Senior Security Engineer

STEPS Talent

New York (NY)

Hybrid

USD 140,000 - 200,000

Full time

32 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

STEPS Talent in New York City is seeking a Senior Security Engineer - Application Security to join a hybrid team protecting applications, cloud infrastructure, systems, and customer data. You will collaborate with engineering to embed security in the SDLC and drive secure design and implementation.

Requirements include 4+ years in application or software security, strong OWASP knowledge, API security experience, and cloud security with AWS/GCP/Azure.

Qualifications

  • 4+ years in application, product, or software security or security-focused transition from software engineering.
  • Strong understanding of vulnerabilities and attack techniques including OWASP Top 10 and API security risks.
  • Experience testing modern web apps, APIs, and distributed systems manually.
  • Ability to assess architecture and source code for security weaknesses.
  • Experience integrating security tools into CI/CD workflows.
  • Familiarity with SAST, DAST, secrets detection, container and dependency scanning, IaC scanning.
  • Understanding authentication, authorization, session management, cryptography, and secure API design.
  • Cloud security experience with AWS, GCP, or Azure; proficiency with programming languages and security tooling.

Responsibilities

  • Develop and implement application security controls across the SDLC.
  • Partner with engineering to embed security in architecture, design, and deployment.
  • Perform hands-on security testing of web apps, APIs, and cloud services.
  • Enhance automated security testing in CI/CD pipelines (static, dynamic, secrets, container scans).
  • Evaluate tools, reduce false positives, and minimize developer friction.
  • Review architecture and code for weaknesses and document secure coding standards.
  • Support vulnerability management, incident response, and third-party risk assessments.
  • Ensure compliance with healthcare and data protection requirements (HIPAA, GDPR).

Skills

Application security
OWASP Top 10
API security
CI/CD security
Cloud security
Web app security
Code security testing
SAST/DAST
Secure coding
Security testing

Tools

SAST tools
DAST tools
Secrets detection tools
Container scanning tools
Dependency scanning tools
IaC scanning tools

Job description

Position: Senior Security Engineer - Application Security

Location: New York City, NY (HYBRID: 4 days a week in office)

Duration: DIRECT HIRE – FULL TIME

Summary:

We are seeking an experienced Application Security professional to protect applications, cloud infrastructure, systems, and customer data. As part of a lean security team, this individual will contribute across application security, cloud security, security operations, IT security, and compliance while helping design and implement new security solutions.

Skills/Experience Needed:
  • 4+ years of experience in application, product, or software security, or software engineering experience followed by a transition into security.
  • Strong understanding of application security vulnerabilities and attack techniques, including the OWASP Top 10 and API security risks.
  • Experience manually testing modern web applications, APIs, and distributed systems.
  • Ability to assess application architecture and source code for security weaknesses.
  • Experience integrating application security tools into modern CI/CD workflows.
  • Familiarity with SAST, DAST, secrets detection, container security, dependency scanning, and Infrastructure-as-Code scanning.
  • Understanding of authentication, authorization, session management, cryptography, secrets management, and secure API design.
  • Strong cloud security experience with AWS, Google Cloud Platform, or Azure.
  • Proficiency with modern programming languages and familiarity with generative coding tools and their security implications.
  • Experience researching, establishing, and implementing enterprise-wide security policies and guidelines
Responsibilities:
  • Develop and implement application security controls throughout the Software Development Lifecycle (SDLC).
  • Partner with engineering teams to incorporate security into architecture, design, development, testing, and deployment.
  • Perform hands-on security testing of web applications, APIs, cloud-native services, and supporting infrastructure.
  • Build and improve automated security testing within CI/CD pipelines, including static analysis, dependency scanning, secrets detection, container scanning, and dynamic testing.
  • Evaluate application security tools, improve the quality of results, reduce false positives, and minimize developer friction.
  • Review application architecture and source code for security weaknesses.
  • Develop secure coding standards and developer-focused documentation.
  • Support vulnerability management, security investigations, incident response, and post-incident reviews.
  • Evaluate third-party applications, libraries, APIs, and integrations for security risks.
  • Ensure compliance with applicable healthcare and data-protection requirements, including HIPAA and GDPR.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Chris Baily • New York (NY)

On-site
USD 150,000 - 190,000
On-site in NYC
Competitive salary
Senior Security Engineer - Application Security
Senior Security Engineer - Application Security

TechAviv • New York (NY)

On-site
USD 120,000 - 160,000
Application Security Engineer
Application Security Engineer

Franklin Fitch • New York (NY)

On-site
USD 130,000 - 200,000
Application Security Engineer
Application Security Engineer

RedStream Technology • Charlotte (NC)

On-site
USD 120,000 - 150,000
Senior Application Security Specialist
Senior Application Security Specialist

CLS Group • Woodbridge Township (NJ)

On-site
USD 140,000 - 180,000
Senior Application Security Engineer - AppSec & SDLC
Senior Application Security Engineer - AppSec & SDLC

K Health • New York (NY)

On-site
USD 150,000 - 200,000
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)

The Mom Project • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Medical
Dental
401k
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)

The Mom Project • New York (NY)

Hybrid
USD 140,000 - 190,000
Medical
Dental
401k (no match)
Senior Application Security Engineer
Senior Application Security Engineer

High Trail • Arlington (VA)

On-site
USD 140,000 - 190,000
Senior Application Security Engineer
Senior Application Security Engineer

Interactive Resources - iR • Jacksonville (FL)

On-site
USD 120,000 - 180,000