Application Security Engineer

Cybersecurity Jobs

New York (NY)

On-site

USD 75,000 - 135,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

The City of New York’s Technology & Innovation team seeks an Application Security Engineer, onsite in Brooklyn, NY, to protect critical digital services within the Software Security Assurance Program (SSAP).

You will conduct hands-on security testing (SAST/DAST/SCA), threat modeling, and secure coding guidance while collaborating with agency development teams to reduce vulnerabilities before deployment.

Qualifications

  • Bachelor's degree with four years of related experience or an equivalent combination of education and experience.
  • 2–4 years of professional experience in application security, penetration testing, or software engineering with a focus on application security.
  • Hands-on experience configuring, operating, and tuning SAST, DAST, and SCA tools (e.g., Veracode, Checkmarx, Snyk, Burp Suite) and working with CI/CD pipelines.

Responsibilities

  • Execute application security assessments within the SSAP to ensure web apps, APIs, and mobile systems meet city security standards before release.
  • Run SAST, DAST, and manual reviews to validate vulnerabilities, reduce false positives, and prioritize issues by risk.
  • Operate SCA tools to monitor open-source components and drive remediation.
  • Perform threat modeling and logic reviews during design to surface security flaws early.
  • Provide remediation guidance and secure coding advice to agency development teams.

Skills

SAST
DAST
SCA
Threat modeling
CI/CD pipelines
GitHub Actions
Azure DevOps
GitLab
Python
Java
JavaScript/TypeScript
C#/.NET
OWASP Top 10

Education

Baccalaureate degree
4 years of full-time experience or equivalent

Tools

Veracode
Checkmarx
Snyk
Burp Suite

Job description

The City of New York’s Technology & Innovation team is seeking an Application Security Engineer to help protect critical digital services. In this onsite role based in Brooklyn, NY, you will assess software security risk across web applications, APIs, and mobile systems, supporting the Software Security Assurance Program (SSAP) through analysis, validation, and remediation guidance.

The position involves hands-on security testing using SAST, DAST, and SCA, along with threat modeling and manual review work during the design and development lifecycle. You will also collaborate closely with agency development teams to reduce vulnerabilities before deployment and improve secure development practices.

What You’ll Do
  • Execute application security assessments within the SSAP to confirm that web applications, APIs, and mobile systems meet city security standards before release.
  • Run SAST, DAST, and manual security reviews to validate vulnerabilities, reduce false positives, and prioritize issues by operational risk.
  • Operate Software Composition Analysis (SCA) tools to monitor and track open-source and third-party component vulnerabilities and drive remediation.
  • Perform structured threat modeling and logic reviews on assigned applications during the design phase to surface security flaws early.
  • Act as a technical point of contact for agency development teams, providing clear and actionable remediation guidance and secure coding advice.
  • Assist with configuring and integrating automated security scanning tools into CI/CD pipelines for DevSecOps workflows (including GitHub Actions, Azure DevOps, and GitLab).
  • Conduct security reviews for third-party vendor solutions and web APIs (including OAuth and REST) to verify alignment with city security policies and industry best practices.
  • Contribute to maintaining secure coding guidelines, application security documentation, and training materials for agency development staff.
Requirements
  • A baccalaureate degree from an accredited college, plus four years of satisfactory full-time experience related to projects and policies required for the position; or an equivalent combination of education and experience.
  • 2–4 years of dedicated professional experience in application security, penetration testing, or software engineering with a focus on application security.
  • Hands-on experience configuring, operating, and tuning SAST, DAST, and SCA tools (for example: Veracode, Checkmarx, Snyk, Burp Suite) and experience working with CI/CD pipelines.
  • Strong practical knowledge of OWASP Top 10, CWE flaw types, manual vulnerability verification, and secure coding concepts in languages such as Python, Java, JavaScript/TypeScript, or C#/.NET.
  • Working knowledge of web API security principles (including REST and OAuth 2.0) and basic application security controls in cloud environments (AWS, Azure, or GCP).
  • Experience conducting application threat modeling and architectural flaw reviews.
  • Strong verbal and written communication skills, with demonstrated ability to explain technical vulnerabilities and remediation steps to developers and project teams.
  • Mid-level application security or testing certifications are a plus, such as GIAC GWAPT, GWEB, eWPT, CompTIA PenTest+, or CSSLP.
Tools and Technologies
  • SAST, DAST, SCA, Software Composition Analysis (SCA), SSAP
  • Veracode, Checkmarx, Snyk, Burp Suite
  • GitHub Actions, Azure DevOps, GitLab
  • OAuth, REST, OAuth 2.0
  • AWS, Azure, GCP
  • Python, Java, JavaScript/TypeScript, C#/.NET
  • OWASP Top 10, CWE
Work Schedule

Day hours are expected, but due to technical duties of a 24/7 operation, candidates may be required to work various shifts, including weekends and/or nights/evenings.

Compensation

USD 75,000 - 135,000 per year.

Additional Information
  • Residency requirement: New York City residency is not required.
  • Public Service Loan Forgiveness: As a prospective employee of the City of New York, you may be eligible for federal loan forgiveness programs and state repayment assistance programs. More information is available at https://studentaid.gov/pslf/.
  • Equal opportunity: The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment free from discrimination and harassment based on legally protected status or protected characteristic.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

City of New York • New York (NY)

On-site
USD 110,000 - 160,000
Application Security Engineer
Application Security Engineer

SmartRecruiters, Inc. • New York (NY)

On-site
USD 125,000 - 150,000
Application Developer
Application Developer

City of New York • New York (NY)

On-site
USD 90,000 - 140,000
Application Security Engineer — SAST, DAST & CI/CD
Application Security Engineer — SAST, DAST & CI/CD

Cybersecurity Jobs • New York (NY)

On-site
USD 75,000 - 135,000
Senior Technical Program Manager
Senior Technical Program Manager

New York City Police Department • New York (NY)

On-site
USD 90,000 - 130,000
Health insurance
Pension
Paid annual leave
+4
P/T Quality Assurance Auditor
P/T Quality Assurance Auditor

City of New York • New York (NY)

On-site
USD 90,000 - 130,000
Senior Cyber Cloud Security Engineer
Senior Cyber Cloud Security Engineer

City of New York • New York (NY)

On-site
USD 120,000 - 170,000
Senior Application Developer
Senior Application Developer

NYC Department of Citywide Administrative Services • New York (NY)

On-site
USD 120,000 - 180,000
55a Program
Public Service Loan Forgiveness
Application Developer
Application Developer

SmartRecruiters, Inc. • New York (NY)

On-site
USD 100,000 - 150,000
Cyber Security Analyst
Cyber Security Analyst

City of New York • New York (NY)

On-site
USD 100,000 - 140,000