verified listingSign up to apply with your verified profile — no re-entering experience or references.
source · wttj·req · jb_b6278e4965·listed 6h ago

Senior Application Security Engineer

TripleLift·New York, United States·Hybrid·Full-time
Sourced listing · wttjSalary disclosed
Posted
3 August 2026
via wttj
Type
Full-time
Arrangement
Hybrid
United States
Deadline
2 September 2026
closes in 30d
compensation · disclosed
$125,000 — $165,000
source · wttj

Summary

the pitch

Join TripleLift as a Senior Application Security Engineer, where you will play a critical role in driving secure software development and application security maturity. You will partner closely with various teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security. This is an exciting opportunity to build and scale an application security program in a rapidly evolving ad-tech landscape.

Role

posted by company
  • Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure
  • Experience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review
  • Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security)
  • Experience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go)
  • Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows
  • Strong understanding of secure coding practices and ability to guide developers on remediation strategies
  • 5+ years of experience in application security, secure software development, security engineering, or a similar role
  • Ability to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and services
  • Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode)
  • Continuously learns, adapts, and values correctness, efficiency, and constructive feedback
  • Strong understanding of AWS security services and controls (IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, with the ability to deploy security tools within them
  • Understanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similar
  • Takes ownership of projects, works independently with minimal oversight, and delivers results in a fast-paced environment while balancing multiple priorities
  • Experience in the ad-tech / programmatic advertising industry, or another high-scale, real-time environment
  • Holds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc
  • Preferred: Familiarity with using AI/LLM-based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automation