T
source · wttj·req · jb_b6278e4965·listed 6h ago
Senior Application Security Engineer
TripleLift·New York, United States·Hybrid·Full-time
Sourced listing · wttjSalary disclosed
compensation · disclosed
$125,000 — $165,000
source · wttj
Summary
the pitchJoin TripleLift as a Senior Application Security Engineer, where you will play a critical role in driving secure software development and application security maturity. You will partner closely with various teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security. This is an exciting opportunity to build and scale an application security program in a rapidly evolving ad-tech landscape.
Role
posted by company- Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure
- Experience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review
- Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security)
- Experience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go)
- Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows
- Strong understanding of secure coding practices and ability to guide developers on remediation strategies
- 5+ years of experience in application security, secure software development, security engineering, or a similar role
- Ability to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and services
- Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode)
- Continuously learns, adapts, and values correctness, efficiency, and constructive feedback
- Strong understanding of AWS security services and controls (IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, with the ability to deploy security tools within them
- Understanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similar
- Takes ownership of projects, works independently with minimal oversight, and delivers results in a fast-paced environment while balancing multiple priorities
- Experience in the ad-tech / programmatic advertising industry, or another high-scale, real-time environment
- Holds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc
- Preferred: Familiarity with using AI/LLM-based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automation