Figure Lending - Application Security Engineer
Requirements
• Responsibilities include: - Architect, design, and implement end-to-end security solutions including firewalls, intrusion detection, encryption protocols, security event management, and cloud security controls - Collaborate with DevOps to integrate security into CI/CD pipelines with automation - Conduct security assessments, threat modeling, architecture reviews, and manage vulnerability programs including triage and remediation tracking - Lead third-party penetration tests, incident response, on-call rotations, and mentor engineers on security best practices • Requirements: - Experience in application security domains such as penetration testing, vulnerability research, secure coding, security architecture, and hardware security - Strong software engineering skills in languages like C/C++, Rust, Go, Python or similar - Experience with embedded systems security, web/mobile security, or cryptography - Ability to collaborate across teams and balance security with development velocity Perks &
Responsibilities
• Architect, design, and implement end-to-end security solutions, including firewalls, intrusion detection, encryption protocols, security event management, and cloud security controls. • Collaborate with DevOps to integrate security into CI/CD pipelines, ensuring automation and repeatability of secure deployments. • Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations. • Lead cross-team initiatives that significantly improve our security posture while balancing speed and innovation. • Mentor engineers on security best practices and build a culture of security by design. • Actively participate in incident response, on-call rotations, and post-incident reviews to continuously improve defenses. • What We Look For • What We Look For • Improve and run Figure's vulnerability management program including triage, prioritization, tracking remediation, and reporting on risk reduction over time. • Collaborate with DevOps to integrate security gates at various points throughout the software development lifecycle, ensuring automation and repeatability of secure deployments. • Manage third-party penetration tests, including scoping, vendor coordination, and tracking remediation of findings. • Automate sources of toil, such as routine patching or dependency upgrades. • Conduct threat modeling and security reviews for new features and services, partnering with engineering teams early in the design process. • Adhere to all company security policies and data handling procedures. • Complete mandatory security awareness training within required timeframes. • Promptly report any suspected security incidents or suspicious activity to the Security team.
Benefits
• Comprehensive medical, dental, and vision coverage, with 100% employer-paid premiums for employees and their dependents on select plansCompany HSA, FSA, Dependent Care FSA, 401(k), and commuter benefitsEmployer-paid life and disability insurance11 observed holidays and PTO planUp to 12 weeks of paid family leaveContinuing education reimbursement • Depending on your residential location certain laws might regulate the way Figure manages applicant data. California Residents, please review our California Employee and General Workforce Privacy Notice for further information. By submitting your application, you are agreeing and acknowledging that you have read and understand the above notice. • Figure will not sponsor work visas for this position. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. • #LI-SB1 #LI-Hybrid
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT