Senior Application Security Engineer

Cybersecurity Jobs

Boston (MA)

On-site

USD 110,000 - 315,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Annual discretionary bonuses
Benefits package

Job summary

Arrowstreet Capital is seeking a Senior Application Security Engineer to embed security controls across the software development lifecycle and CI/CD pipelines. The role emphasizes building a modern DevSecOps ecosystem, integrating AI-driven vulnerability analysis, and advancing software supply chain security to reduce risk and improve developer velocity.

You will lead threat modeling for AI-enabled systems, implement secure SDLC policies, and collaborate with development teams to remediate

Qualifications

  • Experience in DevSecOps and secure SDLC practices.
  • Experience building dashboards for risk indicators and trends.
  • Hands-on collaboration with developers to remediate vulnerabilities.
  • Familiarity with CI/CD platforms and source control tools.

Responsibilities

  • Manage and improve pipeline security posture with a modern DevSecOps ecosystem.
  • Modernize vulnerability management with AI-driven analysis mapping risk to business impact.
  • Lead threat modeling and security reviews for AI-enabled systems.
  • Define metrics and reporting to communicate security posture to tech teams and leadership.
  • Drive security controls in CI/CD pipelines (SAST, DAST, SCA, secret detection, container scanning, API testing).
  • Advance software supply chain security with SBOM adoption and third-party risk management.

Skills

DevSecOps
security engineering
threat modeling
leadership
communication

Tools

GitHub
GitLab
Azure DevOps
Jenkins
SAST
DAST
SCA

Job description

Arrowstreet Capital is hiring a Senior Application Security Engineer to embed application security controls across the software development lifecycle and CI/CD pipelines.

Responsibilities
  • Manage and improve pipeline security posture by building a modern DevSecOps ecosystem that uses secure workflows and vulnerability management across the development lifecycle.
  • Modernize vulnerability management by integrating AI-driven analysis that maps technical risk to business impact for more informed prioritization and remediation.
  • Explore and implement responsible AI use to enhance vulnerability discovery, code review, threat modeling, risk prioritization, security monitoring, and remediation recommendations.
  • Lead threat modeling and security reviews for AI-enabled systems, including risks such as prompt injection, insecure handling of model outputs, sensitive data disclosure, model abuse, excessive agency, and data or model poisoning.
  • Define metrics and reporting that communicate the security posture and risk exposure of AI-enabled applications to technical teams and senior leadership.
  • Define and maintain secure SDLC policies, procedures, and workflows, translating them into actionable technical requirements.
  • Drive security controls in CI/CD pipelines, including SAST, DAST, SCA, secret detection, container scanning, and API testing.
  • Partner with development teams to explain findings, risks, and remediation steps, guiding fixes using an internal risk matrix that ties attack vectors to business objectives.
  • Advance software supply chain security with dependency governance, artifact integrity, SBOM adoption, and third-party risk management.
  • Improve pipelines with automated vulnerability and risk measurement, and implement promotion guardrails that balance effective risk management with delivery speed.
  • Support incident response for application and pipeline security events.
Requirements
  • Ability to leverage frontier AI models to enhance secure code scanning, vulnerability discovery, and application penetration testing.
  • Experience in application security, DevSecOps, secure SDLC, vulnerability management, or security engineering.
  • Experience building advanced dashboards for key risk indicators, trends, and actionable insights for technical and business stakeholders.
  • Hands-on experience collaborating with developers to remediate vulnerabilities.
  • Proficiency with CI/CD platforms and source control tools, including GitHub, GitLab, Azure DevOps, Jenkins, etc.
  • Use experience with application security testing tools: SAST, DAST, SCA, container scanning, API testing, etc.
  • Experience conducting security reviews of application architectures and APIs to identify design weaknesses, vulnerabilities, and potential attack paths.
  • Familiarity with modern architectures such as microservices, containers, APIs, and cloud-native apps.
  • Programming/scripting experience: Python, PowerShell, Bash, C#, Java, JS/TS, Ruby, etc.
  • Working knowledge of AWS/Azure cloud security concepts.
  • Experience developing technical documentation and secure coding guides.
  • Effective communication of technical security concepts.
  • Strong collaboration and relationship-building skills.
  • Ability to influence secure development practices and drive adoption.
  • Adaptability to pivot strategy or priorities when facing technical challenges or evolving scope.
  • Risk-based mindset that accounts for both business and delivery needs.
  • Initiative and independent leadership with strong project management.
  • Analytical and detail-oriented with excellent problem solving.
  • Thrives in fast-paced, multi-team environments.
  • Metrics-driven approach to program effectiveness.
  • Clear written and verbal communication of vulnerabilities and remediation.
  • Passion for enabling secure development through automation, training, and scalable processes.
  • Familiarity with frameworks/standards: NIST, CIS, ISO 27001, SOC 2, PCI DSS.
  • Some knowledge of application security risks and frameworks: OWASP Top 10, CWE/SANS 25, secure coding, and threat modeling.
  • Developer-first tools and integration (pull requests, issue tracking, IDEs) preferred.
  • Threat modeling methodologies such as STRIDE, attack trees, and agile models.
  • Experience with containers and cloud-native platforms (desired): Docker, Kubernetes, ECS/EKS/AKS/OpenShift.
  • Relevant certifications are an asset: CSSLP, CISSP, GWAPT, GWEB, OSWE, and AWS/Azure Security.
Technology Focus
  • AI-driven analysis, frontier AI models
  • SAST, DAST, SCA, secret detection, container scanning, API testing
  • CI/CD pipelines, GitHub, GitLab, Azure DevOps, Jenkins
  • Python, PowerShell, Bash, C#, Java, JS/TS, Ruby
  • AWS/Azure cloud security concepts; microservices, containers, APIs, cloud-native apps
  • SBOM, dependency governance, artifact integrity, third-party risk management
  • NIST, CIS, ISO 27001, SOC 2, PCI DSS; OWASP Top 10, CWE/SANS 25
  • Threat modeling: STRIDE, attack trees, agile models
  • Docker, Kubernetes, ECS/EKS/AKS/OpenShift
Compensation
  • $110,000 - $315,000 per year
Location
  • Boston, MA (onsite)
Additional Information
  • Total compensation approach includes base salaries, annual discretionary bonuses, and a benefits package.
  • Base salary placement within the range varies based on relevant experience and qualifications, including relevant certifications/credentials/education, role scope, and other factors.
  • The salary range is an estimate; additional compensation details will be communicated during recruitment.
  • Arrowstreet Capital provides reasonable accommodations for qualified individuals with disabilities; contact them to discuss accommodation needs during the employment process.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Arrowstreet Capital, Limited Partnership • Boston (MA)

On-site
USD 110,000 - 315,000
Senior Application Security Engineer
Senior Application Security Engineer

Arrowstreet Capital, Limited • Boston (MA)

On-site
USD 110,000 - 315,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Arrowstreet Capital, Limited Partnership • Boston (MA)

On-site
USD 110,000 - 315,000
Senior Application Security Engineer
Senior Application Security Engineer

Lever, Inc. • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Senior Software Engineer - Investment Data Systems
Senior Software Engineer - Investment Data Systems

Arrowstreet Capital, Limited Partnership • Boston (MA)

On-site
USD 95,000 - 165,000
Discretionary bonuses
Robust benefits package
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital • Reno (NV)

On-site
USD 111,000 - 144,400
Profit-sharing bonus
401(k) with employer match
Comprehensive health insurance
Senior Software Engineer - Investment Platform Engineering
Senior Software Engineer - Investment Platform Engineering

Arrowstreet Capital, Limited Partnership • Boston (MA)

On-site
USD 135,000 - 325,000
Technology Business Management and Analytics
Technology Business Management and Analytics

Arrowstreet Capital, Limited Partnership • Boston (MA)

On-site
USD 115,000 - 290,000
Senior AI Platform Engineer
Senior AI Platform Engineer

Arrowstreet Capital, Limited Partnership • Boston (MA)

On-site
USD 195,000 - 325,000
Competitive compensation package
Senior Network Security Engineer
Senior Network Security Engineer

Arrowstreet Capital, Limited Partnership • Boston (MA)

On-site
USD 110,000 - 315,000