CybersecurityJobs.io
← Back to all jobs

Job Description

TripleLift is hiring a Senior Application Security Engineer to strengthen secure software development across engineering, platform, cloud infrastructure, and security.

Responsibilities

  • Build and maintain a global security compliance program aligned to NIST CSF.
  • Scale application security by developing automated security testing using enterprise SAST, DAST, and code-review tools.
  • Promote an SDLC that supports secure application development and infrastructure deployment, including secure coding remediation activities.
  • Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations.
  • Administer and drive adoption of GitHub Advanced Security (GHAS) across engineering repositories, including:
    • Code scanning
    • Secret scanning
    • Dependency review
  • Participate in threat modeling and design or architecture specification reviews to identify and mitigate risks early in the SDLC.
  • Coordinate stakeholders to develop and implement a vulnerability management program and support threat-hunting activities.
  • Own and conduct internal penetration testing and vulnerability assessments for applications and infrastructure, and validate outcomes from third-party pentest engagements.
  • Monitor and respond to application-layer threats, including API abuse, business logic flaws, and common web vulnerabilities.
  • Collaborate with product and engineering teams to ensure security is built into software design and architecture.
  • Improve application security posture by implementing authentication, authorization, and data protection mechanisms.
  • Enhance and facilitate security incident handling activities.
  • Evangelize security best practices by providing education and awareness for employees; develop and implement secure coding guidelines and run secure development training for engineers.
  • Evaluate and continuously improve security program maturity by deploying and managing security tools and processes.

Requirements

  • 5 years minimum experience in application security, secure software development, security engineering, or a related role.
  • Strong understanding of secure coding practices and ability to guide developers through remediation strategies.
  • Experience with GitHub Advanced Security (GHAS) including:
    • Code Scanning (SAST)
    • Secret Scanning
    • Dependency Review
  • Proficiency with SAST, DAST, and SCA tools (examples include CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode).
  • Hands-on experience integrating security testing tools into CI/CD pipelines for automated scanning, including designing and building pipeline workflows.
  • Hands-on penetration testing and offensive security experience across web applications, APIs, or cloud infrastructure.
  • Knowledge of common application security vulnerabilities and mitigations including OWASP Top 10 and CWE, with a focus on business logic flaws and API security.
  • Ability to perform threat modeling and participate in design or architecture spec reviews to assess security risks.
  • Experience conducting security code reviews across programming languages such as Python, Java, TypeScript, and Go.
  • Security fundamentals mapped to cybersecurity and compliance frameworks, especially NIST CSF (also includes PCI, SOC2, HITRUST, ISO 27001/2, or similar).
  • Strong understanding of AWS security services and controls (including IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, including deploying security tools within them.
  • Ownership mindset with the ability to work independently with minimal oversight, delivering results in a fast-paced environment while balancing multiple priorities.
  • Continually learns and adapts, valuing correctness, efficiency, and constructive feedback.

Technologies

  • NIST CSF
  • GitHub Advanced Security (GHAS): Code Scanning, Secret Scanning, Dependency Review
  • SAST, DAST, SCA
  • CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode
  • CI/CD
  • OWASP Top 10, CWE
  • Python, Java, TypeScript, Go
  • PCI, SOC2, HITRUST, ISO 27001/2
  • AWS: IAM, VPC, KMS, GuardDuty, CloudTrail
  • OSCP, GWAPT, CISSP, CISA
  • Claude

Preferred

  • Experience in ad-tech or programmatic advertising, or another high-scale real-time environment.
  • Familiarity with using AI/LLM-based tools (for example, Claude or similar) for threat intelligence, alert triage, or security automation.
  • Cybersecurity certification such as OSCP, GWAPT, CISSP, CISA, etc.

Location and Compensation

  • Location: Hoboken, NJ (onsite)
  • Salary: USD 160,000 - 200,000 per year

Life at TripleLift

  • Team culture focused on people who like who they work with and aim to help everyone around them improve.
  • Continuous innovation and fast-moving execution.
  • Learn more via TripleLift’s LinkedIn Life page.

People, Culture and Community Initiatives

  • Commitment to building a culture that helps people feel connected, supported, and empowered.
  • Investment in employees and encouragement of curiosity, shared values, and meaningful connections across teams and communities.
  • Focus on ensuring talent of every background, viewpoint, and experience can be hired, belong, and develop.
  • People, Culture, and Community initiatives designed to help everyone thrive and feel a sense of belonging.

Privacy Policy

  • See TripleLift and 1plusX websites for Privacy Policies.
  • TripleLift does not accept unsolicited resumes from recruitment search firms.

Similar Jobs