Polymarket Inc. logo

Application Security Engineer

Job Overview

Location

New York

Job Type

Full-time

Category

Security Engineer

Date Posted

May 21, 2026

Full Job Description

đź“‹ Description

  • • Own the end-to-end application security program across the software development lifecycle, ensuring security is integrated from design through deployment to prevent vulnerabilities from reaching production.
  • • Conduct threat modeling and security design reviews for new features and architectural changes, delivering specific, actionable findings to engineering teams to mitigate risks before implementation.
  • • Lead secure code reviews for high-risk changes, focusing on authentication, authorization, financial transaction flows, and API security, with clear guidance tailored to the engineering stack.
  • • Deploy, tune, and integrate SAST, DAST, and SCA tooling (e.g., Semgrep, Snyk, Burp Suite) into CI/CD pipelines to surface findings at commit time rather than post-deployment.
  • • Triage and prioritize automated scanner output by risk ranking, transforming raw alerts into actionable, prioritized backlogs that engineering teams can efficiently address.
  • • Perform manual penetration testing on web applications, REST/GraphQL APIs, and internal services, with emphasis on identifying exploitable flaws in authentication, session management, RBAC, and financial systems.
  • • Manage the external penetration testing program, coordinating with third-party testers and ensuring comprehensive coverage of critical attack surfaces.
  • • Operate the company’s bug bounty program end-to-end, including triage of submissions, severity calibration, researcher communication, and payout coordination.
  • • Track and drive remediation of application-layer vulnerabilities across the entire product portfolio, monitoring CVEs and escalating critical, exploitable issues for immediate action.
  • • Develop and maintain secure coding guidelines and developer-facing security education materials aligned with the team’s technology stack and evolving threat landscape.
  • • Act as a security partner to product and engineering teams, embedding secure practices into rapid development cycles without creating bottlenecks or slowing innovation.
  • • Collaborate with infrastructure and DevOps teams to ensure application-layer security controls are properly configured in cloud environments, particularly on AWS.
  • • Stay current with emerging attack vectors and security standards in web applications, APIs, and blockchain-based systems to continuously improve the security posture of the platform.
  • • Communicate complex security risks clearly and concisely to technical and non-technical stakeholders, ensuring findings are understood and acted upon promptly.
  • • Foster a culture of security ownership by encouraging adoption of secure development practices across engineering teams, including mentoring and knowledge sharing.

Skills & Technologies

Python
TypeScript
Express
AWS
GraphQL
Onsite

Ready to Apply?

You will be redirected to an external site to apply.

AI Job Fit Analysis
Pro

See exactly how your profile matches this role — strengths, skill gaps, and what to do about them.

Polymarket Inc. logo
Polymarket Inc.
Visit Website

About Polymarket Inc.

Polymarket is a decentralized prediction market platform that allows users to trade on the outcomes of future events. Operating on blockchain technology, it enables individuals to bet on a wide range of topics, including politics, current events, and cryptocurrency. The platform facilitates transparent and trustless trading by leveraging smart contracts, ensuring that payouts are automatically executed based on verified event resolutions. Polymarket aims to democratize information and provide a novel way for people to engage with and profit from their insights into the future, fostering a global community of informed predictors.

Get more remote jobs like this

Subscribe to the weekly newsletter for similar remote roles and curated hiring updates.

Newsletter

Weekly remote jobs and featured talent.

No spam. Only curated remote roles and product updates. You can unsubscribe anytime.

Similar Opportunities

Expired
London Office
Full-time
Expired May 12, 2026
Onsite

4 months ago

Expired
Sydney
Full-time
Expired Apr 14, 2026
Senior
Onsite

5 months ago

Expired
Remote - Bulgaria
Full-time
Expired Apr 25, 2026

4 months ago

Brazil - Remote
Full-time
Expires Jul 16, 2026
Python
Java
AWS
+4 more

1 month ago