Full-Time

Application Security Engineer

Posted on 2/13/2025

Fetch

Fetch

1,001-5,000 employees

Receipt-scanning rewards mobile app

No salary listed

United States

Candidates must be based in the United States.

Candidates must be based in the United States.

Candidates must be based in the United States.

Category
IT & Security (1)
Required Skills
Kubernetes
Python
Docker
Microservices
AWS
Go
Requirements
  • Strong problem-solving and critical thinking skills.
  • Excellent communication and ability to translate technical security findings into actionable insights for non-technical teams.
  • Strong collaboration and relationship-building skills to work effectively with developers, operations, and business stakeholders.
  • Ability to thrive in a fast-paced and agile environment, adapting to changing priorities.
  • Proficiency in programming languages such as Python or Go.
  • Strong understanding of secure coding practices and application security frameworks (OWASP Top 10, SANS CWE).
  • Experience with static and dynamic application security testing (SAST/DAST) tools.
  • Hands-on experience implementing security in CI/CD pipelines (DevSecOps).
  • Solid understanding of web application architecture (APIs, microservices, authentication mechanisms).
  • Experience building and deploying security solutions in AWS or other cloud environments.
  • Familiarity with security automation tools.
  • Proven understanding of container security (Docker/Kubernetes).
  • Knowledge of cloud platforms like AWS (IAM, security groups, encryption) and their security best practices.
  • Familiarity with penetration testing tools (Burp Suite, ZAP) and vulnerability management platforms.
  • Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent work experience).
  • 3+ years of experience in application security or a related role.
Responsibilities
  • Collaborate with engineering and product teams to incorporate security principles throughout the software development process.
  • Conduct and facilitate secure code reviews, analyzing code for vulnerabilities and providing actionable, prioritized recommendations for remediation.
  • Guide teams in implementing secure coding practices, such as input validation, proper error handling, and adherence to standards (OWASP Top 10, SANS CWE).
  • Perform and consult on application security testing, including static analysis (SAST), dynamic analysis (DAST), and manual penetration testing of applications.
  • Identify and assess vulnerabilities, risks, and gaps in Fetch's applications. Work with developers to triage vulnerabilities and ensure timely resolution.
  • Develop and integrate security tools into CI/CD pipelines (DevSecOps) to automate security checks.
  • Maintain and enhance security tools, including SAST, DAST, and open-source vulnerability scanners.
  • Conduct threat modeling and security reviews of applications and systems.
  • Develop and communicate strategies for mitigating identified risks early in the development cycle.
  • Respond to security incidents involving application vulnerabilities.
  • Assist in root cause analysis, remediation planning, and implementation to prevent reoccurrence.
  • Educate and train developers and teams on secure coding practices, security frameworks, and emerging threats.
  • Foster a security-first culture, encouraging secure design and development practices.
  • Stay up-to-date with the latest application security tools, techniques, and threat landscapes.
  • Continuously improve security processes, practices, and tools based on industry standards and lessons learned.
Desired Qualifications
  • Relevant certifications such as CISSP, CEH, OSCP, GWAPT, or CSSLP are a plus.

Fetch Rewards is a mobile rewards app that helps people save money on groceries by earning points for scanned receipts. Users scan their grocery receipts after shopping, and the app automatically identifies eligible products to award points, which can be redeemed for gift cards and merchandise. The service works through partnerships with brands and retailers that pay Fetch Rewards to promote products and engage customers, with revenue coming from brand partnerships and advertising. The app emphasizes a simple experience that lets consumers save money without changing their shopping habits. Compared to competitors, Fetch Rewards combines broad brand partnerships with automatic receipt parsing and a focus on easy, everyday savings through a familiar mobile interface. The goal is to give users a straightforward way to earn rewards on their regular purchases while providing brands with ways to reach shoppers and drive engagement.

Company Size

1,001-5,000

Company Stage

Debt Financing

Total Funding

$850.1M

Headquarters

Madison, Wisconsin

Founded

2013

Simplify Jobs

Simplify's Take

What believers are saying

  • Morgan Stanley invested $110M debt in 2025 for user growth.
  • Fetch achieved profitability in Q4 2023, secured $50M more.
  • Fetch hired first CAIO Gowtham Gundu to lead AI strategy.

What critics are saying

  • Ibotta erodes Fetch's base with superior targeted cashback.
  • Rakuten crushes Fetch Shop via Walmart, Target partnerships.
  • AI-generated receipt fraud causes payout losses, partner exodus.

What makes Fetch unique

  • Fetch rewards points on every receipt from any store without coupons.
  • Fetch Shop enables online rewards via app and browser extension.
  • Fetch provides brands 360-degree shopping insights from 28 monthly receipts.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Fetch who can refer or advise you

Benefits

Stock options

401k match

Medical, dental, & vision

Pet insurance

Education reimbursement

Flexible PTO

Parental leave

Flexible work schedule

Hybrid work environment

Growth & Insights and Company News

Headcount

6 month growth

-1%

1 year growth

0%

2 year growth

1%
Latham & Watkins LLP
Oct 7th, 2025
Latham & Watkins Advises Fetch Rewards on Series of Strategic Growth Financing Transactions

Firm represents leading unicorn consumer loyalty technology company on debt and customer acquisition flow facilities supporting the company’s continued growth.

Stock Titan
Sep 16th, 2025
Morgan Stanley Invests $110M in Fetch

Morgan Stanley Private Credit has led an incremental senior debt financing for Fetch, increasing the existing debt facility to $110 million. This investment aims to accelerate user growth and innovation as Fetch expands into new market verticals. The funding will support product development, AI and machine learning technologies, and user base growth. Fetch's CFO, Gideon Oppenheimer, and Ashwin Krishnan from Morgan Stanley expressed optimism about the partnership and Fetch's growth trajectory.

PR Newswire
Jul 29th, 2025
Fetch Taps Kard to Unlock More Offers for Consumers, Bringing the Power of America's Rewards App to More Brands

MADISON, Wis., July 29, 2025 /PRNewswire/ - Fetch, America's Rewards App, today announced its collaboration with Kard, a rewards infrastructure and demand platform, to expand offers on the Fetch app and reach new brands looking to attract and retain lifelong consumers.

The CDO TIMES
Jun 26th, 2025
Fetch Appoints First-Ever CAIO to Accelerate Company's AI-First Vision - PR Newswire

Gowtham Gundu joins Fetch as the company's first-ever Chief AI Officer to lead its AI and ML strategy

Advanced Television Ltd.
Jun 11th, 2025
Fetch, Kochava launch Loyalty+ programme

The partnership unites Fetch's universal rewards ecosystem with Kochava's omnichannel measurement and attribution technology.

INACTIVE