> Markdown version of [/jobs/ext/2828386-senior-application-security-engineer-red-team](https://www.wearedevelopers.com/jobs/ext/2828386-senior-application-security-engineer-red-team). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer (Red Team) - **Company:** Altruist Corp - **Location:** Los Angeles, CA, United States - **Experience:** Expert - **Salary:** $170,000.0 - $225,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Android Software Development, Apple IOS, Software System Penetration Testing, Burp Suite, Cyber Security, Computer Engineering, Emulators, Mobile Application Software, Spring Framework, Open Web Application Security, Phishing, Red Team (Cyber Security), Web Applications, Software Security, Kubernetes, Information Technology, Terraform - **Published:** September 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=aacdb2d09b6d4bfa ## About the Role + Experience - 4+ years of experience working as an Application/Product Security Engineer: o Experience as a pentester across web, API, and mobile targets o Extensive experience with security assessments o Experience with tools such as Burp Suite o Strong ability to work independently + Education - A B.A. / B.S. degree in relevant fields such as Computer Science or Computer Engineering or Information Security or relevant experience + Technical aptitude - You're technologically savvy and can easily get up to speed on modern tech stacks (i.e., Java, Spring, Terraform, Kubernetes, etc.) + Ownership - The pride you put into every aspect of your work is unparalleled and undeniable + Superb communication - Intentional dialogue is a superpower. You listen as well as you share your perspective with others. + Resilience - We're inspired by your unwavering determination to achieve success, no matter the adversity you face along the way. + Assurance - Your confidence is brilliant, yet ego-less. You possess a strong knowledge base, the ability to discover the unknown, and are open to differing perspectives. + Creative problem solving - Identifying the problem is simply not enough. You're instinctually creative with your approach in finding solutions to roadblocks. Bonus points if you bring + Experience working in regulated environments (fintech / financial services) + Mobile application pentesting (OWASP MASVS) and cloud/red-team / adversary emulation experience + Relevant certifications (e.g., OSCP, OSWE, GXPN) ## Description Altruist is in the midst of an exciting phase and we're excited to hire a Senior Application Security Engineer to join our growing Security team. Your expertise will ensure our products are secure - by continuously attacking them the way a real adversary would. This role follows a hybrid schedule, with three days per week onsite in our San Francisco FiDi or Culver City office. Your impact + Pentest the Altruist web application, APIs, infrastructure, Android application, and iOS application. + Break security controls continuously so we can build them better each time. + Perform focused authorization and exploitability assessments on high-risk attack paths + Conduct cloud pentests and identity-focused offensive testing. + Run purple-team exercises with Detection & Response and help build detections from your tradecraft. + Develop and maintain offensive tooling and repeatable testing playbooks; contribute to phishing and social-engineering assessments. + Document findings with reproducible proofs-of-concept, clear risk ratings, and actionable remediation guidance. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Xcode development redefAIned](https://www.wearedevelopers.com/videos/100195-xcode-development-redefained) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)