Application Security Engineer
Job Description
The City of New York’s Technology & Innovation team is seeking an Application Security Engineer to help protect critical digital services. In this onsite role based in Brooklyn, NY, you will assess software security risk across web applications, APIs, and mobile systems, supporting the Software Security Assurance Program (SSAP) through analysis, validation, and remediation guidance.
The position involves hands-on security testing using SAST, DAST, and SCA, along with threat modeling and manual review work during the design and development lifecycle. You will also collaborate closely with agency development teams to reduce vulnerabilities before deployment and improve secure development practices.
What You’ll Do
- Execute application security assessments within the SSAP to confirm that web applications, APIs, and mobile systems meet city security standards before release.
- Run SAST, DAST, and manual security reviews to validate vulnerabilities, reduce false positives, and prioritize issues by operational risk.
- Operate Software Composition Analysis (SCA) tools to monitor and track open-source and third-party component vulnerabilities and drive remediation.
- Perform structured threat modeling and logic reviews on assigned applications during the design phase to surface security flaws early.
- Act as a technical point of contact for agency development teams, providing clear and actionable remediation guidance and secure coding advice.
- Assist with configuring and integrating automated security scanning tools into CI/CD pipelines for DevSecOps workflows (including GitHub Actions, Azure DevOps, and GitLab).
- Conduct security reviews for third-party vendor solutions and web APIs (including OAuth and REST) to verify alignment with city security policies and industry best practices.
- Contribute to maintaining secure coding guidelines, application security documentation, and training materials for agency development staff.
Requirements
- A baccalaureate degree from an accredited college, plus four years of satisfactory full-time experience related to projects and policies required for the position; or an equivalent combination of education and experience.
- 2–4 years of dedicated professional experience in application security, penetration testing, or software engineering with a focus on application security.
- Hands-on experience configuring, operating, and tuning SAST, DAST, and SCA tools (for example: Veracode, Checkmarx, Snyk, Burp Suite) and experience working with CI/CD pipelines.
- Strong practical knowledge of OWASP Top 10, CWE flaw types, manual vulnerability verification, and secure coding concepts in languages such as Python, Java, JavaScript/TypeScript, or C#/.NET.
- Working knowledge of web API security principles (including REST and OAuth 2.0) and basic application security controls in cloud environments (AWS, Azure, or GCP).
- Experience conducting application threat modeling and architectural flaw reviews.
- Strong verbal and written communication skills, with demonstrated ability to explain technical vulnerabilities and remediation steps to developers and project teams.
- Mid-level application security or testing certifications are a plus, such as GIAC GWAPT, GWEB, eWPT, CompTIA PenTest+, or CSSLP.
Tools and Technologies
- SAST, DAST, SCA, Software Composition Analysis (SCA), SSAP
- Veracode, Checkmarx, Snyk, Burp Suite
- GitHub Actions, Azure DevOps, GitLab
- OAuth, REST, OAuth 2.0
- AWS, Azure, GCP
- Python, Java, JavaScript/TypeScript, C#/.NET
- OWASP Top 10, CWE
Work Schedule
Day hours are expected, but due to technical duties of a 24/7 operation, candidates may be required to work various shifts, including weekends and/or nights/evenings.
Compensation
USD 75,000 - 135,000 per year.
Additional Information
- Residency requirement: New York City residency is not required.
- TO APPLY: Applicants with other civil service titles who meet the preferred requirements should submit a resume for consideration.
- Public Service Loan Forgiveness: As a prospective employee of the City of New York, you may be eligible for federal loan forgiveness programs and state repayment assistance programs. More information is available at https://studentaid.gov/pslf/.
- Equal opportunity: The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment free from discrimination and harassment based on legally protected status or protected characteristic.