Senior Application Security Engineer
Cross River provides API-driven banking infrastructure enabling embedded financial services including payments, lending, card programs, and cryptocurrency solutions.
Funding history
Projects
About Cross River Bank
Cross River operates a proprietary real-time banking core platform that delivers embedded financial services to fintech and technology companies. The platform provides payment rails including ACH, wires, RTP, and FedNow, card issuing and processing capabilities, digital lending infrastructure, and cryptocurrency banking services. Cross River enables partners to access banking functionality through API integrations while maintaining federal regulatory compliance.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will help developers build secure systems by mentoring them on secure coding, facilitating threat modeling and design reviews, and guiding architecture decisions. You will lead a Security Champions program, integrate application-security tools into CI/CD workflows, provide actionable remediation guidance, and support compliance documentation and secure development evidence.
Requirements
- Native-level written and verbal English and Hebrew fluency
- 7+ years of software security engineering experience, including 4–5 years in application security or secure-development enablement
- Coding ability in JavaScript, TypeScript, Python, Go, Java, or C#
- Experience teaching, mentoring, or enabling developers
- Knowledge of secure coding, vulnerability classes, API security, and secure design
- Experience with SAST, SCA, IaC scanners, secret scanning, and developer workflow integration
- Experience with cloud-native architectures and security in AWS or Azure
- Familiarity with PCI DSS, SOC 2, FFIEC, NIST, OWASP, and ASVS
- Communication and storytelling skills
Responsibilities
- Mentor, coach, and educate developers on secure coding through workshops, training, pair reviews, and ongoing guidance
- Lead and scale a Security Champions program within engineering
- Facilitate threat-modeling sessions and design reviews
- Guide secure architecture patterns, API security practices, and design principles
- Integrate and tune SAST, SCA, IaC scanning, and secret-scanning guardrails into CI/CD pipelines
- Translate vulnerabilities into actionable remediation guidance
- Create internal security content, best-practice playbooks, and reusable patterns
- Produce compliance documentation and SDLC evidence for FFIEC, PCI DSS, and SOC 2
- Stay current on emerging threats, developer tooling, and secure engineering patterns
Benefits
- Flexible hybrid model with three office days per week
- ₪1,000 net monthly wellness benefit
- Full Keren Hishtalmut
- Private health and dental insurance
- Donation matching
- Volunteering days
- Team outings
