CybersecurityJobs.io
← Back to all jobs

Job Description

Arrowstreet Capital is hiring a Senior Application Security Engineer to embed application security controls across the software development lifecycle and CI/CD pipelines.

Responsibilities

  • Manage and improve pipeline security posture by building a modern DevSecOps ecosystem that uses secure workflows and vulnerability management across the development lifecycle.
  • Modernize vulnerability management by integrating AI-driven analysis that maps technical risk to business impact for more informed prioritization and remediation.
  • Explore and implement responsible AI use to enhance vulnerability discovery, code review, threat modeling, risk prioritization, security monitoring, and remediation recommendations.
  • Lead threat modeling and security reviews for AI-enabled systems, including risks such as prompt injection, insecure handling of model outputs, sensitive data disclosure, model abuse, excessive agency, and data or model poisoning.
  • Define metrics and reporting that communicate the security posture and risk exposure of AI-enabled applications to technical teams and senior leadership.
  • Define and maintain secure SDLC policies, procedures, and workflows, translating them into actionable technical requirements.
  • Drive security controls in CI/CD pipelines, including SAST, DAST, SCA, secret detection, container scanning, and API testing.
  • Partner with development teams to explain findings, risks, and remediation steps, guiding fixes using an internal risk matrix that ties attack vectors to business objectives.
  • Advance software supply chain security with dependency governance, artifact integrity, SBOM adoption, and third-party risk management.
  • Improve pipelines with automated vulnerability and risk measurement, and implement promotion guardrails that balance effective risk management with delivery speed.
  • Support incident response for application and pipeline security events.

Requirements

  • Ability to leverage frontier AI models to enhance secure code scanning, vulnerability discovery, and application penetration testing.
  • Experience in application security, DevSecOps, secure SDLC, vulnerability management, or security engineering.
  • Experience building advanced dashboards for key risk indicators, trends, and actionable insights for technical and business stakeholders.
  • Hands-on experience collaborating with developers to remediate vulnerabilities.
  • Proficiency with CI/CD platforms and source control tools, including GitHub, GitLab, Azure DevOps, Jenkins, etc.
  • Use experience with application security testing tools: SAST, DAST, SCA, container scanning, API testing, etc.
  • Experience conducting security reviews of application architectures and APIs to identify design weaknesses, vulnerabilities, and potential attack paths.
  • Familiarity with modern architectures such as microservices, containers, APIs, and cloud-native apps.
  • Programming/scripting experience: Python, PowerShell, Bash, C#, Java, JS/TS, Ruby, etc.
  • Working knowledge of AWS/Azure cloud security concepts.
  • Experience developing technical documentation and secure coding guides.
  • Effective communication of technical security concepts.
  • Strong collaboration and relationship-building skills.
  • Ability to influence secure development practices and drive adoption.
  • Adaptability to pivot strategy or priorities when facing technical challenges or evolving scope.
  • Risk-based mindset that accounts for both business and delivery needs.
  • Initiative and independent leadership with strong project management.
  • Analytical and detail-oriented with excellent problem solving.
  • Thrives in fast-paced, multi-team environments.
  • Metrics-driven approach to program effectiveness.
  • Clear written and verbal communication of vulnerabilities and remediation.
  • Passion for enabling secure development through automation, training, and scalable processes.
  • Familiarity with frameworks/standards: NIST, CIS, ISO 27001, SOC 2, PCI DSS.
  • Some knowledge of application security risks and frameworks: OWASP Top 10, CWE/SANS 25, secure coding, and threat modeling.
  • Developer-first tools and integration (pull requests, issue tracking, IDEs) preferred.
  • Threat modeling methodologies such as STRIDE, attack trees, and agile models.
  • Experience with containers and cloud-native platforms (desired): Docker, Kubernetes, ECS/EKS/AKS/OpenShift.
  • Relevant certifications are an asset: CSSLP, CISSP, GWAPT, GWEB, OSWE, and AWS/Azure Security.

Technology Focus

  • AI-driven analysis, frontier AI models
  • SAST, DAST, SCA, secret detection, container scanning, API testing
  • CI/CD pipelines, GitHub, GitLab, Azure DevOps, Jenkins
  • Python, PowerShell, Bash, C#, Java, JS/TS, Ruby
  • AWS/Azure cloud security concepts; microservices, containers, APIs, cloud-native apps
  • SBOM, dependency governance, artifact integrity, third-party risk management
  • NIST, CIS, ISO 27001, SOC 2, PCI DSS; OWASP Top 10, CWE/SANS 25
  • Threat modeling: STRIDE, attack trees, agile models
  • Docker, Kubernetes, ECS/EKS/AKS/OpenShift

Compensation

  • $110,000 - $315,000 per year

Location

  • Boston, MA (onsite)

Additional Information

  • Total compensation approach includes base salaries, annual discretionary bonuses, and a benefits package.
  • Base salary placement within the range varies based on relevant experience and qualifications, including relevant certifications/credentials/education, role scope, and other factors.
  • The salary range is an estimate; additional compensation details will be communicated during recruitment.
  • Arrowstreet Capital provides reasonable accommodations for qualified individuals with disabilities; contact them to discuss accommodation needs during the employment process.

Similar Jobs