Get more replies from employers
Send a job-specific resume in minutes.
TripleLift in New York seeks a Senior Application Security Engineer to drive secure software development and maturity across engineering and security teams. You will partner with Engineering, Platform, Cloud Infrastructure, and Security to embed secure coding, CI/CD security, and remediation, building a resilient ad-tech platform.
The role emphasizes threat modeling, automated security testing, and education across engineers to raise security standards and resilience.
Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructureExperience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency ReviewKnowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security)Experience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go)Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflowsStrong understanding of secure coding practices and ability to guide developers on remediation strategies5+ years of experience in application security, secure software development, security engineering, or a similar roleAbility to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and servicesProficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode)Continuously learns, adapts, and values correctness, efficiency, and constructive feedbackStrong understanding of AWS security services and controls (IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud‑native environments and workloads, with the ability to deploy security tools within themUnderstanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similarTakes ownership of projects, works independently with minimal oversight, and delivers results in a fast‑paced environment while balancing multiple prioritiesExperience in the ad‑tech / programmatic advertising industry, or another high‑scale, real‑time environmentPreferred: Familiarity with using AI/LLM‑based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automationHolds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc