Senior Application Security Engineer
Senior
Ai Security
Application Security
Application Security Engineering
Container Security
DevSecOps
Dynamic Application Security Testing
Engineer
Information Security
InfoSec
Secrets Scanning
Security Automation
Security Testing
Static Application Security Testing
Static Code Analysis
Threat Modeling
Job Description
Arrowstreet Capital is hiring a Senior Application Security Engineer to embed application security controls across the software development lifecycle and CI/CD pipelines.
Responsibilities
- Manage and improve pipeline security posture by building a modern DevSecOps ecosystem that uses secure workflows and vulnerability management across the development lifecycle.
- Modernize vulnerability management by integrating AI-driven analysis that maps technical risk to business impact for more informed prioritization and remediation.
- Explore and implement responsible AI use to enhance vulnerability discovery, code review, threat modeling, risk prioritization, security monitoring, and remediation recommendations.
- Lead threat modeling and security reviews for AI-enabled systems, including risks such as prompt injection, insecure handling of model outputs, sensitive data disclosure, model abuse, excessive agency, and data or model poisoning.
- Define metrics and reporting that communicate the security posture and risk exposure of AI-enabled applications to technical teams and senior leadership.
- Define and maintain secure SDLC policies, procedures, and workflows, translating them into actionable technical requirements.
- Drive security controls in CI/CD pipelines, including SAST, DAST, SCA, secret detection, container scanning, and API testing.
- Partner with development teams to explain findings, risks, and remediation steps, guiding fixes using an internal risk matrix that ties attack vectors to business objectives.
- Advance software supply chain security with dependency governance, artifact integrity, SBOM adoption, and third-party risk management.
- Improve pipelines with automated vulnerability and risk measurement, and implement promotion guardrails that balance effective risk management with delivery speed.
- Support incident response for application and pipeline security events.
Requirements
- Ability to leverage frontier AI models to enhance secure code scanning, vulnerability discovery, and application penetration testing.
- Experience in application security, DevSecOps, secure SDLC, vulnerability management, or security engineering.
- Experience building advanced dashboards for key risk indicators, trends, and actionable insights for technical and business stakeholders.
- Hands-on experience collaborating with developers to remediate vulnerabilities.
- Proficiency with CI/CD platforms and source control tools, including GitHub, GitLab, Azure DevOps, Jenkins, etc.
- Use experience with application security testing tools: SAST, DAST, SCA, container scanning, API testing, etc.
- Experience conducting security reviews of application architectures and APIs to identify design weaknesses, vulnerabilities, and potential attack paths.
- Familiarity with modern architectures such as microservices, containers, APIs, and cloud-native apps.
- Programming/scripting experience: Python, PowerShell, Bash, C#, Java, JS/TS, Ruby, etc.
- Working knowledge of AWS/Azure cloud security concepts.
- Experience developing technical documentation and secure coding guides.
- Effective communication of technical security concepts.
- Strong collaboration and relationship-building skills.
- Ability to influence secure development practices and drive adoption.
- Adaptability to pivot strategy or priorities when facing technical challenges or evolving scope.
- Risk-based mindset that accounts for both business and delivery needs.
- Initiative and independent leadership with strong project management.
- Analytical and detail-oriented with excellent problem solving.
- Thrives in fast-paced, multi-team environments.
- Metrics-driven approach to program effectiveness.
- Clear written and verbal communication of vulnerabilities and remediation.
- Passion for enabling secure development through automation, training, and scalable processes.
- Familiarity with frameworks/standards: NIST, CIS, ISO 27001, SOC 2, PCI DSS.
- Some knowledge of application security risks and frameworks: OWASP Top 10, CWE/SANS 25, secure coding, and threat modeling.
- Developer-first tools and integration (pull requests, issue tracking, IDEs) preferred.
- Threat modeling methodologies such as STRIDE, attack trees, and agile models.
- Experience with containers and cloud-native platforms (desired): Docker, Kubernetes, ECS/EKS/AKS/OpenShift.
- Relevant certifications are an asset: CSSLP, CISSP, GWAPT, GWEB, OSWE, and AWS/Azure Security.
Technology Focus
- AI-driven analysis, frontier AI models
- SAST, DAST, SCA, secret detection, container scanning, API testing
- CI/CD pipelines, GitHub, GitLab, Azure DevOps, Jenkins
- Python, PowerShell, Bash, C#, Java, JS/TS, Ruby
- AWS/Azure cloud security concepts; microservices, containers, APIs, cloud-native apps
- SBOM, dependency governance, artifact integrity, third-party risk management
- NIST, CIS, ISO 27001, SOC 2, PCI DSS; OWASP Top 10, CWE/SANS 25
- Threat modeling: STRIDE, attack trees, agile models
- Docker, Kubernetes, ECS/EKS/AKS/OpenShift
Compensation
- $110,000 - $315,000 per year
Location
- Boston, MA (onsite)
Additional Information
- Total compensation approach includes base salaries, annual discretionary bonuses, and a benefits package.
- Base salary placement within the range varies based on relevant experience and qualifications, including relevant certifications/credentials/education, role scope, and other factors.
- The salary range is an estimate; additional compensation details will be communicated during recruitment.
- Arrowstreet Capital provides reasonable accommodations for qualified individuals with disabilities; contact them to discuss accommodation needs during the employment process.