MisuJob - AI Job Search Platform MisuJob

Application Security Engineer

Polymarket

New York, NY, United States permanent

Posted: May 19, 2026

Interested in this position?

Create a free account to apply with AI-powered matching

Quick Summary

We are looking for an Application Security Engineer to join our team at Polymarket, where we enable individuals to express views on real-world events by trading on outcomes across politics, economics, sports, culture, and current affairs.

Job Description

About Polymarket

Polymarket is the world's largest prediction market platform. We enable individuals to express views on real-world events by trading on outcomes across politics, economics, sports, culture, and current affairs. Built as a peer-to-peer marketplace with no centralized "house," Polymarket aggregates diverse opinions into transparent, market-based probabilities that reflect collective expectations about the future.

We're growing fast — both in terms of volume ($21B traded in 2025) and adoption as an alternative news source. Our ambition is to become a ubiquitous beacon of truth in global media and we need your help adding fuel to the fire.

About the Role

Polymarket is looking for an Application Security Engineer to embed security throughout our software development lifecycle. You'll partner directly with product and engineering teams to identify and fix vulnerabilities before they reach production, own the tooling and processes that make secure development the default, and lead hands-on security assessments of our externally-facing platform.

This is a high-ownership role at a company where engineering moves fast — the right candidate knows how to raise the security bar without becoming a bottleneck.

What You'll Do

• Own the application security program across the SDLC — from design review through deployment — ensuring security is addressed early and consistently

• Conduct threat modeling on new features and architectural changes; perform security design reviews and code reviews on high-risk changes with specific, actionable findings

• Own the SAST, DAST, and SCA toolchain — selection, deployment, tuning, and CI/CD integration so findings surface at commit time, not post-deployment

• Triage and prioritize automated scanner output, delivering a risk-ranked backlog rather than raw tool output to engineering teams

• Conduct manual penetration testing and security assessments of web applications, APIs, and internal services — with particular focus on authentication, authorization, and financial transaction flows

• Manage the external penetration testing program and own the bug bounty program end-to-end: triage, severity calibration, researcher communication, and payout coordination

• Track and drive remediation of application-layer vulnerabilities across the product portfolio; monitor CVEs and escalate exploitable issues requiring immediate action

• Develop and maintain secure coding guidelines and developer-facing security education tailored to the team's stack and threat model

What We're Looking For

• 3+ years of hands-on application security experience — penetration testing, secure code review, or a dedicated AppSec engineering role

• Strong proficiency identifying and exploiting OWASP Top 10 vulnerabilities; experience assessing modern web applications and API architectures

• Experience deploying and operating SAST, DAST, and SCA tooling (Semgrep, Snyk, Burp Suite, or equivalent)

• Ability to read and write code in at least one common backend language (Python, Go, TypeScript, or similar) to conduct meaningful code review

• Experience conducting or managing penetration tests against web applications and REST/GraphQL APIs

• Solid understanding of authentication and authorization patterns: OAuth 2.0, JWT, session management, RBAC, and common weaknesses in each

• Clear written communication — able to write findings that developers actually read and act on

• (Plus) Experience with a bug bounty platform (HackerOne, Bugcrowd, or equivalent) as an operator

• (Plus) Familiarity with smart contract security, blockchain transaction flows, or Web3 threat models

• (Plus) Experience securing financial transaction systems — payment flows, fraud vectors, double-spend risks

• (Plus) Security certifications: OSCP, GWAPT, GWEB, or equivalent

• (Plus) Exposure to AWS application-layer security services: WAF, API Gateway, Cognito, Shield

• (Plus) Prior experience building or scaling a security champions program inside an engineering organization

Benefits

• Competitive salary & equity

• Unlimited PTO

• Full Health, Vision, & Dental coverage

• 401k match

• Hardware setup: new MacBook Pro, big display, & accessories

Why Apply Through MisuJob?

AI-Powered Job Matching: MisuJob uses advanced artificial intelligence to analyze your skills, experience, and career goals. Our matching algorithm compares your profile against thousands of job requirements to find positions where you have the highest chance of success. This saves you hours of manual job searching and ensures you only see relevant opportunities.

One-Click Applications: Once you create your profile, applying to jobs is effortless. Your resume and cover letter are automatically tailored to highlight the most relevant experience for each position. You can apply to multiple jobs in minutes, not hours.

Career Intelligence: Beyond job matching, MisuJob provides valuable career insights. See how your skills compare to market demands, identify skill gaps to address, and understand salary benchmarks for your experience level. Make data-driven decisions about your career path.

Frequently Asked Questions

How do I apply for this position?

Click the "Register to Apply" button above to create a free MisuJob account. Once registered, you can apply with one click and track your application status in your dashboard.

Is MisuJob free for job seekers?

Yes, MisuJob is completely free for job seekers. Create your profile, get matched with jobs, and apply without any cost. We help you find your dream job without any hidden fees.

How does AI matching work?

Our AI analyzes your resume, skills, and experience to understand your professional profile. It then compares this against job requirements using natural language processing to calculate a match percentage. Higher matches mean better fit for the role.

Can I apply to jobs in other countries?

Absolutely. MisuJob features jobs from companies worldwide, including remote positions. Filter by location or look for remote opportunities to find jobs that match your preferences.

Ready to Apply?

Join thousands of job seekers using MisuJob's AI to find and apply to their dream jobs automatically.

Register to Apply