HimalayasHimalayas logo
wexWE

Sr. Application Security Architect

WEX Inc. is a global commerce platform that simplifies the business of running a business by offering personalized technology solutions for employee benefits, mobility and fleet management, and corporate payments.

wex

Employee count: 5000+

Salary: 143k-189k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Job Summary

Wex, Inc. is looking for a Sr. Application Security Architect with broad software development and application security experience. This individual would be responsible for designing, guiding, and assessing security solutions in software projects to ensure that security is built in from the beginning. With the assistance of tools including SAST, DAST and SCA, perform assessments of software projects to identify security issues and guide teams to effective remediations.

About Us

WEX is a global leader in financial technology solutions, based in Portland, Maine, United States, with over 6,000 WEXers distributed in over 40 countries. We simplify the complexities of payment systems across continents and industries like Fleet, Corporate Payments, and Benefits. We look to manage employee benefits, streamline how companies pay and get paid by suppliers, save on fuel costs, or modernize how companies manage their fleet, WEX solutions reduce the administrative burdens.

Who Are We?

We’re the Global Product Security Team at WEX, responsible for enabling a modern and effective Secure Software Development Lifecycle throughout WEX.. We partner closely with internal teams and customers to assure WEX operates in a secure and compliant manner. Our team holds itself to a high-standard and we collaborate closely with one another to ensure strong, reliable and effective relationships. We own our results and we take pride of ownership in everything we do.

We need help!

Changing the world isn’t easy, and we have a lot of work ahead of us. From securing applications, data centers and cloud resources, we’ve got more work than we can handle and we’re looking for great people to come along for the ride.

Who are you?

Culturally, you’re:

  • A highly motivated security architect who loves working on small, high performing teams that interface with the entire enterprise

  • A collaborative, solid communicator who works well with your team and stakeholders to drive projects from inception to completion

  • Someone who cares deeply for team results but is able to work independently to deliver high quality solutions for projects and operational tasks

  • Comfortable balancing the need to move fast with the realities of working in a highly regulated organization

  • Passionate about security, but pragmatic about delivering business value

  • Customer focused - whether it’s internal teams that we’re supporting or the WEX partner, you prioritize ensuring they have a great experience with WEX and our team

  • A skilled worker that has the motivation, expertise, and work ethic to operate independently across global time zones, and who is able to complete tasks and deliverables with minimal oversight

  • A strong leader who builds consensus and drives change through buy-in and education rather than mandates

  • Work closely with development teams on securing Wex's applications

  • Able to mentor other engineers & architects on your team and other teams both technically and professionally

  • Champion of a shift-left and DevSecOps approach to security, but tenacious enough to build such a program from the ground up

  • A lifelong learner that is excited by new technologies and challenges

Technically, you:

  • Are a Subject Matter Expert in software development and software security, particularly with web applications, APIs, mobile apps and enterprise applications delivered in a SaaS model.

  • Provide leadership and help shape the WEX application security program and strategy

  • Have a deep understanding of web application attacks and mitigations

  • Think strategically about and research the latest trends in identity management, software attacks and mitigations

  • Mentor and lead threat modeling sessions, focused primarily on teaching others to effectively practice effective and lightweight threat modeling

  • Train other team members in risk based analysis of issues uncovered in manual and automated secure code reviews, and commercial static and dynamic application security scanning tools (SAST, DAST, SCA, etc)

  • Do web application and mobile app penetration testing

  • Deliver actionable security guidance to project teams

  • Lead Security Development Lifecycle efforts, coordinating other security architects, security champions and project teams in performing secure architecture reviews, secure code reviews, threat models and penetration testing through the software development lifecycle;

  • Keeps abreast of security industry best practices and OWASP recommendations utilizing knowledge to contribute to remediation efforts across the platform, as well as security policies and procedures;

  • Actively identify and collaborate with security champions in the development and engineering organization to scale security expertise and awareness.

  • Write and oversee the creation of application security standards and guidelines and assist in the implementation of these standards across the organization

  • Deep experience working with compliance and regulatory frameworks such as PCI-DSS, HIPAA/HITRUST, SOX, GDPR, NIST, etc.

At a minimum, you

  • Have 8+ years of progressive experience in software development and software architecture

  • Have 3+ years experience with software security or information security

  • Have 3+ years experience with application and container security tools such as SAST, DAST, SCA, IaC scanning and container image scanning, including integrating them to build and ticketing tools.

  • Are an expert at identifying, exploiting and mitigating common application security issues, ie OWASP Top10,

  • Are an expert at customer identity and related technologies, including OpenID Connect, OAuth 2.0, SAML 2.0

  • Are able to troubleshoot security issues within a complex on-prem and multi-cloud environment

  • A degree in Business, Computer Science or equivalent combination of education and relevant experience.

  • Have experience working closely with many teams across departmental and business unit boundaries and can effect change in such complex environments

  • Can commit and deliver on very specific project/delivery timelines with minimal supervision

  • Have excellent communication skills, both written and verbal

It would be nice if you have

  • Security certifications such as CISSP, CEH, OSCP, GWAPT or similar and cloud certifications

  • Have an understanding of modern CI/CD approaches and tooling, preferably with multiple toolsets such as Azure DevOps, GitHub Actions, Jenkins and others

  • Hands on experience with IAM tools like Okta, Auth0, Ping or similar

  • Experience with designing and securing container technologies - Kubernetes, Docker, EKS, ECS, AKS, service mesh

  • Experience with infrastructure as code (Terraform, CloudFormation, …) and automation

  • 3+ years of cloud hosted applications and public cloud experience (IaaS, PaaS, FaaS, SaaS)

  • Experience working on agile teams

The base pay range represents the anticipated low and high end of the pay range for this position. Actual pay rates will vary and will be based on various factors, such as your qualifications, skills, competencies, and proficiency for the role. Base pay is one component of WEX's total compensation package. Most sales positions are eligible for commission under the terms of an applicable plan. Non-sales roles are typically eligible for a quarterly or annual bonus based on their role and applicable plan. WEX's comprehensive and market competitive benefits are designed to support your personal and professional well-being. Benefits include health, dental and vision insurances, retirement savings plan, paid time off, health savings account, flexible spending accounts, life insurance, disability insurance, tuition reimbursement, and more. For more information, check out the "About Us" section.Pay Range: $143,400.00 - $189,100.00

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Salary

Salary: 143k-189k USD

Education

Bachelor degree

Experience

8 years minimum

Experience accepted in place of education

Location requirements

Hiring timezones

United States +/- 0 hours

About wex

Learn more about wex and their company culture.

View company profile

WEX Inc. is a global commerce platform that simplifies the business of running a business. Many of our customers face the challenge of managing complex operational processes due to the rapid pace of regulatory, economic, and societal change worldwide. They are often stretched thin and lack the in-house expertise to solve these intricate problems. This is why WEX offers personalized technology solutions designed to simplify employee benefits, mobility and fleet management, and accounts payable and receivables processes. From our origins as a pioneer in fleet card payments in 1983, we have expanded our scope to become a multi-channel provider of corporate payment solutions, helping businesses navigate these complexities and achieve greater efficiency.

Our customers in the fleet industry, for example, need robust tools to manage fuel and maintenance expenses, ensure driver safety, and optimize operations. WEX Fleet provides them with fuel cards, telematics, and data analytics to meet these needs. For businesses involved in travel, managing cross-border payments and streamlining back-end accounting can be a significant hurdle. WEX's travel and corporate solutions, including virtual payment solutions, help these clients automate processes, reduce costs, and gain better insights into their spending. Similarly, in the healthcare sector, employers and employees alike grapple with the administration of benefits and healthcare payments. WEX Health offers a cloud-based platform to simplify the management of Health Savings Accounts (HSAs), Flexible Spending Accounts (FSAs), and other benefit plans, making it easier for millions of consumers to manage their healthcare expenses. By embedding our solutions into our customers' workflows and leveraging our expertise in data and analytics, we empower them to make smarter decisions, reduce operating costs, and ultimately, reach their full potential.

Employee benefits

Learn about the employee benefits and perks provided at wex.

View benefits

Company equity

WEX offers company equity.

Life insurance

WEX offers life insurance.

Paid sick days

WEX provides paid sick days.

Sabbatical

WEX offers sabbatical leave.

View wex's employee benefits
Claim this profilewex logoWE

wex

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

99 remote jobs at wex

Explore the variety of open remote roles at wex, offering flexible work options across multiple disciplines and skill levels.

View all jobs at wex

Remote companies like wex

Find your next opportunity by exploring profiles of companies that are similar to wex. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan