FOMO Labs is seeking a Staff Security Engineer to lead their application security program, focusing on secure software development and vulnerability management.
About fomo
fomo is growing fast, now serving 2M+ users and backed by a $75M Series B (Index Ventures, with Union Square Ventures and Benchmark) at a $550M valuation. As we scale, we're investing in a security function that can keep pace with an increasingly complex product surface without slowing down engineering velocity.What you'll do
- Lead security architecture reviews and threat modeling for new features and major system changes, partnering directly with engineering and product teams from design through launch
- Own our secure SDLC program: static and dynamic analysis (SAST/DAST), dependency and software composition analysis, secrets scanning, and CI/CD security gates
- Perform deep-dive code reviews and manual penetration testing of high-risk services, APIs, and web applications
- Design and build internal security tooling and guardrails that let engineers move fast without introducing risk
- Run and mature our vulnerability management program, including triage, severity scoring, and driving remediation with engineering owners
- Manage relationships with external pentest vendors and bug bounty programs, and turn findings into durable fixes rather than one-off patches
- Set technical direction on authentication, authorization, API security, and data protection patterns used across the product
- Mentor engineers on secure coding practices and act as a go-to resource for security questions across the org
- Contribute to incident response when application-layer issues arise
- Help define and evolve fomo's overall AppSec roadmap and metrics
What we're looking for
- 7+ years in security engineering, with a substantial and recent focus on application security (not primarily corporate/IT security)
- Deep hands-on experience with secure code review, threat modeling, and common vulnerability classes (OWASP Top 10, auth/session flaws, SSRF, injection, business logic flaws, etc.)
- Strong software engineering background; comfortable reading and writing production code, not just running scanners
- Experience building and scaling AppSec tooling and processes (SAST/DAST, SCA, CI/CD security integration) at a growing company
- Track record of driving security into engineering culture through influence, not just gatekeeping
- Familiarity with cloud-native environments (AWS/GCP/Azure), container security, and modern API architectures
- Excellent communication skills; able to explain risk to both engineers and non-technical stakeholders
- Prior experience as a technical lead or staff-level IC who can operate with high autonomy
Nice to have:
- Experience with bug bounty program management
- Background in a high-growth consumer or marketplace product