Description
About Us OpenFX is on a mission to move money as freely as data, unrestricted by time zones, banking hours, or legacy systems. We are building the infrastructure that will power the next generation of cross-border payment systems for institutions. The team's execution has been exceptional, and we're scaling at a remarkable pace.
P. Morgan, Goldman Sachs, FalconX, PayPal, Affirm, Polygon, Kraken, Nium & others. We're backed by Accel, Faction, NfX, Accomplice, and other top-tier investors.
Role Overview This is a hybrid Application + Cloud Security role for an engineer who has 2–4 years of hands-on security experience and is ready to grow into a specialist. You'll spend roughly half your time supporting AppSec (code review, secure SDLC tooling, threat modeling, findings triage) and half on CloudSec (AWS account security, IAM reviews, Kubernetes hardening, WAF tuning). You'll partner closely with our Sr.
Application Security Engineer and Cloud Security Engineer (both L3), picking up increasingly complex work as you ramp. The goal is for you to develop deep expertise in one of the two specializations within 12–18 months while remaining strong across both. This role is ideal for someone who is technically curious, has shipped real security work (not just evaluated tools), and wants to grow fast in a high-stakes fintech environment.
Key
Responsibilities
Application Security (~50%) Perform manual and automated code reviews alongside the Sr. AppSec engineer, with growing independence over time Triage, reproduce, and drive remediation on findings from SAST, DAST, SCA, bug bounty, and internal reports Support threat-modeling sessions for
Employer contacts (email/phone/telegram) are hidden from the public preview —
send your CV, and we will connect you directly.