Full-Time

Application Security Engineer

Confirmed live in the last 24 hours

ONE Finance

ONE Finance

1,001-5,000 employees

Digital banking platform with high-yield savings

Fintech

Compensation Overview

$175k - $220kAnnually

Mid

Remote in USA

Remote friendly (anywhere in the US) and office friendly - you pick the schedule.

Category
Cybersecurity
IT & Security
Required Skills
Datadog
Kubernetes
React.js
Wireshark
GraphQL
TypeScript
AWS
Cryptography
Requirements
  • 4+ years of experience in security engineering, DevSecOps, and application development.
  • Excellent knowledge of the CVSS, MITRE ATT&CK, and OWASP Top 10.
  • Proficiency in TypeScript.
  • Practical understanding of AWS and its core services (VPC, EC2, RDS).
  • Demonstrated experience in modern application architecture and deployment practices.
  • Experience with Library/API/Framework development.
  • Experience with integrating security scanning tools with CI/CD, Web Application pentesting, fuzzing and DAST.
  • Expertise in verifying and measuring common security vulnerabilities, and demonstrated ability to communicate these concepts to technical and non-technical partners.
  • Exposure to most of the following technologies: AWS, iOS, Android, Vault, Kubernetes, PKI, React, GraphQL, and Datadog.
  • Knowledge of cryptography including algorithms, standards, and their practical applications such as x.509 certificates.
  • Experience defining security architecture patterns and standards.
  • Proficiency in modern security evaluation tooling (Burp, Wireshark, Kali et al.).
  • Preferably, understanding of regulatory compliance concerns (GLBA, CCPA, PCI).
  • The Triple H Factor: Humble, Hungry and Honest.
Responsibilities
  • Ensuring the quality and security of our applications and products by guiding their development through the Secure Development Lifecycle (SDLC) process.
  • Performing SAST/DAST and penetration testing on core application services, web applications, and mobile applications.
  • Developing, maintaining, and extending our in-house application security and penetration testing automated testing framework.
  • Developing safe libraries and hardening existing libraries and frameworks to eliminate classes of vulnerabilities.
  • Ensuring SDLC practices are enforced via Infrastructure-As-Code (IaC) policies, wherever possible.
  • Working closely with Engineering teams to validate the security posture of new features prior to production deployment.
  • Triaging and validating security vulnerabilities found or reported, and serving as a subject-matter expert in AppSec to the Engineering team in identifying and implementing mitigation solutions.
  • Refactoring and deploying secure libraries and frameworks across the code repository.
  • Training engineers, architects, code reviewers, and others on secure coding practices.
  • Contributing to application threat models.
  • Constantly maintaining awareness of known vulnerabilities in application technologies used within One.
  • Working with the Security and other engineering teams to maintain a security architecture that provides security controls throughout all platforms to mitigate risk, and to meet goals and regulatory requirements.
  • Providing expertise around code-level security concerns during product development.

One Finance provides a digital banking platform through its mobile app, allowing users to manage their finances conveniently. The app offers a debit Mastercard® and is designed for both individuals and small businesses. By partnering with Coastal Community Bank, One Finance enables users to access banking services without being a bank itself. A key feature of the app is a high-yield savings account that offers an Annual Percentage Yield (APY) of up to 5.00% on balances up to $250,000, which is significantly higher than typical savings accounts. One Finance generates revenue primarily through interchange fees when customers use their debit card for purchases. Additional benefits include early direct deposit, cash back rewards at Walmart, instant money transfers, and overdraft protection. The goal of One Finance is to provide a cost-effective and user-friendly financial management solution that helps customers grow their savings and avoid unnecessary fees.

Company Stage

Seed

Total Funding

$66.7M

Headquarters

New York City, New York

Founded

2022

Growth & Insights
Headcount

6 month growth

18%

1 year growth

64%

2 year growth

207%
Simplify Jobs

Simplify's Take

What believers are saying

  • The potential launch of a BNPL service backed by Walmart could significantly expand ONE Finance's product offerings and customer base.
  • High APY on savings accounts can attract a large number of customers looking for better returns on their deposits.
  • The backing and majority ownership by Walmart provide financial stability and a strong market presence.

What critics are saying

  • The fintech market is highly competitive, with numerous players offering similar services, which could impact customer acquisition and retention.
  • Reliance on interchange fees for revenue may be vulnerable to regulatory changes and market fluctuations.

What makes ONE Finance unique

  • ONE Finance offers a high-yield savings account with an APY of up to 5.00%, significantly higher than the industry average.
  • The partnership with Coastal Community Bank allows ONE Finance to provide banking services without being a bank itself, reducing regulatory burdens.
  • The integration of features like early direct deposit, cash back at Walmart, and overdraft protection makes ONE Finance a comprehensive financial solution.

Help us improve and share your feedback! Did you find this helpful?