Senior Application Security Engineer

savvy

New York (NY)

On-site

USD 150,000 - 210,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive salary and equity package
Unlimited PTO + holidays
Medical, dental, and vision plans
401(k) and health savings account

Job summary

Savvy Wealth in NYC seeks a Senior Application Security Engineer to join our first dedicated security hire. This hands-on role enforces security hygiene, implements guardrails for AI-assisted development, and partners with the CTO and IT leadership to close vulnerabilities across product, codebases, and cloud infrastructure.

You will own vulnerability management end to end, build our AppSec tooling, set standards for code review, and collaborate with internal AI teams to keep velocity and safety

Qualifications

  • 5+ years of hands-on security engineering experience in application or product security.
  • Strong software engineering fundamentals; able to read, write, and remediate code.
  • Proven track record enforcing security across technical and non-technical teams.
  • Experience embedding security into existing workflows.
  • Deep experience with AppSec toolchain: secrets scanning, SCA, SAST, CI/CD security integration (GitHub-centric).
  • Practical experience securing SaaS environments: OAuth & third-party app review, configuration hardening, least-privilege access.

Responsibilities

  • Own vulnerability management end to end across product, codebases, and cloud (AWS, GCP, Cloudflare).
  • Build and operate AppSec tooling pipeline (secrets scanning, SCA, SAST, CI/CD).
  • Set and enforce security hygiene standards within codebases, including AI-generated code review."
  • Partner with AI team to design guardrails for AI-assisted development and secure defaults.
  • Secure the SaaS stack: review OAuth grants, third-party integrations, and misconfiguration risk.
  • Help establish conditional access and identity controls with IT (SSO, MFA, device posture).
  • Define cloud/SaaS configuration baselines for our footprint.
  • Contribute to detection and response readiness and participate in incident response as needed.
  • Work cross-functionally with Engineering, IT, and AI teams; communicate risk and roadmaps clearly.

Skills

Security engineering
Software fundamentals
AppSec tooling
SaaS security
Cloud security
AI security
Communication
Independent work

Tools

Secrets scanning
SCA
SAST
CI/CD security
GitHub

Job description

About Savvy Wealth:

Wealth management is a $545 billion industry that still runs on manual work. 75% of advisors offer no digital communication beyond email, and most still build financial plans by hand in Excel. Savvy is reinventing what it looks like to be a financial advisor. Founder Ritik Malhotra saw the fragmentation firsthand after seeking out his own advisor, and started Savvy to give independent advisors a modern, AI-native home.

Savvy is a registered investment advisor (RIA), and we partner with experienced financial advisors who want to grow without running the back office themselves. Advisors bring their book and join Savvy, running under their own brand (or ours), and Savvy earns a percentage of the assets they manage. In return, they get a true business-in-a-box: a proprietary tech platform and client portal, an in-house marketing team that helps them grow, a world-class investment management team, and a dedicated client services team that runs day-to-day operations and support. Advisors at Savvy service up to 50% more households and save 19 hours a week.

AI runs through everything we do. On the product side, Savvy Intelligence (released April 2026) is the only AI built for wealth managers that can see a client's complete financial picture. Internally, everyone at Savvy uses Claude and is encouraged to experiment with it, backed by a dedicated AI enablement team and a RevOps org building agents in-house.

The trajectory is steep and it's still early. We're a Series C company with 170+ people, $200M raised, and $100M ARR in sight this year. Inc. ranked us the No. 1 fastest-growing financial services company in America in 2026. Come build the next stage with us!

Recognition:

We're a Certified Great Place to Work and have been honored for our culture and our growth:

  • Newsweek's America's Greatest Startup Workplaces (2026)

  • Fortune Best Workplaces in New York

  • Great Place to Work Certified

The Role

We are seeking a Senior Application Security Engineer to join Savvy Wealth at our NYC headquarters as our first dedicated security hire. This is a hands-on, in-the-weeds engineering role. You will execute the security strategy set by our Director of IT & Information Security and our CTO, with day-to-day work centered on identifying vulnerabilities, remediating them, and closing the longer-term gaps that make us exposed, both in our product and in the SaaS tools our teams use every day.

Savvy is an AI-forward company. Most of our engineering is AI-assisted, and we enable people across the business, including non-technical roles, to build with AI coding tools. That enablement is a core part of how we work, and we intend to keep it. Your job is to make it safe: setting security hygiene standards in our codebases, building guardrails around AI-assisted development, and partnering closely with our internal AI team so that speed and security move together. You will make the secure path the easy path.

This role is deliberately not a compliance or GRC position. There are no audits to run, no certifications to chase, and no questionnaires to fill out. This is purely technical security work: finding and eliminating the vectors that make us vulnerable.

Responsibilities:

  • Own vulnerability management end to end: identify, triage, prioritize by real-world risk, and drive remediation to closure across our product, codebases, and cloud infrastructure (AWS, GCP, Cloudflare)

  • Build and operate our AppSec tooling pipeline: secrets scanning in CI and at the git layer, SCA/dependency scanning with triage SLAs, and SAST rollout on our most sensitive repos, tuned for signal over noise

  • Set and enforce security hygiene standards within our codebases, including code review standards that explicitly account for AI-generated code (authorship transparency, mandatory human review on security-sensitive paths)

  • Partner with our internal AI team to design guardrails that keep AI-assisted development, including vibe coding by non-technical builders, safe by default: sanctioned tooling, data handling boundaries, dependency vetting, and secure defaults for AI-built integrations

  • Secure the SaaS stack: harden configurations, review OAuth grants and third-party integrations, reduce misconfiguration risk across platforms like Google Workspace, GitHub, Rippling, and Slack

  • Help establish conditional access and identity-layer controls in partnership with IT (SSO, phishing-resistant MFA, managed-device posture)

  • Define cloud and SaaS configuration baselines for the infrastructure footprint we operate

  • Contribute to detection and response readiness: high-signal detections (new OAuth grants, mass code-host downloads, credential anomalies) and participate in incident response when needed

  • Work cross-functionally with Engineering, IT, and the internal AI team; clearly articulate risk, remediation paths, and tradeoffs to both technical and non-technical stakeholders

Must have:

  • 5+ years of hands-on security engineering experience, with significant time in application security or product security

  • Strong software engineering fundamentals; comfortable reading, writing, and remediating code, not just filing findings

  • Track record of enforcing security across technical and non-technical teams without slowing anyone down. The goal isn't to restrict how people work, it's to keep us safe while they keep working the way they need to.

  • Experience embedding security into existing workflows rather than bolting it on

  • Deep experience with the modern AppSec toolchain: secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration (GitHub-centric)

  • Practical experience securing SaaS environments: OAuth and third-party app review, configuration hardening, and least-privilege access design

  • Working knowledge of cloud security across AWS and/or GCP, and edge/CDN security (Cloudflare)

  • A pragmatic, risk-based mindset: you prioritize by what actually gets exploited, ship iteratively, and avoid drowning teams in noise

  • Strong perspective on AI-assisted development security: you understand how AI coding tools change the shape of AppSec risk (hallucinated dependencies, leaked secrets, insecure patterns at scale) and how to build guardrails without killing velocity

  • Excellent communication skills and ability to work independently in a fast-paced environment

  • Strong writing skills; Savvy is a written culture

Nice to have:

  • Experience building security programs at an early-to-mid stage company, taking a function from reactive to systematic

  • Experience with SaaS security posture management, CSPM, or identity threat detection

  • Familiarity with securing LLM-based tooling, agentic workflows, or internal AI platforms

  • Detection engineering experience (SIEM/MDR, high-signal alerting)

  • Fintech or financial services environment experience

  • Offensive security background (pentesting, bug bounty, red team) that informs how you defend

Benefits:
  • Competitive salary and equity package

  • Unlimited PTO + paid company holidays

  • Access to holistic medical, dental, and vision plans

  • Company 401(k), Commuter, and HSA/FSA plans

  • NYC office in the heart of Manhattan

  • Lunch and snacks provided in the office

  • Access to virtual mental health care (Spring Health) and health concierge (Rightway) to help you find the right care

  • Access to counseling for stress management, dependent care, nutrition, fitness, legal, and financial issues (Guardian WorkLifeMatters EAP)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Savvy Wealth • New York (NY)

On-site
USD 150,000 - 210,000
Equity
Unlimited PTO
Medical/Dental/Vision
+5
Senior Engineering Manager
Senior Engineering Manager

savvy • New York (NY)

Hybrid
USD 180,000 - 280,000
Competitive salary
Equity package
Unlimited PTO
+5
First Dedicated Security Engineer
First Dedicated Security Engineer

vibehackers • New York (NY)

On-site
USD 220,000 - 235,000
Paid holidays
Medical insurance
Dental insurance
+5
Software Engineer, Applied AI (all levels)
Software Engineer, Applied AI (all levels)

Savvy Wealth • New York (NY)

On-site
USD 120,000 - 160,000
Competitive salary and equity package
Unlimited PTO + paid company holidays
Health, dental, and vision plans
+4
Senior Engineer - Technical Staff
Senior Engineer - Technical Staff

Savvy Wealth • New York (NY)

On-site
USD 175,000 - 230,000
Unlimited PTO
Medical, dental, and vision plans
401(k) plan
+2
Senior Developer Experience Engineer
Senior Developer Experience Engineer

Savvy-Wealth • New York (NY)

On-site
USD 180,000 - 240,000
Competitive salary and equity package
Unlimited PTO + paid company holidays
Medical, dental, and vision plans
+1
Product Manager
Product Manager

savvy • New York (NY)

On-site
USD 140,000 - 210,000
Competitive salary and equity
Unlimited PTO
Medical, dental, vision
+5
Senior Engineering Manager
Senior Engineering Manager

Savvy Wealth • United States

Hybrid
USD 240,000 - 265,000
Competitive salary and equity package
Unlimited PTO + holidays
Medical, dental, vision plans
+1
Senior Developer Experience Engineer
Senior Developer Experience Engineer

Savvy Wealth • New York (NY)

On-site
USD 180,000 - 235,000
Competitive salary and equity package
Unlimited PTO + paid holidays
Comprehensive medical, dental, vision
Senior Engineering Manager
Senior Engineering Manager

Savvy • United States

On-site
USD 180,000 - 250,000
Competitive salary
Equity package
Unlimited PTO
+8