Senior Security Engineer

STEPS Talent

New York (NY)

Hybrid

USD 140,000 - 190,000

Full time

4 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

STEPS Talent in New York City seeks a Senior Security Engineer specialized in Application Security to lead secure software development across the SDLC, collaborating with Dev and Ops to embed security.

The candidate will assess architectures, perform hands-on testing, and champion cloud security practices while shaping enterprise-wide policies and secure design standards.

Qualifications

  • 4+ years in application/product/software security as IC or security-focused engineer.
  • Strong knowledge of OWASP Top 10 and API security risks.
  • Experience performing manual security testing of web apps and APIs.
  • Ability to review architecture and source code for weaknesses.
  • Experience integrating security tooling into CI/CD workflows.
  • Familiar with SAST, DAST, secrets detection, container security, IaC scanning.
  • Understanding authentication, authorization, session management, cryptography, secrets management and secure API design.
  • Cloud expertise across AWS/GCP/Azure and awareness of AI code security implications.
  • Experience establishing enterprise-wide security policies and guidelines.

Responsibilities

  • Lead the development and implementation of application security across the SDLC.
  • Partner with engineering to embed security into architecture, design, development, testing and deployment.
  • Perform hands-on security testing of web apps, APIs, and cloud services.
  • Improve automated security testing within CI/CD pipelines (static, dynamic, secret scanning, container security).
  • Evaluate tooling effectiveness and reduce noisy findings to minimize developer friction.
  • Develop secure coding standards with developer-focused docs.
  • Contribute security expertise during incidents, investigations and post-incident reviews.
  • Evaluate third-party libraries and integrations for security risk.
  • Ensure adherence to healthcare regulatory and compliance requirements where applicable.

Skills

Application security
OWASP Top 10
Manual security testing
Architecture review
CI/CD security tooling
SAST/DAST/IAST
Cloud security (AWS/GCP/Azure)
Secure coding / API design
Security policy & governance

Job description

Position: Senior Security Engineer - Application Security

Location: New York City, NY (HYBRID: 4 days a week in office)

Duration: DIRECT HIRE – FULL TIME

Summary:

This person needs to operate with foresight in protecting our infrastructure, applications, cloud security, and customer trust. As a lean team, we span across multiple areas such as AppSec, CloudSec, SecOps, ITSec, and Compliance and apply it towards reading and interpreting architecture, or planning and building out net new security solutions.

Skills/Experience Needed:

  • 4+ years of professional experience in application, product or software security, operating as an individual contributor, OR as a software engineer that has pivoted into security
  • Strong understanding of application security vulnerabilities and attach techniques, including OWASP Top 10 and API security risks
  • Experience performing manual security testing of modern web applications, APIs and distributed systems
  • Ability to review application architecture and source code for security weaknesses
  • Experience integrating application security tools into modern CI/CD workflows
  • Familiarity with static application security testing, dynamic testing, secrets detection, container security and infrastructure-as-code scanning
  • Understanding of authentication, authorization, session management, cryptography, secrets management and secure API design
  • Strong expertise in cloud technology (AWS, Google Cloud Platform, or Azure), modern programming languages, utilization of generative coding utilities, and the security implications of utilizing AI code development utilities.
  • Demonstrated experience researching, establishing, and successfully rolling out enterprise-wide security policies and guidelines.

Responsibilities:

  • Lead the development and implementation of robust application security protocols throughout the entire Software Development Lifecycle (SDLC).
  • Partner with engineering teams to incorporate security into architecture, design, development, testing and deployment
  • Perform hands-on security testing of web applications, APIs, cloud-native services and supporting infrastructure
  • Build and improve automated security testing within CI/CD pipelines, including static analysis, dependency scanning, secrets detection, container scanning and dynamic testing
  • Evaluate effectiveness of application security tools, improve tooling output quality and reduce unnecessary findings and developer friction
  • Develop secure coding standards with developer-focused documentation
  • Contribute application security expertise to vulnerability management, during security incidents/investigations and post-incident reviews
  • Evaluate third party applications, libraries and APIs and integrations for security risk
  • Ensure adherence to relevant healthcare regulatory and compliance requirements (e.g., HIPAA, GDPR, etc.) across all product lines and systems.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer - AppSec & SDLC
Senior Application Security Engineer - AppSec & SDLC

K Health • New York (NY)

On-site
USD 150,000 - 200,000
Application Security Engineer
Application Security Engineer

Ringside Talent Acquisition Partners • Columbus (OH)

Hybrid
USD 100,000 - 130,000
Competitive compensation
Hybrid work flexibility
Opportunities for advancement
Senior Application Security Engineer – Cloud & AppSec
Senior Application Security Engineer – Cloud & AppSec

K Health • New York (NY)

On-site
USD 150,000 - 200,000
Application Security Engineer
Application Security Engineer

Franklin Fitch • New York (NY)

On-site
USD 130,000 - 200,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Senior Security Engineer
Senior Security Engineer

StreetID • New York (NY)

On-site
USD 120,000 - 160,000
Senior Application Security Engineer
Senior Application Security Engineer

TKO • New York (NY)

Hybrid
USD 180,000 - 240,000
Senior Security Engineer - Cloud & AppSec (Healthcare tech)
Senior Security Engineer - Cloud & AppSec (Healthcare tech)

Khealthcareers • New York (NY)

Hybrid
USD 150,000 - 200,000
Hybrid work schedule
18 vacation days
401(k) benefit
+2
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000