
Job Overview
Location
New York - Hybrid
Job Type
Full-time
Category
Software Engineering
Date Posted
June 16, 2026
Full Job Description
đź“‹ Description
- • Conduct threat modelling reviews of Technical Design Documents (TDDs) for new and existing features, providing clear, actionable security recommendations early in the design process.
- • Perform and support application security assessments, including penetration testing, vulnerability assessments, and proof-of-concept (PoC) development for web and mobile applications.
- • Investigate, triage, and respond to submissions from the Bug Bounty program, validating findings and collaborating with engineering teams to drive timely remediation.
- • Own and continuously improve application-layer protections by managing and tuning Cloudflare WAF and related security controls.
- • Partner with engineering teams to embed security best practices throughout the SDLC, from design and development through deployment and maintenance.
- • Research and track emerging threats and vulnerabilities, translating findings into practical mitigation strategies aligned with the organization’s technology stack.
- • Develop and deliver security guidance, training, and awareness programs to engineering teams to elevate the organization’s overall security maturity.
- • Contribute to the creation, maintenance, and evolution of security standards, processes, and documentation.
- • Participate in and eventually lead incident response activities, supporting investigation, containment, remediation, and post-incident improvements.
- • Read, understand, and review source code—particularly JavaScript and TypeScript—to identify security issues and assess attack surfaces.
- • Collaborate with engineering teams to clearly communicate security findings, attack paths, and remediation steps to both technical and non-technical audiences.
- • Operate effectively in a remote environment while maintaining a proactive, collaborative, and ownership-driven mindset.
🎯 Requirements
- • Experience performing white-box, source code-assisted web and mobile application penetration testing from vulnerability discovery through exploitation.
- • Ability to read, understand, and review JavaScript and TypeScript codebases to identify security vulnerabilities.
- • Strong understanding of Threat Modelling principles and their application within the secure software development lifecycle (SDLC).
- • Hands-on experience working with web application firewalls (e.g., Cloudflare WAF) to assess coverage and tune rules for common attack patterns.
- • Experience embedding application security practices into CI/CD pipelines to enable early vulnerability detection.
- • Proven ability to collaborate with engineering teams to communicate security risks and drive remediation for technical and non-technical stakeholders.
🏖️ Benefits
- • Remote work flexibility with support for US, Canada (Toronto), and Mexico locations.
- • Opportunity to work on a platform trusted by over 30 million customers and 500+ ecosystem partners.
- • Exposure to cutting-edge technologies in Web3, blockchain, and decentralized finance.
- • Contribution to a secure-by-design culture within a regulated, enterprise-grade financial technology environment.
- • Potential to engage with the broader security community through open source, CTFs, or conference speaking.
- • Work on a product that aims to make financial freedom and autonomy accessible to everyone globally.
Skills & Technologies
See exactly how your profile matches this role — strengths, skill gaps, and what to do about them.
About MoonPay Inc.
MoonPay Inc. is a financial technology company offering a fiat-to-crypto on-ramp and off-ramp platform that enables consumers, brands, and developers to buy and sell cryptocurrency using traditional payment methods. The company provides compliance, fraud prevention, and payment infrastructure to bridge Web2 and Web3. Founded in 2018 and headquartered in Miami, Florida, MoonPay serves customers globally through APIs and consumer-facing products.
Subscribe to the weekly newsletter for similar remote roles and curated hiring updates.
Newsletter
Weekly remote jobs and featured talent.
No spam. Only curated remote roles and product updates. You can unsubscribe anytime.
Similar Opportunities

Partly Limited
29 days ago

Anyone AI Inc.
1 month ago

Leap Technologies, Inc.
29 days ago

JAMS Software LLC
3 months ago