First Dedicated Security Engineer

vibehackers

New York (NY)

On-site

USD 220,000 - 235,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Paid holidays
Medical insurance
Dental insurance
Company 401(k)
NYC office in Manhattan
Lunch and snacks provided
Health concierge
Employee Assistance Program

Job summary

Savvy Wealth, based in NYC, is seeking a Senior Application Security Engineer to lead hands-on AppSec across product and SaaS tooling. You will own vulnerability management, CI/CD security tooling, and cloud hardening while building guardrails for AI-assisted development and non-technical workflows.

The role requires 5+ years in security engineering, strong code literacy, and the ability to influence both technical and non-technical teams in a fast-paced startup environment.

Qualifications

  • 5+ years in hands-on application security, preferably in a product or small security team.
  • Experience embedding security into CI/CD workflows and development lifecycle.
  • Ability to read, write, and remediate code, not just surface findings.
  • Strong cross-functional communication with technical and non-technical stakeholders.
  • Practical SaaS security experience including OAuth reviews and configuration hardening.

Responsibilities

  • Own vulnerability management end-to-end across product, codebases, and cloud infrastructure.
  • Build and operate the AppSec tooling pipeline with CI secrets scanning, SCA, and SAST rollout.
  • Set security hygiene standards and enforce human review on AI-generated code paths.
  • Partner with AI teams to design guardrails for AI-assisted development and vibe coding.
  • Secure SaaS configurations and third-party integrations across platforms (Google Workspace, GitHub, Slack).
  • Help establish conditional access and identity controls (SSO, MFA, device posture).
  • Define cloud/SaaS baselines and contribute to detection, response, and IR readiness.
  • Communicate risk and remediation tradeoffs clearly to stakeholders.

Skills

AppSec engineering
Vulnerability management
CI/CD security
SAST / SCA / Secrets scanning
Cloud security (AWS/GCP)
Threat modeling
Security tooling

Tools

GitHub
SAST tooling
SCA tooling
Secrets scanning
OAuth reviews
Cloudflare

Job description

Directly addresses vibe coding: building guardrails and secure defaults for AI-assisted and non-technical "vibe" coding workflows.

About the Role

Senior Application Security Engineer based in NYC as Savvy Wealth's first dedicated security hire. Hands-on role executing AppSec strategy across product and SaaS tooling, focusing on vulnerability management, CI/CD/security tooling, cloud/SaaS hardening, and building guardrails for AI-assisted and 'vibe' coding workflows.

Job Description
Role

Savvy Wealth is hiring a Senior Application Security Engineer to be the company’s first dedicated security hire at their NYC headquarters. This is a hands‑on engineering role focused on technical AppSec work — finding and remediating vulnerabilities across product, codebases, cloud infrastructure, and the SaaS stack — and designing security guardrails for AI-assisted development.

Key Responsibilities
  • Own vulnerability management end-to-end: identify, triage, prioritize by real-world risk, and drive remediation to closure across product, codebases, and cloud infrastructure (AWS, GCP, Cloudflare).
  • Build and operate the AppSec tooling pipeline: secrets scanning in CI and at the git layer, SCA/dependency scanning with triage SLAs, and SAST rollout for sensitive repositories.
  • Set and enforce security hygiene standards, including code review processes that account for AI-generated code and require human review on security-sensitive paths.
  • Partner with the internal AI team to design guardrails for AI-assisted development and non-technical “vibe” coding: sanctioned tooling, data handling boundaries, dependency vetting, and secure defaults.
  • Secure SaaS configurations and integrations (OAuth reviews, third-party apps) across platforms such as Google Workspace, GitHub, Rippling, and Slack.
  • Help establish conditional access and identity-layer controls (SSO, phishing-resistant MFA, managed-device posture) in partnership with IT.
  • Define cloud and SaaS configuration baselines and contribute to detection and response readiness and incident response when needed.
  • Communicate risk, remediation plans, and tradeoffs clearly to both technical and non-technical stakeholders.
Requirements
  • 5+ years of hands-on security engineering experience, with significant time in application or product security within a small security team.
  • Strong software engineering fundamentals: ability to read, write, and remediate code (not just file findings).
  • Proven ability to enforce security across technical and non-technical teams without obstructing workflows.
  • Experience embedding security into existing workflows and CI/CD (GitHub-centric).
  • Deep familiarity with AppSec toolchain: secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration.
  • Practical experience securing SaaS environments: OAuth and third-party app review, configuration hardening, least-privilege access design.
  • Working knowledge of cloud security (AWS and/or GCP) and edge/CDN security (Cloudflare).
  • Risk-based mindset that prioritizes exploitability and high-value remediation.
  • Strong communication and writing skills and ability to work independently in a fast-paced environment.
Nice to have
  • Experience building security programs at early-to-mid stage companies.
  • Experience with SaaS security posture management (CSPM) or identity threat detection.
  • Familiarity with securing LLM-based tooling, agentic workflows, or internal AI platforms.
  • Detection engineering experience (SIEM/MDR, high-signal alerting).
  • Fintech or financial services experience.
  • Offensive security background (pentesting, bug bounty, red team).
  • Competitive salary and equity package
  • Compensation Range: $220,000 - $235,000
  • Medical, dental, and vision plans
  • Company 401(k), commuter benefits, HSA/FSA plans
  • NYC office in Manhattan; lunch and snacks provided
  • Access to virtual mental health care (Spring Health) and health concierge (Rightway)
  • Employee assistance program (Guardian WorkLifeMatters)

AWS GCP Cloudflare GitHub Google Workspace Rippling Slack Claude CI/CD SAST SCA Secrets scanning OAuth SIEM MDR LLM-based tooling Agentic workflows

Skills

Application Security Vulnerability Management Secure Coding / Code Review CI/CD Security Integration Secrets Management Dependency Management / SCA SAST Cloud Security SaaS Security Identity & Access Management Detection & Response Incident Response Risk-based Prioritization Cross-functional Collaboration Communication Technical Writing Security Program Building

Experience Level

Senior

USD 220,000 - 235,000/year

Employment Type

Full-time

  • Paid company holidays
  • Medical insurance
  • Dental insurance
  • Company 401(k)
  • NYC office (Manhattan)
  • Lunch and snacks provided
  • Health concierge (Rightway)
  • Employee Assistance Program (Guardian WorkLifeMatters)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

savvy • New York (NY)

On-site
USD 150,000 - 210,000
Competitive salary and equity package
Unlimited PTO + holidays
Medical, dental, and vision plans
+1
Senior Application Security Engineer
Senior Application Security Engineer

Savvy Wealth • New York (NY)

On-site
USD 150,000 - 210,000
Equity
Unlimited PTO
Medical/Dental/Vision
+5
Senior Developer Experience Engineer
Senior Developer Experience Engineer

Savvy Wealth • New York (NY)

On-site
USD 180,000 - 235,000
Competitive salary and equity package
Unlimited PTO + paid holidays
Comprehensive medical, dental, vision
Senior Agent Harness Engineer
Senior Agent Harness Engineer

Savvy Wealth • New York (NY)

On-site
USD 180,000 - 235,000
Competitive salary and equity package
Unlimited PTO + paid company holidays
Comprehensive medical, dental, vision
Senior AppSec Engineer: First Dedicated Security Hire in NYC
Senior AppSec Engineer: First Dedicated Security Hire in NYC

vibehackers • New York (NY)

On-site
USD 220,000 - 235,000
Paid holidays
Medical insurance
Dental insurance
+5
Senior Engineer - Technical Staff
Senior Engineer - Technical Staff

Savvy Wealth • New York (NY)

On-site
USD 175,000 - 230,000
Unlimited PTO
Medical, dental, and vision plans
401(k) plan
+2
Senior Agent Harness Engineer
Senior Agent Harness Engineer

Savvy-Wealth • New York (NY)

On-site
USD 180,000 - 260,000
Salary + equity
Unlimited PTO
Medical insurance
+5
Senior Agent Harness Engineer
Senior Agent Harness Engineer

Savvy Wealth, Inc. • Northern (KY), New York (NY)

Hybrid
USD 140,000 - 190,000
Competitive salary and equity
Unlimited PTO
Medical, dental, and vision plans
+1
Senior AppSec Engineer — AI-Driven SaaS Security Leader
Senior AppSec Engineer — AI-Driven SaaS Security Leader

savvy • New York (NY)

On-site
USD 150,000 - 210,000
Competitive salary and equity package
Unlimited PTO + holidays
Medical, dental, and vision plans
+1
Senior Engineering Manager
Senior Engineering Manager

Savvy Wealth • United States

Hybrid
USD 240,000 - 265,000
Competitive salary and equity package
Unlimited PTO + holidays
Medical, dental, vision plans
+1