Senior Application Security Engineer
Moonpay
Moonpay
MoonPay is for builders with something to prove.
This isn't a "work on cool crypto stuff" company. It's a high-standards, high-velocity, high-accountability company building the operating system for value movement. If the internet moves information, we move value: crypto, stablecoins, tokenized assets, and whatever comes next. Four offerings make that real: fund, tokenize, trade, and spend. 30M+ customers and 500+ ecosystem partners run on us. Licensed in the U.S. Regulated across the UK, EU, Canada, and Australia.
AI is the default operating mode here. It's woven into every role, and we expect you to use it daily. It handles the manual work so you can deliver on what actually matters.
You'll thrive here if outcomes excite you more than process, if impact motivates you more than titles, and if you want hard problems, real ownership, and teammates who love winning, building, and doing it together.
The bar is high. The pace is real. We're building for what's next, for humans and agents.
Recent recognition:
Forbes' America's Best Startup Employers 2026 .
2nd in Crypto Services on Fortune's inaugural Crypto 100
The Sunday Times Best Places to Work two years running
Research has shown that women are less likely than men to apply for this role if they do not have experience in 100% of these areas. Please know that this list is indicative, and that we would still love to hear from you even if you feel that you are only a 75% match. Skills can be learned, diversity cannot.
US (East Coast)
Canada (Toronto)
Mexico
Relocation available:No
Work pattern:
This role will be remote.
Our SRE/Cloud Security teams are a dynamic blend of proactive defenders and inquisitive problem-solvers. We are dedicated to strengthening our systems through rigorous security reviews and hands-on penetration testing, and we actively manage our Bug Bounty program to ensure timely validation, response, and remediation.
We leverage cutting-edge tools and techniques to build robust defenses, and collaboration is central to how we work; embedding security best practices throughout the SDLC. We continuously research emerging threats, develop effective mitigation strategies, and empower engineering teams through clear guidance and practical security training.
We maintain up-to-date security standards and documentation, lead incident response efforts with precision, and are passionate about spreading a secure-by-design culture while contributing to the wider security community.
Conduct threat modelling reviews of Technical Design Documents (TDDs) for new and existing features, providing clear, actionable security recommendations early in the design process.
Perform and support application security assessments, including penetration testing, vulnerability assessments, and proof-of-concept (PoC) development where appropriate.
Investigate, triage, and respond to Bug Bounty program submissions, validating findings and working with engineering teams to drive timely remediation.
Own and continuously improve application-layer protections, including managing and tuning Cloudflare WAF and related security controls.
Partner closely with engineering teams to embed security best practices throughout the SDLC, from design and development through deployment and maintenance.
Research and track emerging threats and vulnerabilities, translating findings into practical mitigation strategies relevant to our technology stack.
Develop and deliver security guidance, training, and awareness for engineering teams to raise the overall security maturity of the organization.
Contribute to the creation, maintenance, and evolution of security standards, processes, and documentation.
Participate in and eventually lead incident response activities, supporting investigation, containment, remediation, and post-incident improvements.
Must-have experience and skills
You have developed a breadth of experience across multiple security domains, including web and mobile application security, infrastructure and cloud security, and can connect these areas to drive a holistic security approach.
You have hands-on experience performing white-box, source code-assisted web and mobile application penetration testing, from vulnerability discovery through triage and exploitation.
You have the ability to read, understand, and review source code to identify security issues, with ideally, a particular focus on JavaScript and TypeScript codebases.
You have a strong understanding of Threat Modelling principles and their practical application to the secure software development lifecycle (SDLC).
You have experience working with web application firewalls to help protect applications, assess coverage, and support tuning rules to mitigate common attack patterns.
You have experience embedding application security practices into CI/CD pipelines, enabling early detection of vulnerabilities and close collaboration with engineering teams throughout the development lifecycle.
You have collaborated closely with engineering teams to clearly communicate security findings, explain vulnerabilities, attack paths, and mitigations, and support the implementation of effective fixes for both technical and non-technical audiences.
You are self-motivated, proactive, and take strong ownership of your work, operating effectively in a remote environment while maintaining a collaborative, team-focused mindset.
Nice-to-have experience
You have experience in JavaScript and TypeScript, including the ability to read, understand, and reason about modern web application codebases.
You have experience working with Cloudflare, including its hosting and Web Application Firewall (WAF) capabilities, to help secure and operate internet-facing applications.
You have experience testing and securing GraphQL, REST APIs, including understanding common GraphQL/REST-specific attack vectors and security considerations.
You have experience or a strong interest in Web3 security testing, including assessing smart contracts, blockchain-based applications, or Web3 integrations.
You have an interest in agentic engineering, including emerging patterns in autonomous systems, tooling, or workflows, and their security implications.
You contribute or have contributed to the security community through open source involvement, participation in CTFs, or speaking at local information security meetups and conferences.
Your background includes experience working with disruptive technologies and successfully launching products, ideally within FinTech, SaaS, or Crypto.
You hold one or more security relevant certifications such as OSCP or OSWE.
π° Competitive salary package
π€ Equity package: financial freedom starts with our employees, so all employees have ownership at MoonPay
π Pay-for-performance equity bonus: those who drive outsized outcomes receive outsized rewards
π Moonshot award: we honor exceptional impact. 10 employees twice a year, each earning a $250,000 equity grant
πPension: employer contributions from day one
πEmployee referral program: refer great people, earn 10K in USDC
π Flexible Time Off: choose when to work and when to switch off
π Birthday leave: take the day off to celebrate you
πΌ Enhanced parental leave: more time with family, no second thought
π Hybrid working schedule: work fully remotely or from your nearest Moonbase
π Commuter benefits: public transport to and from the office
π©Ί Private healthcare benefits: to protect you and your loved ones
π§ Wellhub wellness membership: access to gyms, studios, classes, and wellness apps in one membership
π€ Unlimited enterprise access to the latest AI tools: Claude, ChatGPT, Gemini and whatever's next
π± Lunch credit: meals covered on the days you're in the office
πͺ Home office setup allowance: build the home office of your dreams
π Remote working allowance: those working fully remotely get a little extra for utilities
π Monthly product budget and zero-fee crypto transactions
π $1,000 Annual training budget: we support your learning journey
π― High Potential Program: structured development, mentorship, and stretch opportunities
βοΈ Regular remote company offsites: high-impact in-person sessions and hackathons
π² (Ireland) Cycle to Work scheme: tax-efficient bike, gear, and safety kit
π (UK) EV Salary Sacrifice: lease an electric vehicle through pre-tax salary