Application & Product Security Engineer
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
About Jump
Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up — which means our customers trust us with some of their most sensitive client data. Security isn’t a checkbox for us; it’s core to the product and to earning that trust every day.
About the Role
We’re hiring our first dedicated Application & Product Security Engineer. You’ll partner with engineering and product teams from the earliest design conversations to make sure security is built into what we ship — not bolted on afterward. This is a hands-on, high-ownership role at a startup: some days you’ll be threat modeling a new feature, other days reviewing code, tuning our security tooling, or jumping in on an incident. If you like variety and want your work to directly shape how a product is built, this role is for you.
What You’ll Do
Partner with product and engineering teams during design and planning to identify risks early and build security into new features from the start.
Lead threat modeling and secure design reviews for new products, features, and architecture changes.
Perform security-focused code reviews and help engineers fix vulnerabilities — and understand how to avoid them next time.
Build and maintain application security tooling (SAST, dependency scanning, secrets detection) integrated into CI/CD.
Participate in incident response: triage, investigate, contain, and drive post-incident learning.
Triage findings from bug bounty reports, pen tests, and vulnerability scans, and drive remediation with owning teams.
Develop lightweight security guidance, paved-road patterns, and training that make the secure way the easy way.
Wear multiple hats as needed — from customer security questionnaires to cloud and corporate security improvements.
What We’re Looking For
2–4 years of experience in application security, product security, or a software engineering role with significant security responsibilities.
Solid grasp of common vulnerability classes (OWASP Top 10, authn/authz flaws, injection, SSRF) and how to prevent them in real codebases.
Experience with threat modeling and secure design review, and the ability to explain risk in terms engineers and PMs care about.
Hands-on incident response experience — you’ve helped detect, investigate, or contain real security events.
Ability to read and write code (e.g., Python, TypeScript/JavaScript, Go, or similar) well enough to review PRs and build small tools.
Strong communication and collaboration skills — you build trust with engineers rather than throwing findings over the wall.
Comfort with ambiguity and shifting priorities; you can self-direct and wear multiple hats.
Nice to Have
Prior security experience at a startup or on a small security team (a major plus).
Cloud security experience (AWS, GCP, or Azure) and infrastructure-as-code familiarity.
Experience securing AI/LLM-powered products or working with sensitive financial data.
Familiarity with compliance frameworks (SOC 2, GDPR) as they relate to product security.
Contributions to CTFs, bug bounty, open-source security tools, or security community involvement.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Jump
Explore Top Companies in this Space
Zocks
FinTech / AI Assistant / Wealth Management / SaaS
HireLago
Job Listings / Recruitment / Human Resources / SaaS
Regal Realms
PropTech / Real Estate / Luxury Hospitality / Property Management
Hustler Marketing
Digital Marketing / Small Business Tools / SaaS / Online Advertising
Jump is an enterprise-grade artificial intelligence platform engineered to orchestrate massive-scale workflow automation for wealth managers and financial advisory firms. Operating as a highly integrated, AI-native digital ecosystem, the company eliminates the massive operational friction of manual administrative tasks by seamlessly transcribing client meetings, extracting critical financial data, and automatically generating compliance-ready documentation. Moving beyond legacy dictation tools, Jump securely integrates directly into a firm's existing tech stack—including industry-standard CRMs like Salesforce, Wealthbox, and Redtail—to deploy autonomous data synchronization. Under the hood, their sophisticated natural language processing (NLP) engine parses complex financial dialogue in real-time, instantly converting client conversations into structured tasks and actionable insights. What sets Jump apart is its uncompromising dedication to frictionless operational agility; by bridging the gap between deep client relationship management and hyper-efficient AI execution, the platform empowers financial professionals to reclaim thousands of hours, dramatically scale their advisory capacity, and eliminate administrative bottlenecks.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.

