About the job
About Branch
Branch helps workers gain financial independence by making it easier for companies to pay them quickly and by offering accessible, no-cost financial services. The team is committed to building inclusive and transparent products that improve the financial lives of working Americans.
Ideas and initiative matter here. Employees are encouraged to share their thoughts, those ideas can shape products, culture, and the company’s direction. Branch values diverse perspectives and working styles, aiming to create an environment where everyone can thrive.
Role Overview: Senior Application Security Engineer (Remote, US)
Branch is hiring a Senior Application Security Engineer to help protect applications, networks, cloud infrastructure, and corporate devices. This role calls for broad security expertise and hands-on experience across multiple domains. The engineer will work closely with teams to build secure systems and processes that support Branch’s mission.
What You Will Do
- Collaborate with Engineering to embed security into the Software Development Life Cycle (SDLC): implement secure design patterns, lead threat modeling, and deliver AppSec training for developers.
- Plan and conduct application security assessments, including static and dynamic analysis (SAST, DAST), software composition analysis (SCA), and manual code reviews for web, mobile, and API platforms.
- Strengthen API security for both internal and external services by improving authentication, authorization, rate limiting, and abuse prevention.
- Manage and improve the vulnerability management program: set prioritization frameworks, track SLAs, and coordinate remediation across teams.
- Champion software supply chain security, including generating SBOMs, analyzing dependency risks, and reviewing third-party components.
- Support Governance, Risk, and Compliance (GRC) with technical evaluations of third-party risks and vendor security assessments.
- Lead incident response efforts from initial detection through resolution and post-incident review.
- Develop and maintain security policies and procedures, ensuring alignment with industry standards and best practices.
Location
This position is remote within the United States.

