Demo

Staff Application Security Engineer

Gemini
Gemini Salary
San Francisco, CA Full Time
POSTED ON 12/27/2025
AVAILABLE BEFORE 2/2/2026
About The Company

Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in over 70 countries. Our mission is to unlock the next era of financial, creative, and personal freedom by providing trusted access to the decentralized future. We envision a world where crypto reshapes the global financial system, internet, and money to create greater choice, independence, and opportunity for all — bridging traditional finance with the emerging cryptoeconomy in a way that is more open, fair, and secure. As a publicly traded company, Gemini is poised to accelerate this vision with greater scale, reach, and impact.

The Department: Application Security

The Role: Staff Application Security Engineer

As a member of the Application Security (AppSec) team, you will share in the responsibility of protecting the company and our customers against application security threats. The AppSec team is focused on the advancement of modern application security practices and supports the engineering organization by finding, fixing, and preventing software security vulnerabilities.

As a Staff Application Security Engineer on Gemini’s AppSec team, you will work closely with security, engineering, and product teams to set technical direction and provide security recommendations while identifying security issues throughout the software development lifecycle. This includes leading high-risk secure design reviews, threat modeling, and building paved roads among other activities.

This role is required to be in person twice a week at either our San Francisco, CA or New York City, NY office.

Responsibilities

  • Own and evolve the Gemini Secure Software Development Lifecycle guardrails as an application security subject matter expert
  • Lead architecture reviews, threat modeling, code reviews, and penetration testing for high-risk applications and services
  • Research, build and drive adoption of high-signal application security automation and secure-by-default frameworks
  • Create and deliver hands-on application security training to enable engineers at scale
  • Participate in the Application Security on-call rotation and lead post-incident hardening

Minimum Qualifications

  • Proven ability to perform design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset
  • Strong background in application security best practices and familiarity with common vulnerabilities (e.g. SSRF, race conditions, privilege escalations, etc.)
  • Deep code review proficiency in Scala/JVM (preferred) or other languages and at least one of Python/Go/etc for building; able to review production services in other languages
  • Experience implementing custom detection and prevention application security controls to eliminate application security issues beyond OWASP Top 10
  • Familiarity with and ability to understand business objectives, business context, and security risk
  • Strong cross-functional communication and collaboration (Security, Engineering, and Product)
  • Typically 7-10 years of experience or equivalent impact in application security, product security, or similar roles

Preferred Qualifications

  • Experience implementing supply chain security controls (SCA, SLSA, signing, etc.)
  • Prior experience in cryptocurrency firms or highly regulated environments (PCI DSS, SOX, SOC2, ISO 27001)
  • Open-source impact such as conference talks, blogs/papers, tooling, or libraries

It Pays to Work Here

The Compensation & Benefits Package For This Role Includes

  • Competitive starting salary
  • A discretionary annual bonus
  • Long-term incentive in the form of a new hire equity grant
  • Comprehensive health plans
  • 401K with company matching
  • Paid Parental Leave
  • Flexible time off

Salary Range: The base salary range for this role is between $168,000 - $240,000 in the State of New York, the State of California and the State of Washington. This range is not inclusive of our discretionary bonus or equity package. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.

In the United States, we offer a hybrid work approach at our hub offices, balancing the benefits of in-person collaboration with the flexibility of remote work. Expectations may vary by location and role, so candidates are encouraged to connect with their recruiter to learn more about the specific policy for the role. Employees who do not live near one of our hubs are part of our remote workforce.

At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.

Salary : $168,000 - $240,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Staff Application Security Engineer?

Sign up to receive alerts about other jobs on the Staff Application Security Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$86,680 - $110,316
Income Estimation: 
$110,730 - $135,754
Income Estimation: 
$117,033 - $148,289
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Gemini

  • Gemini Seattle, WA
  • About The Company Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, a... more
  • 12 Days Ago

  • Gemini San Francisco, CA
  • About The Company Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, a... more
  • 12 Days Ago

  • Gemini York, NY
  • About The Company Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, a... more
  • 13 Days Ago

  • Gemini San Francisco, CA
  • About The Company Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, a... more
  • 13 Days Ago


Not the job you're looking for? Here are some other Staff Application Security Engineer jobs in the San Francisco, CA area that may be a better fit.

  • OpenAI San Francisco, CA
  • About The Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team... more
  • 19 Days Ago

  • GSK San Francisco, CA
  • Site Name: USA - Pennsylvania - Upper Providence, Cambridge 300 Technology Square, Philadelphia Walnut Street, Seattle Sixth Ave, South San Francisco 611 G... more
  • 29 Days Ago

AI Assistant is available now!

Feel free to start your new journey!