Senior Application Security Engineer

TripleLift

New York (NY)

On-site

USD 180,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TripleLift in New York seeks a Senior Application Security Engineer to drive secure software development and maturity across engineering and security teams. You will partner with Engineering, Platform, Cloud Infrastructure, and Security to embed secure coding, CI/CD security, and remediation, building a resilient ad-tech platform.

The role emphasizes threat modeling, automated security testing, and education across engineers to raise security standards and resilience.

Qualifications

  • 5+ years in application security or related field.
  • Experience with secure SDLC and guiding developers on remediation.
  • Strong knowledge of SAST/DAST/SCA tools and secure coding practices.
  • AWS security services and cloud controls understanding.
  • Ability to perform threat modeling and design reviews.

Responsibilities

  • Build and scale an application security program across the org.
  • Develop automated security testing using enterprise SAST, DAST and code-review tools.
  • Automate security testing in CI/CD pipelines and build integrations.
  • Administer and drive adoption of GitHub Advanced Security (GHAS).
  • Conduct internal penetration testing and vulnerability assessments.
  • Monitor and respond to application-layer security threats.
  • Collaborate with product and engineering to embed security into design.
  • Educate engineers through secure development training and guidelines.
  • Improve security program maturity through tools and processes.

Skills

Penetration testing
Application security
Threat modeling
CI/CD security
Security tooling
OWASP Top 10
Secure coding guidance
Engineering collaboration

Tools

GHAS
CodeQL
Burp Suite
OWASP ZAP
Snyk
Checkmarx
Veracode

Job description

  • The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift’s Engineering and Security organization, directly influencing how we protect our advertising platforms and the trust our publishers and advertisers place in us
  • In this position, you will partner closely with Engineering, Platform, Cloud Infrastructure, and Security teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security, ensuring security is embedded into how we design, build, deploy, and operate our products
  • This is an exciting opportunity for someone who wants to build and scale an application security program at a company operating at the center of a rapidly evolving, high-stakes ad-tech landscape, while contributing meaningfully to the long‑term security posture and resilience of the organization
  • Play a critical role in building and maintaining a global security compliance program based on NIST CSF
  • Scale application security by developing automated security testing utilizing enterprise SAST, DAST, and code‑review tools
  • Champion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities
  • Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations themselves
  • Administer and drive adoption of GitHub Advanced Security (GHAS) : code scanning, secret scanning, and dependency review across engineering repositories
  • Participate in threat modeling and design/architecture spec reviews to identify and mitigate security risks early in the SDLC
  • Coordinate with stakeholders to develop and implement a vulnerability management program and to perform threat‑hunting activities
  • Own and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate findings from third‑party pentest engagements
  • Monitor and respond to application‑layer security threats like API abuses, business logic flaws, and common web vulnerabilities
  • Collaborate with product and engineering teams to ensure security is a key consideration in software design and architecture
  • Enhance application security posture by working with cross‑functional teams to implement proper authentication, authorization, and data protection mechanisms
  • Enhance and facilitate security incident handling activities
  • Evangelize security best practices and provide education and awareness to company employees. Develop and implement secure coding guidelines and conduct secure development training for engineers
  • Evaluate and continuously improve the maturity of the security program through the deployment and management of various security tools and processes
Benefits
  • Medical, Dental & Vision Plans
  • Unlimited PTO
  • 401k w/ employer match

Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructureExperience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency ReviewKnowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security)Experience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go)Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflowsStrong understanding of secure coding practices and ability to guide developers on remediation strategies5+ years of experience in application security, secure software development, security engineering, or a similar roleAbility to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and servicesProficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode)Continuously learns, adapts, and values correctness, efficiency, and constructive feedbackStrong understanding of AWS security services and controls (IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud‑native environments and workloads, with the ability to deploy security tools within themUnderstanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similarTakes ownership of projects, works independently with minimal oversight, and delivers results in a fast‑paced environment while balancing multiple prioritiesExperience in the ad‑tech / programmatic advertising industry, or another high‑scale, real‑time environmentPreferred: Familiarity with using AI/LLM‑based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automationHolds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

TripleLift • New London (NY)

On-site
USD 125,000 - 165,000
Medical, Dental & Vision Plans
Flexible PTO
401k with employer match
Senior AppSec Engineer: Drive Secure Software at Ad Tech Scale
Senior AppSec Engineer: Drive Secure Software at Ad Tech Scale

TripleLift • New London (NY)

On-site
USD 125,000 - 165,000
Medical, Dental & Vision Plans
Flexible PTO
401k with employer match
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Senior Director, Security
Senior Director, Security

TripleLift • New York (NY)

On-site
USD 165,000 - 220,000
Medical, Dental & Vision Plans
Flexible PTO
401k w/ employer match
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Security Engineer II, Ads Security
Security Engineer II, Ads Security

Amazon • Boston (MA)

On-site
USD 90,000 - 150,000
Flexible Working Hours
Training & Career Growth Opportunities
Work/Life Balance Support
+1
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Application Security Engineer
Application Security Engineer

Jobtailor • Atlanta (GA)

On-site
USD 120,000 - 160,000
Staff Security Engineer (Product Security and Architecture)
Staff Security Engineer (Product Security and Architecture)

Compass • Ventura (CA)

On-site
USD 150,000 - 230,000