, integrating lessons learned into ongoing improvements.
- →
Align AppSec practices with PCI DSS, SOC 2, and relevant frameworks to support regulatory audits.
- →
Work closely with Risk, Fraud, and Compliance teams to ensure continuous alignment between engineering, security, and business goals.
5+ years in cybersecurity, specifically focused on Application Security.
Hands-on coding experience and familiarity with modern development stacks (e.g., microservices, REST APIs, containerized environments).
Proficiency with SAST/DAST tools, threat modeling methodologies (e.g., MITRE ATT&CK), cryptography concepts (key management, encryption standards), and cloud security services (AWS, GCP, or Azure).
Excellent communication, collaboration, and problem-solving skills in a fast-paced, cross-functional setting.
Nice to Have
~1 min readIndustry certifications (CISSP, CSSLP, OSCP, CEH)
Experience with compliance frameworks (PCI DSS, SOC 2, ISO 27001).Exposure to fintech/payments environments
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- February 4, 2025
- First seen
- May 7, 2026
- Last seen
- May 8, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 25%
- Scored at
- May 7, 2026
Signal breakdown
Please let imprint know you found this job on Jobera.
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.