Senior Application Security Engineer

TKO

New York (NY)

Hybrid

USD 180,000 - 240,000

Full time

21 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

TKO is seeking a hands-on Director, Application Security Engineering to strengthen cybersecurity posture and partner with teams building software across web, mobile, data, and AI-enabled workflows. This role embeds security into delivery practices and improves how we prevent and remediate risk while communicating clearly with technical and non-technical stakeholders.

This Director will work across software engineering, platform, DevOps, architecture, QA, infrastructure, compliance, and security

Qualifications

  • 5+ years in application security or related software security role.
  • Experience working directly with engineering teams in fast-moving environments.
  • Hands-on with SAST/SCA tooling such as SonarQube, Dependabot, GitHub Advanced Security, or similar.
  • Ability to interpret code and provide actionable remediation guidance.
  • Practical SSDLC and shift-left experience with automated review, threat modeling, and vulnerability management.
  • Strong understanding of application and API security, including authN/authZ and data protection.
  • Experience integrating security controls into CI/CD pipelines and developer workflows.
  • Familiarity with cloud and modern delivery patterns (containers, IaC, Git-based workflows).
  • Strong risk-based vulnerability triage and remediation decision-making.
  • Ability to write clear guidance and technical documentation for diverse audiences.

Responsibilities

  • Own and evolve application security practices across SSDLC with scalable, developer-aligned controls.
  • Operate and improve SAST, SCA, secret scanning, code scanning, and CI/CD protections.
  • Develop secure development enablement for citizen developers and AI-assisted development.
  • Review vulnerabilities, validate findings, reduce noise, and drive remediation plans.
  • Conduct threat modeling and security design reviews for new systems and APIs.
  • Advise teams on secure coding, authentication, session management, secrets handling, and data protection.
  • Improve security guardrails for build pipelines, containers, APIs, and third-party components.
  • Mature risk-based vulnerability management across intake, validation, prioritization, and reporting.
  • Support secure adoption of AI-assisted development and agentic systems, assessing risks and exposure paths.
  • Develop standards, playbooks, reference architectures, and documentation; provide office-hour support.
  • Track weaknesses and advise leadership on where to invest to reduce risk.
  • Use AI responsibly to accelerate analysis while maintaining human judgment.

Skills

Application security
DevSecOps
Threat modeling
Vulnerability management
Secure SDLC
CI/CD security
Code review
AI security awareness
Cloud security
Automation

Tools

SonarQube
Dependabot
GitHub Advanced Security
CI/CD tooling

Job description

We are looking for a hands-on Director, Application Security Engineering to strengthen our cybersecurity posture and partner directly with teams building software across web, mobile, data, and AI-enabled workflows. This role will embed security into delivery practices, improve how we prevent and remediate risk, and communicate clearly with both technical and non-technical stakeholders.

This Director will work across software engineering, platform, DevOps, architecture, QA, infrastructure, compliance, and security teams to mature secure SDLC (i.e., SSDLC) practices, expand developer-friendly guardrails, and improve application and agent security. They should be comfortable moving between code review, tooling configuration, threat modeling, vulnerability management, automation, security enablement, and emerging AI security considerations. This is a hybrid role (3 days/week in-office). Preference given to candidates near a TKO office, including NYC, Stamford, Orlando, Austin, or Las Vegas.

The Role and What You’ll Do

The Director, Application Security Engineering will:

  • Own and evolve application security practices across the SSDLC, emphasizing scalable, developer-aligned, shift-left controls
  • Operate and improve SAST, SCA, secret scanning, code scanning, repository protections, and related controls across repositories and CI/CD pipelines
  • Develop secure development enablement for citizen developers, vibe coding, and AI-assisted development, including practical guidance for tooling, code assurance, identity, observability, and enterprise standards
  • Review application and code-level vulnerabilities, validate findings, reduce noise, and drive risk-based remediation plans
  • Conduct threat modeling and security design reviews for new systems, major changes, integrations, APIs, and high-risk workflows
  • Advise teams on secure coding, authentication and authorization, session management, secrets handling, logging, encryption, dependency hygiene, and data protection
  • Improve security guardrails for build pipelines, containers, APIs, third-party components, and deployment practices across modern and legacy environments
  • Mature risk-based vulnerability management across intake, validation, prioritization, remediation guidance, exception handling, and reporting
  • Support secure adoption of AI-assisted development and agentic systems by assessing trust boundaries, data exposure paths, prompt and tool-invocation risks, and misuse scenarios
  • Develop pragmatic standards, playbooks, reference architectures, documentation, and office-hour support that improve consistency without slowing teams down unnecessarily
  • Track recurring weaknesses, recommend structural fixes, and help leadership understand where engineering investment will reduce risk most effectively
  • Use AI productively and responsibly to accelerate analysis, triage, documentation, coding support, and security review while maintaining strong human judgment
Required Skills and Experience
  • 5+ years of hands‑on experience in application security, product security, DevSecOps, and security engineering or a closely related software security role
  • Proven experience working directly with engineering teams in fast‑moving delivery environments
  • Hands‑on experience configuring, tuning, and operationalizing SAST, SCA, and related tooling such as SonarQube, Dependabot, GitHub, GitHub Advanced Security, or comparable platforms
  • Ability to interpret and reason about code, identify meaningful risk, and provide specific, implementable remediation guidance to engineers
  • Practical experience with SSDLC and shift‑left practices, including automated code review support, threat modeling, security design review, and vulnerability management
  • Strong understanding of application and API security, including common software weaknesses, authN/authZ, secrets handling, dependency risk, injection, deserialization, and data protection
  • Experience integrating reliable, scalable, and minimally disruptive security controls into CI/CD pipelines and developer workflows
  • Hands‑on familiarity with cloud and modern software delivery patterns, including containers, IaC, and Git‑based workflows
  • Strong judgment in vulnerability triage, balancing severity, exploitability, business impact, and engineering realities
  • Ability to write clear guidance, standards, and technical documentation for technical and non‑technical audiences
  • Bias toward automation, simplification, and scalable solutions over manual heroics
  • Broad DevSecOps mindset across code, pipelines, dependencies, platforms, deployment, and operations
  • Experience using AI tools responsibly to improve engineering and security outcomes
Preferred Skills and Experience
  • Experience securing AI agents, LLM-enabled applications, copilots, or agentic workflows in production or near‑production environments
  • Experience with DAST, API security testing, penetration testing coordination, red‑team support, or adversarial testing of application and AI systems
  • Experience with policy‑as‑code, IaC scanning, container/image security, software supply‑chain security, SBOMs, provenance, attestation, and secrets management
  • Familiarity with cloud security across AWS and/or GCP and the application‑layer implications of cloud‑native architectures
  • Experience in regulated, audit‑sensitive, or event‑critical environments where evidence, controls, and operational rigor matter
  • Experience building metrics, dashboards, or reporting that show AppSec posture and remediation progress
  • Experience mentoring engineers and influencing secure engineering culture without direct people management responsibility
What Good Looks Like in This Role
  • Engineering teams get faster, clearer, and more actionable security guidance as well as assistance with implementation and mechanics for a "teach a person to fish" approach
  • Security tooling produces more trustworthy signals and leads to better adoption, not just more alerts
  • Teams catch and remediate issues earlier in design and development rather than late in release cycles
  • Application and agent-security risks are surfaced in practical terms with concrete mitigation paths
  • Standards, playbooks, and tooling make secure delivery easier and more consistent
  • Security becomes more embedded in day‑to‑day engineering execution and technical operations, and less dependent on last‑minute security scrambles and efforts
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director Application Security
Director Application Security

Vibehackers • Austin (TX), Northern (KY)

Hybrid
USD 180,000 - 250,000
Medical Insurance
Dental Insurance
Life Insurance
+3
Director Application Security Engineering
Director Application Security Engineering

OpenTalent • United States

On-site
USD 140,000 - 180,000
Growth opportunities
Collaborative team environment
Professional development
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Director, Cyber Security Wanted!
Director, Cyber Security Wanted!

HealthCare Talent • Irvine (CA)

On-site
USD 130,000 - 160,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
Senior Application Security Specialist
Senior Application Security Specialist

CLS Group • Woodbridge Township (NJ)

On-site
USD 140,000 - 180,000
Senior Application Security Engineer DevSecOps and CICD
Senior Application Security Engineer DevSecOps and CICD

3Core Systems, Inc • Chicago (IL), Northern (KY)

Hybrid
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Senior AppSec Engineer
Senior AppSec Engineer

Dream • United States

On-site
USD 120,000 - 160,000