Senior Application Security Engineer
Senior
Application Security
Code Scanning
Cybersecurity Tools
Dependency Scanning
DevSecOps
Dynamic Application Security Testing
Engineer
Information Security
InfoSec
Secret Scanning
Security Automation
Security Compliance
Security Standards
Security Testing
Software Security
Static Application Security Testing
Static Code Analysis
Job Description
TripleLift is hiring a Senior Application Security Engineer to strengthen secure software development across engineering, platform, cloud infrastructure, and security.
Responsibilities
- Build and maintain a global security compliance program aligned to NIST CSF.
- Scale application security by developing automated security testing using enterprise SAST, DAST, and code-review tools.
- Promote an SDLC that supports secure application development and infrastructure deployment, including secure coding remediation activities.
- Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations.
- Administer and drive adoption of GitHub Advanced Security (GHAS) across engineering repositories, including:
- Code scanning
- Secret scanning
- Dependency review
- Participate in threat modeling and design or architecture specification reviews to identify and mitigate risks early in the SDLC.
- Coordinate stakeholders to develop and implement a vulnerability management program and support threat-hunting activities.
- Own and conduct internal penetration testing and vulnerability assessments for applications and infrastructure, and validate outcomes from third-party pentest engagements.
- Monitor and respond to application-layer threats, including API abuse, business logic flaws, and common web vulnerabilities.
- Collaborate with product and engineering teams to ensure security is built into software design and architecture.
- Improve application security posture by implementing authentication, authorization, and data protection mechanisms.
- Enhance and facilitate security incident handling activities.
- Evangelize security best practices by providing education and awareness for employees; develop and implement secure coding guidelines and run secure development training for engineers.
- Evaluate and continuously improve security program maturity by deploying and managing security tools and processes.
Requirements
- 5 years minimum experience in application security, secure software development, security engineering, or a related role.
- Strong understanding of secure coding practices and ability to guide developers through remediation strategies.
- Experience with GitHub Advanced Security (GHAS) including:
- Code Scanning (SAST)
- Secret Scanning
- Dependency Review
- Proficiency with SAST, DAST, and SCA tools (examples include CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode).
- Hands-on experience integrating security testing tools into CI/CD pipelines for automated scanning, including designing and building pipeline workflows.
- Hands-on penetration testing and offensive security experience across web applications, APIs, or cloud infrastructure.
- Knowledge of common application security vulnerabilities and mitigations including OWASP Top 10 and CWE, with a focus on business logic flaws and API security.
- Ability to perform threat modeling and participate in design or architecture spec reviews to assess security risks.
- Experience conducting security code reviews across programming languages such as Python, Java, TypeScript, and Go.
- Security fundamentals mapped to cybersecurity and compliance frameworks, especially NIST CSF (also includes PCI, SOC2, HITRUST, ISO 27001/2, or similar).
- Strong understanding of AWS security services and controls (including IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, including deploying security tools within them.
- Ownership mindset with the ability to work independently with minimal oversight, delivering results in a fast-paced environment while balancing multiple priorities.
- Continually learns and adapts, valuing correctness, efficiency, and constructive feedback.
Technologies
- NIST CSF
- GitHub Advanced Security (GHAS): Code Scanning, Secret Scanning, Dependency Review
- SAST, DAST, SCA
- CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode
- CI/CD
- OWASP Top 10, CWE
- Python, Java, TypeScript, Go
- PCI, SOC2, HITRUST, ISO 27001/2
- AWS: IAM, VPC, KMS, GuardDuty, CloudTrail
- OSCP, GWAPT, CISSP, CISA
- Claude
Preferred
- Experience in ad-tech or programmatic advertising, or another high-scale real-time environment.
- Familiarity with using AI/LLM-based tools (for example, Claude or similar) for threat intelligence, alert triage, or security automation.
- Cybersecurity certification such as OSCP, GWAPT, CISSP, CISA, etc.
Location and Compensation
- Location: Hoboken, NJ (onsite)
- Salary: USD 160,000 - 200,000 per year
Life at TripleLift
- Team culture focused on people who like who they work with and aim to help everyone around them improve.
- Continuous innovation and fast-moving execution.
- Learn more via TripleLift’s LinkedIn Life page.
People, Culture and Community Initiatives
- Commitment to building a culture that helps people feel connected, supported, and empowered.
- Investment in employees and encouragement of curiosity, shared values, and meaningful connections across teams and communities.
- Focus on ensuring talent of every background, viewpoint, and experience can be hired, belong, and develop.
- People, Culture, and Community initiatives designed to help everyone thrive and feel a sense of belonging.
Privacy Policy
- See TripleLift and 1plusX websites for Privacy Policies.
- TripleLift does not accept unsolicited resumes from recruitment search firms.