Skip to content
← Back to job listings

Senior Application Security Engineer

TripleLift · New York, United States

External listingfull-time2 days ago

About The Role

Join TripleLift as a Senior Application Security Engineer, where you will play a critical role in driving secure software development and application security maturity. You will partner closely with various teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security. This is an exciting opportunity to build and scale an application security program in a rapidly evolving ad-tech landscape.

  • Collaborer étroitement avec les équipes d'ingénierie, de plateforme, d'infrastructure cloud et de sécurité pour façonner les pratiques de codage sécurisé, les outils de sécurité des applications, la remédiation des vulnérabilités et la sécurité CI/CD.
  • Développer des tests de sécurité automatisés en utilisant des outils SAST, DAST et de révision de code d'entreprise, et automatiser les tests de sécurité dans les pipelines CI/CD.
  • Participer à la modélisation des menaces et aux examens de conception/architecture pour identifier et atténuer les risques de sécurité dès le début du cycle de vie du développement logiciel.
  • Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure
  • Experience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review
  • Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security)
  • Experience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go)
  • Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows
  • Strong understanding of secure coding practices and ability to guide developers on remediation strategies
  • 5+ years of experience in application security, secure software development, security engineering, or a similar role
  • Ability to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and services
  • Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode)
  • Continuously learns, adapts, and values correctness, efficiency, and constructive feedback
  • Strong understanding of AWS security services and controls (IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, with the ability to deploy security tools within them
  • Understanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similar
  • Takes ownership of projects, works independently with minimal oversight, and delivers results in a fast-paced environment while balancing multiple priorities
  • Experience in the ad-tech / programmatic advertising industry, or another high-scale, real-time environment
  • Holds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc
  • Preferred: Familiarity with using AI/LLM-based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automation

This is an external listing. JobSpring does not represent or verify the employer. Report this listing