Gemini
Staff Application Security Engineer
About this role
Description: Join Gemini's Application Security team as a Staff Application Security Engineer, focusing on securing critical attack surfaces like on-chain, exchange, and credit card. Operate with autonomy and collaborate with senior engineering leadership to design and build AI agents for secure software development lifecycle (SDLC). Requirements: Proven experience in design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset. Strong knowledge of application security best practices and common vulnerabilities (e.g., SSRF, race conditions). Proficiency in Scala, Java, Go, and experience in Python or similar for building. Experience in implementing custom application security controls beyond OWASP Top 10. Familiarity with regulated environments (financial services, fintech, crypto). Excellent cross-functional communication skills. Typically 7-10+ years of experience in application security or similar roles. Benefits: Competitive starting pay with a discretionary annual bonus. Long-term incentive through a new hire equity grant. Comprehensive health plans and 401K with company matching. Paid Parental Leave and flexible time off.