Staff Security Engineer, Application Security at FOMO Labs · Web3Vacancy
Jobs Companies Blog About Contact
Post a job
Analysing Your CV...
Extracting your experience, skills, and details...

Staff Security Engineer, Application Security

Office
Market range (est.) $90k–$180k
◆ 6/10 techSecurity Engineeroffice
Join Talent Pool
About this role

FOMO Labs is seeking a Staff Security Engineer to lead their application security program, focusing on secure software development and vulnerability management.

Description

About fomo

fomo is growing fast, now serving 2M+ users and backed by a $75M Series B (Index Ventures, with Union Square Ventures and Benchmark) at a $550M valuation. As we scale, we're investing in a security function that can keep pace with an increasingly complex product surface without slowing down engineering velocity.
Responsibilities

What you'll do

  • Lead security architecture reviews and threat modeling for new features and major system changes, partnering directly with engineering and product teams from design through launch
  • Own our secure SDLC program: static and dynamic analysis (SAST/DAST), dependency and software composition analysis, secrets scanning, and CI/CD security gates
  • Perform deep-dive code reviews and manual penetration testing of high-risk services, APIs, and web applications
  • Design and build internal security tooling and guardrails that let engineers move fast without introducing risk
  • Run and mature our vulnerability management program, including triage, severity scoring, and driving remediation with engineering owners
  • Manage relationships with external pentest vendors and bug bounty programs, and turn findings into durable fixes rather than one-off patches
  • Set technical direction on authentication, authorization, API security, and data protection patterns used across the product
  • Mentor engineers on secure coding practices and act as a go-to resource for security questions across the org
  • Contribute to incident response when application-layer issues arise
  • Help define and evolve fomo's overall AppSec roadmap and metrics
Requirements

What we're looking for

  • 7+ years in security engineering, with a substantial and recent focus on application security (not primarily corporate/IT security)
  • Deep hands-on experience with secure code review, threat modeling, and common vulnerability classes (OWASP Top 10, auth/session flaws, SSRF, injection, business logic flaws, etc.)
  • Strong software engineering background; comfortable reading and writing production code, not just running scanners
  • Experience building and scaling AppSec tooling and processes (SAST/DAST, SCA, CI/CD security integration) at a growing company
  • Track record of driving security into engineering culture through influence, not just gatekeeping
  • Familiarity with cloud-native environments (AWS/GCP/Azure), container security, and modern API architectures
  • Excellent communication skills; able to explain risk to both engineers and non-technical stakeholders
  • Prior experience as a technical lead or staff-level IC who can operate with high autonomy

Nice to have:

  • Experience with bug bounty program management

  • Background in a high-growth consumer or marketplace product

Conditions & Benefits

Why fomo

You'll be the first dedicated AppSec hire shaping the security foundation of a company at real scale, with the autonomy to set standards rather than inherit them.
Job Details
Market range (est.)$90k–$180k
LocationOffice
AI Score★★★★★★☆☆☆☆ 6/10
PostedSep 16, 2026 (3d ago)
Tags & Skills
techSecurity Engineeroffice
Tech Stack
application securitysecure codingthreat modelingvulnerability managementcloud-native environmentsAWSGCPAzurecontainer securityAPI security
Join Talent Pool

Similar Web3 Jobs

Browse Crypto Job Vacancies

The #1 Web3 Job Board for Crypto Jobs & Blockchain Careers

Web3Vacancy is the leading web3 job board for blockchain developers, DeFi engineers, smart contract auditors, NFT product managers, DAO operators, ZK researchers, and Web3 growth leads. We aggregate 2,400+ remote-first crypto jobs from top protocols, decentralized exchanges, layer-2 networks, AI-blockchain startups, and Web3 studios worldwide. Whether you are hiring or looking for your next blockchain job, Web3Vacancy is the go-to job board for the decentralized economy.

Find web3 jobs across every skill level and specialization. Solidity developers, Rust engineers, Move programmers, ZK circuit engineers, tokenomics designers, crypto legal counsel, Web3 community managers, and blockchain data analysts all find their next role here. New crypto job listings are added daily across Ethereum, Solana, Polygon, Arbitrum, Base, Cosmos, Sui, Aptos, and every emerging blockchain ecosystem.

Looking to start a web3 career? Explore our guides on web3 salaries, blockchain interview questions, and the top web3 companies hiring in 2026. New to blockchain? Start with our What Is Web3 guide and learn web3 development from scratch. Employers can post a web3 job.