TripleLift is hiring a Senior Application Security Engineer to strengthen secure development practices and advance application security maturity across the organization. This onsite role in New York, NY partners closely with Engineering, Platform, Cloud Infrastructure, and Security to scale application security testing, improve CI/CD security, remediate vulnerabilities, and support incident handling.
You will help build a program aligned to NIST CSF, integrate automated security checks into delivery workflows, and lead technical efforts that improve security outcomes across applications and infrastructure.
What you’ll do
- Build and maintain a global security compliance program based on NIST CSF.
- Scale application security through automated testing using enterprise SAST, DAST, and code review tooling.
- Promote SDLC practices that support secure application development and infrastructure deployment, including secure coding remediation enablement.
- Automate security testing in CI/CD pipelines, including designing and maintaining pipeline integrations for early vulnerability detection.
- Administer and drive adoption of GitHub Advanced Security (GHAS), including Code Scanning, Secret Scanning, and Dependency Review across engineering repositories.
- Participate in threat modeling and design or architecture spec reviews to identify and mitigate risks early in the SDLC.
- Coordinate with stakeholders to implement a vulnerability management program and support threat-hunting activities.
- Own internal penetration testing and vulnerability assessments for applications and infrastructure, and validate findings from third-party pentest engagements.
- Monitor and respond to application-layer security threats, including API abuses, business logic flaws, and common web vulnerabilities.
- Collaborate with product and engineering teams so security remains a consideration in software design and architecture.
- Improve security posture by implementing mechanisms for authentication, authorization, and data protection.
- Enhance and facilitate security incident handling activities.
- Evangelize security best practices through education and awareness, and develop secure coding guidelines and training for engineers.
- Evaluate and improve security program maturity by deploying and managing security tools and processes.
What you bring
- 5+ years of experience in application security, secure software development, security engineering, or a related role.
- Strong secure coding knowledge with the ability to guide remediation strategies for developers.
- Experience with GitHub Advanced Security (GHAS) including Code Scanning, Secret Scanning, and Dependency Review.
- Proficiency with SAST, DAST, and SCA tools, including examples such as CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, and Veracode.
- Hands-on experience integrating security testing tools into CI/CD pipelines for automated scanning, including building pipeline workflows.
- Hands-on penetration testing or offensive security experience across web applications, APIs, or cloud infrastructure.
- Knowledge of common application security vulnerabilities and mitigations, including OWASP Top 10 and CWE, along with business logic flaws and API security.
- Ability to perform threat modeling and contribute to design and architecture spec reviews.
- Experience conducting security code reviews across languages such as Python, Java, TypeScript, and Go.
- Understanding of security fundamentals across cybersecurity and compliance frameworks, especially NIST CSF, and familiarity with PCI, SOC2, HITRUST, ISO 27001/2, or similar.
- Understanding of AWS security services and controls including IAM, VPC, KMS, GuardDuty, and CloudTrail, with experience deploying security tools in cloud-native environments.
- Ownership mindset, ability to work independently with minimal oversight, and a track record of delivering results in a fast-paced environment.
- Continual learning with a focus on correctness, efficiency, and constructive feedback.
Tools and technologies you’ll work with
- GitHub Advanced Security (GHAS): Code Scanning, Secret Scanning, Dependency Review
- Security testing: SAST, DAST, SCA
- Examples: CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode
- Delivery: CI/CD
- Frameworks and standards: NIST CSF, OWASP Top 10, CWE
- AWS and controls: AWS, IAM, VPC, KMS, GuardDuty, CloudTrail
- Languages: Python, Java, TypeScript, Go
- Compliance mentioned: PCI, SOC2, HITRUST, ISO 27001/2
- Certifications listed: OSCP, GWAPT, CISSP, CISA
- Additional: (OSCP, GWAPT, CISSP, CISA listed within technologies section), CISSP, CISA
Preferred
- Experience in ad-tech / programmatic advertising or another high-scale, real-time environment.
- Familiarity with AI/LLM-based tools (for example, Claude or similar) for threat intelligence, alert triage, or security automation.
- Holding a cybersecurity certification such as OSCP, GWAPT, CISSP, or CISA.
Salary and location
- Location: New York, NY (onsite)
- Salary: USD 160,000 - 200,000 per year
Life at TripleLift
TripleLift emphasizes working with great people who want to improve those around them. The culture focuses on being positive, collaborative, and compassionate, with teams continuously innovating.
People, culture, and community initiatives
TripleLift is committed to building a workplace where people feel connected, supported, and empowered to do their best work. The company invests in people, promotes curiosity, celebrates shared values, and aims to create an environment where everyone can thrive and feel a true sense of belonging.