Join Gemini as a Staff Application Security Engineer, where you'll secure critical attack surfaces and design AI agents for secure software development. Enjoy a competitive salary and benefits in a fully remote role.
Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in over 70 countries. Our mission is to unlock the next era of financial, creative, and personal freedom by providing trusted access to the decentralized future.
- Own and evolve the Gemini Secure Software Development Lifecycle guardrails as an application security subject matter expert
- Lead architecture reviews, threat modeling, code reviews, and penetration testing for high-risk applications and services
- Design and build AI agents throughout the SDLC for automated threat modeling during design, AI-driven secure code generation and review, and reducing AppSec toil
- Create and deliver hands-on application security training to enable engineers at scale
- Participate in the Application Security on-call rotation and lead post-incident hardening
- Proven ability to perform design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset
- Strong background in application security best practices and familiarity with common vulnerabilities (e.g. SSRF, race conditions, privilege escalations, etc.)
- Deep code review proficiency in Scala, Java, Go or other common languages, plus hands-on experience in at least Python, Go, or similar for building. Comfortable reviewing production services written in other languages
- Experience implementing custom detection and prevention application security controls to eliminate application security issues beyond OWASP Top 10
- Familiarity with highly regulated environments (financial services, fintech, crypto, or equivalent) and ability to understand business objectives, business context, and security risk
- Strong cross-functional communication and collaboration (Security, Engineering, and Product)
- Typically 7-10+ years of experience or equivalent impact in application security, product security, or similar roles
- Competitive starting pay
- A discretionary annual bonus
- Long-term incentive in the form of a new hire equity grant
- Comprehensive health plans
- 401K with company matching
- Paid Parental Leave
- Flexible time off