Senior Application Security Engineer

Forward FinancingBoston, MA
$145,000 - $183,000Remote

About The Position

As a Senior Application Security Engineer, you'll find the vulnerabilities in Forward Financing's software before an attacker does. You'll pentest our core systems along with the AI systems and agents our engineers are shipping, and help shape how we test software that AI helped write. Our engineering organization is moving fast with AI, and our security testing needs to move at the same pace.

Requirements

  • 5+ years in application security, offensive security, or product security.
  • Hands-on pentesting and code-review depth across web applications, APIs, and cloud infrastructure (AWS).
  • A hacker mentality. You're curious about how systems break, and you keep pulling on threads after the scanner comes back clean.
  • Interest in using AI to solve problems, whether that's in your own workflow or in the systems you're testing.
  • Understanding of AI/LLM attack surface: prompt injection, insecure agent tool use, and vulnerabilities characteristic of AI-generated code.
  • Experience with modern programming languages such as Ruby, Python, TypeScript, or Go, and with secure SDLC practices.
  • Ability to communicate risk and priorities to other security and software engineers.
  • Typically has a Bachelor's Degree in Computer Science or equivalent technical degree, or equivalent industry experience.

Nice To Haves

  • Experience pentesting or red-teaming LLM applications and agentic systems.
  • OSCP/OSWE or comparable offensive certifications.
  • Experience contributing to bug-bounty or external testing programs.
  • Background in fintech or other regulated environments.

Responsibilities

  • Conduct manual penetration tests against each of our systems, and build the AI-assisted tooling and automation that extends how much ground those tests can cover.
  • Help define how we pentest AI. Bring us new ideas for testing LLM applications, agents, and agent-generated code, and build the ones that work into our regular testing.
  • Triage findings from our SAST tools, fix the vulnerabilities that are real, and tune the rules that produce false positives.
  • Perform secure code review across web applications, APIs, and AWS infrastructure.
  • Build tooling and security services within the Forward application stack, including AI-assisted tooling that speeds up the security team's own work.
  • Support the test-to-production review process so AI-built work is security-reviewed before promotion.
  • Explain risk to engineers in enough detail that they can prioritize and fix what you found.

Benefits

  • medical
  • dental
  • vision
  • commuter benefits
  • a flexible time-off policy
  • paid parental leave
  • 401k match for US employees
  • wellness reimbursement
  • volunteering days
  • annual professional development budget
  • charitable donation match
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service