> Markdown version of [/jobs/ext/2680064-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2680064-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Forward, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $145,000.0 - $183,000.0 - **Contract:** Permanent contract - **Skills:** Testing (Software), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Cloud Computing, Python (Programming Language), Ruby, Secure Coding, TypeScript, Web Applications, Large Language Models, Multi-Agent Systems, Software Security, Information Technology, Programming Languages - **Published:** September 2, 2026 - **Apply:** https://jobs.ashbyhq.com/Forward%20Financing/e2c84aa7-b1d5-4538-b86c-371f44ee26c0?utm_source=kXX9zjrLpM ## About the Role * 5+ years in application security, offensive security, or product security. * Hands-on pentesting and code-review depth across web applications, APIs, and cloud infrastructure (AWS). * A hacker mentality. You're curious about how systems break, and you keep pulling on threads after the scanner comes back clean. * Interest in using AI to solve problems, whether that's in your own workflow or in the systems you're testing. * Understanding of AI/LLM attack surface: prompt injection, insecure agent tool use, and vulnerabilities characteristic of AI-generated code. * Experience with modern programming languages such as Ruby, Python, TypeScript, or Go, and with secure SDLC practices. * Ability to communicate risk and priorities to other security and software engineers. * Typically has a Bachelor's Degree in Computer Science or equivalent technical degree, or equivalent industry experience. Nice to have: * Experience pentesting or red-teaming LLM applications and agentic systems. * OSCP/OSWE or comparable offensive certifications. * Experience contributing to bug-bounty or external testing programs. * Background in fintech or other regulated environments. ## Description As a Senior Application Security Engineer, you'll find the vulnerabilities in Forward Financing's software before an attacker does. You'll pentest our core systems along with the AI systems and agents our engineers are shipping, and help shape how we test software that AI helped write. Our engineering organization is moving fast with AI, and our security testing needs to move at the same pace. In this role you will: * Conduct manual penetration tests against each of our systems, and build the AI-assisted tooling and automation that extends how much ground those tests can cover. * Help define how we pentest AI. Bring us new ideas for testing LLM applications, agents, and agent-generated code, and build the ones that work into our regular testing. * Triage findings from our SAST tools, fix the vulnerabilities that are real, and tune the rules that produce false positives. * Perform secure code review across web applications, APIs, and AWS infrastructure. * Build tooling and security services within the Forward application stack, including AI-assisted tooling that speeds up the security team's own work. * Support the test-to-production review process so AI-built work is security-reviewed before promotion. * Explain risk to engineers in enough detail that they can prioritize and fix what you found. Why you should apply: * Shape a growing function: Our security program is early enough that your work sets the standard. You'll have influence over how we test, what tooling we build, and how we secure AI-built software. * Mission driven company: Forward is a trusted source of fast, flexible funding for small businesses that have often been underserved by traditional financing options. When you join the team, you will help ensure all small businesses have access to the financial support they need to succeed. * Flexibility is a top priority: Our employees are empowered to choose where they want to work (whether that's from home, in the office, or a combination of both) with flexible hours., The Forward Compass is the standard we hold for ourselves and one another-guiding how we lead, collaborate, and show up every day to move in the same direction. Back the Builders: We are wired to fuel customer progress, not just provide support. Rooted in People: We create an environment that balances deep connection with the extreme ownership and honesty required to reach our highest potential. Flying V: We move through coordinated effort with speed and urgency to achieve what no individual could do alone. Always Forward, Never Finished: We pursue growth with a relentless drive that keeps us ahead of the competition. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)