Senior Application Security Engineer

Cybersecurity Jobs

Hoboken (NJ)

On-site

USD 160,000 - 200,000

Full time

13 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

TripleLift in Hoboken, NJ is seeking a Senior Application Security Engineer to strengthen secure software development across engineering, platform, cloud infrastructure, and security.

You will build and maintain a global security program aligned to NIST CSF, scale testing with SAST, DAST, and code-review, and promote an SDLC that supports secure development and deployment.

Qualifications

  • 5+ years in application security or related field.
  • Strong secure coding practices and remediation guidance for developers.
  • Experience with GHAS including Code Scanning, Secret Scanning, Dependency Review.
  • Proficiency with SAST, DAST, and SCA tools (CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode).
  • Hands-on security testing in CI/CD pipelines and code reviews.
  • Threat modeling and security reviews across design/architecture.
  • Security code reviews in Python, Java, TypeScript, and Go.
  • Knowledge of NIST CSF, PCI, SOC2, HITRUST, ISO 27001/2; strong AWS security controls.
  • Independent, proactive, and capable of multi-priority delivery.

Responsibilities

  • Build and maintain a global security compliance program aligned to NIST CSF.
  • Scale application security with automated security testing in SAST, DAST, and code-review tools.
  • Promote a secure SDLC and remediation activities.
  • Automate security testing in CI/CD pipelines and maintain integrations.
  • Drive adoption of GHAS across repositories: code scanning, secret scanning, dependency review.
  • Participate in threat modeling and architecture reviews to identify risks early.
  • Coordinate vulnerability management and threat-hunting activities.
  • Own penetration testing and vulnerability assessments for apps and infrastructure.
  • Monitor/apply response to application-layer threats; secure APIs and business logic.
  • Educate engineers with secure coding guidelines and secure development training.
  • Evaluate and improve security program maturity via tools and processes.

Skills

NIST CSF
GHAS
SAST
DAST
SCA
CodeQL
Burp Suite
OWASP ZAP
Snyk
Checkmarx
Veracode
CI/CD
OWASP Top 10
CWE
Python
Java
TypeScript
Go
AWS IAM
AWS VPC
AWS KMS
GuardDuty
CloudTrail
Threat modeling

Tools

GitHub Advanced Security (GHAS)
CI/CD tooling

Job description

TripleLift is hiring a Senior Application Security Engineer to strengthen secure software development across engineering, platform, cloud infrastructure, and security.

Responsibilities
  • Build and maintain a global security compliance program aligned to NIST CSF.
  • Scale application security by developing automated security testing using enterprise SAST, DAST, and code-review tools.
  • Promote an SDLC that supports secure application development and infrastructure deployment, including secure coding remediation activities.
  • Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations.
  • Administer and drive adoption of GitHub Advanced Security (GHAS) across engineering repositories, including:
    • Code scanning
    • Secret scanning
    • Dependency review
  • Participate in threat modeling and design or architecture specification reviews to identify and mitigate risks early in the SDLC.
  • Coordinate stakeholders to develop and implement a vulnerability management program and support threat-hunting activities.
  • Own and conduct internal penetration testing and vulnerability assessments for applications and infrastructure, and validate outcomes from third-party pentest engagements.
  • Monitor and respond to application-layer threats, including API abuse, business logic flaws, and common web vulnerabilities.
  • Collaborate with product and engineering teams to ensure security is built into software design and architecture.
  • Improve application security posture by implementing authentication, authorization, and data protection mechanisms.
  • Enhance and facilitate security incident handling activities.
  • Evangelize security best practices by providing education and awareness for employees; develop and implement secure coding guidelines and run secure development training for engineers.
  • Evaluate and continuously improve security program maturity by deploying and managing security tools and processes.
Requirements
  • 5 years minimum experience in application security, secure software development, security engineering, or a related role.
  • Strong understanding of secure coding practices and ability to guide developers through remediation strategies.
  • Experience with GitHub Advanced Security (GHAS) including:
    • Code Scanning (SAST)
    • Secret Scanning
    • Dependency Review
  • Proficiency with SAST, DAST, and SCA tools (examples include CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode).
  • Hands‑on experience integrating security testing tools into CI/CD pipelines for automated scanning, including designing and building pipeline workflows.
  • Hands‑on penetration testing and offensive security experience across web applications, APIs, or cloud infrastructure.
  • Knowledge of common application security vulnerabilities and mitigations including OWASP Top 10 and CWE, with a focus on business logic flaws and API security.
  • Ability to perform threat modeling and participate in design or architecture spec reviews to assess security risks.
  • Experience conducting security code reviews across programming languages such as Python, Java, TypeScript, and Go.
  • Security fundamentals mapped to cybersecurity and compliance frameworks, especially NIST CSF (also includes PCI, SOC2, HITRUST, ISO 27001/2, or similar).
  • Strong understanding of AWS security services and controls (including IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, including deploying security tools within them.
  • Ownership mindset with the ability to work independently with minimal oversight, delivering results in a fast‑paced environment while balancing multiple priorities.
  • Continually learns and adapts, valuing correctness, efficiency, and constructive feedback.
Technologies
  • NIST CSF
  • GitHub Advanced Security (GHAS): Code Scanning, Secret Scanning, Dependency Review
  • SAST, DAST, SCA
  • CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode
  • CI/CD
  • OWASP Top 10, CWE
  • Python, Java, TypeScript, Go
  • PCI, SOC2, HITRUST, ISO 27001/2
  • AWS: IAM, VPC, KMS, GuardDuty, CloudTrail
  • OSCP, GWAPT, CISSP, CISA
  • Claude
Preferred
  • Experience in ad-tech or programmatic advertising, or another high‑scale real‑time environment.
  • Familiarity with using AI/LLM-based tools (for example, Claude or similar) for threat intelligence, alert triage, or security automation.
  • Cybersecurity certification such as OSCP, GWAPT, CISSP, CISA, etc.
Location and Compensation
  • Location: Hoboken, NJ (onsite)
  • Salary: USD 160,000 - 200,000 per year
Life at TripleLift
  • Team culture focused on people who like who they work with and aim to help everyone around them improve.
  • Continuous innovation and fast‑moving execution.
  • Learn more via TripleLift’s LinkedIn Life page.
People, Culture and Community Initiatives
  • Commitment to building a culture that helps people feel connected, supported, and empowered.
  • Investment in employees and encouragement of curiosity, shared values, and meaningful connections across teams and communities.
  • Focus on ensuring talent of every background, viewpoint, and experience can be hired, belong, and develop.
  • People, Culture, and Community initiatives designed to help everyone thrive and feel a sense of belonging.
Privacy Policy
  • See TripleLift and 1plusX websites for Privacy Policies.
  • TripleLift does not accept unsolicited resumes from recruitment search firms.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

TripleLift • New London (NY)

On-site
USD 125,000 - 165,000
Medical, Dental & Vision Plans
Flexible PTO
401k with employer match
Senior Director, Security
Senior Director, Security

TripleLift • New York (NY)

On-site
USD 165,000 - 220,000
Medical, Dental & Vision Plans
Flexible PTO
401k w/ employer match
Senior Application Security Engineer
Senior Application Security Engineer

TripleLift • New York (NY)

On-site
USD 180,000 - 230,000
Senior Staff Engineer
Senior Staff Engineer

TripleLift • New York (NY)

On-site
USD 150,000 - 190,000
Medical, Dental & Vision plans
Flexible PTO
401k with employer match
+1
Senior Data Engineer
Senior Data Engineer

TripleLift • New York (NY)

On-site
USD 130,000 - 170,000
Medical, Dental & Vision Plans
Flexible PTO
401k w/ employer match
+1
Senior Data Engineer
Senior Data Engineer

TripleLift • Toronto (OH)

On-site
USD 140,000 - 180,000
Platform Partnerships Director
Platform Partnerships Director

TripleLift • New York (NY)

On-site
USD 120,000 - 160,000
Medical, Dental & Vision Plans
Flexible PTO
401k with employer match
Business Development Representative
Business Development Representative

TripleLift • New York (NY)

On-site
USD 55,000 - 75,000
Medical, Dental & Vision Plans
Flexible PTO
401k with employer match
Trading Specialist
Trading Specialist

TripleLift • Chicago (IL)

On-site
USD 60,000 - 80,000
Medical, Dental & Vision Plans
Flexible PTO
401k w/ employer match
Senior AppSec Engineer: Drive Secure Software at Ad Tech Scale
Senior AppSec Engineer: Drive Secure Software at Ad Tech Scale

TripleLift • New London (NY)

On-site
USD 125,000 - 165,000
Medical, Dental & Vision Plans
Flexible PTO
401k with employer match