Application Security Engineer / Architect (DevSecOps)
About Clear Street
Clear Street’s mission is to give every sophisticated investor access to every asset, in every market, through a unified platform built for speed, transparency and scale. We give our clients the technology, tools, and service once reserved for the largest institutions, rebuilt with modern infrastructure. Our single, cloud-native, end-to-end capital markets platform powers investor growth today and is transforming how they can interact with markets tomorrow.
The Team
As an application security engineer in the Security team, you’ll have the opportunity to problem solve, build and influence the security posture of our products and services across the product ecosystem. In this role specifically, you’ll be responsible for leading application security efforts with our engineers as part of the product development lifecycle at source code and cloud levels within DevSecOps, Vulnerability and other arenas.
Responsibilities
- Own security controls within CI/CD pipelines (SAST, DAST, SCA, secrets detection) and maintain pipeline-as-code tooling.
- Work with engineers to identify and remediate vulnerabilities in application source code.
- Manage the vulnerability lifecycle: triage findings from scanners, prioritize by risk, track remediation, and report on trends.
- Lead cloud security efforts, work with engineering teams to enforce cloud security best practices (IAM, network controls, storage security, workload protection).
- Maintain and tune security tooling including SAST/DAST scanners, container security platforms, and dependency analysis tools.
- Build automation and AI based tools to scale DevSecOps operations.
- Partner with Infra Engineering teams to define secure infrastructure-as-code (IaC) standards and enforce them via policy-as-code.
- Participate in threat modeling sessions and security design reviews for new features and services.
- Support incident response activities related to application and cloud security events.
- Contribute to security documentation, runbooks, and developer-facing guidance.
Requirements
- 7+ years of experience in a DevSecOps, application security, or cloud security engineering role.
- Hands-on experience with CI/CD platforms (GitHub Actions, GitLab CI, Jenkins, or similar).
- Proficiency with at least one major cloud provider (AWS, Azure, or GCP) and its native security services.
- Experience with SAST/SCA tools (e.g., Semgrep, Snyk, Checkmarx, Veracode) and interpreting findings.
- Working knowledge of container and Kubernetes security (image scanning, RBAC, network policies, admission control).
- Scripting skills in Python, Bash, or similar for automation and tooling.
- Familiarity with IaC tools (Terraform, CloudFormation, Pulumi) and policy frameworks (OPA/Rego, Checkov).
- Understanding of OWASP Top 10, CWE, and common vulnerability classes.
- Strong communication skills — able to explain security risk clearly to non-security audiences.
Your impact won't be measured by the number of servers you manage—it will be measured by how much faster and happier our engineers become.
Pay
The Base Salary Range is $175,000 - $210,000. These ranges are representative of the starting base salaries for this role at Clear Street. Which range a candidate fits into and where a candidate falls in the range will be based on job related factors such as relevant experience, skills, and location. The range represents Base Salary only, which is just one element of Clear Street's total compensation.
Benefits
- Competitive compensation packages, including company equity.
- 401k matching.
- Gender neutral parental leave.
- Full medical, dental and vision insurance.
- In-office benefits including lunch stipends, fully stocked kitchens, happy hours, a great location, and amazing views.
Schedule
We are requiring employees to be in the office 4 days per week.