> Markdown version of [/jobs/ext/171648-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/171648-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** POLYMARKET CLEARING LLC - **Location:** New York, NY, United States - **Experience:** Experienced - **Salary:** $180,000.0 - $250,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, User Authentication, Burp Suite, Code Review, Continuous Integration, Payment Systems, Python (Programming Language), OAuth, Open Web Application Security, Systems Development Life Cycle, Role-Based Access Control, Blockchain, JSON Web Token, Secure Coding, Session Management, Software Engineering, TypeScript, Web Applications, Software Security, Backend, GWAPT, Graphql, Web3.js, Api Gateway, Static Application Security Testing, Vulnerability Analysis, Golang, Dynamic Application Security Testing - **Published:** May 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e5f963d42f274796 ## About the Role Do you have experience in Vulnerability assessment tools?, * 3+ years of hands-on application security experience - penetration testing, secure code review, or a dedicated AppSec engineering role * Strong proficiency identifying and exploiting OWASP Top 10 vulnerabilities; experience assessing modern web applications and API architectures * Experience deploying and operating SAST, DAST, and SCA tooling (Semgrep, Snyk, Burp Suite, or equivalent) * Ability to read and write code in at least one common backend language (Python, Go, TypeScript, or similar) to conduct meaningful code review * Experience conducting or managing penetration tests against web applications and REST/GraphQL APIs * Solid understanding of authentication and authorization patterns: OAuth 2.0, JWT, session management, RBAC, and common weaknesses in each * Clear written communication - able to write findings that developers actually read and act on * (Plus) Experience with a bug bounty platform (HackerOne, Bugcrowd, or equivalent) as an operator * (Plus) Familiarity with smart contract security, blockchain transaction flows, or Web3 threat models * (Plus) Experience securing financial transaction systems - payment flows, fraud vectors, double-spend risks * (Plus) Security certifications: OSCP, GWAPT, GWEB, or equivalent * (Plus) Exposure to AWS application-layer security services: WAF, API Gateway, Cognito, Shield * (Plus) Prior experience building or scaling a security champions program inside an engineering organization ## Description Polymarket is looking for an Application Security Engineer to embed security throughout our software development lifecycle. You'll partner directly with product and engineering teams to identify and fix vulnerabilities before they reach production, own the tooling and processes that make secure development the default, and lead hands-on security assessments of our externally-facing platform. This is a high-ownership role at a company where engineering moves fast - the right candidate knows how to raise the security bar without becoming a bottleneck. What You'll Do * Own the application security program across the SDLC - from design review through deployment - ensuring security is addressed early and consistently * Conduct threat modeling on new features and architectural changes; perform security design reviews and code reviews on high-risk changes with specific, actionable findings * Own the SAST, DAST, and SCA toolchain - selection, deployment, tuning, and CI/CD integration so findings surface at commit time, not post-deployment * Triage and prioritize automated scanner output, delivering a risk-ranked backlog rather than raw tool output to engineering teams * Conduct manual penetration testing and security assessments of web applications, APIs, and internal services - with particular focus on authentication, authorization, and financial transaction flows * Manage the external penetration testing program and own the bug bounty program end-to-end: triage, severity calibration, researcher communication, and payout coordination * Track and drive remediation of application-layer vulnerabilities across the product portfolio; monitor CVEs and escalate exploitable issues requiring immediate action * Develop and maintain secure coding guidelines and developer-facing security education tailored to the team's stack and threat model ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Retooling and refactoring - an investment in people.](https://www.wearedevelopers.com/videos/371-retooling-and-refactoring-an-investment-in-people) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)