×
Register Here to Apply for Jobs or Post Jobs. X

Senior Application Security Engineer

Job in New York, New York County, New York, 10261, USA
Listing for: TripleLift
Full Time position
Listed on 2026-09-09
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 180000 - 230000 USD Yearly USD 180000.00 230000.00 YEAR
Job Description & How to Apply Below
Location: New York

  • The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within Triple Lift’s Engineering and Security organization, directly influencing how we protect our advertising platforms and the trust our publishers and advertisers place in us
  • In this position, you will partner closely with Engineering, Platform, Cloud Infrastructure, and Security teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security, ensuring security is embedded into how we design, build, deploy, and operate our products
  • This is an exciting opportunity for someone who wants to build and scale an application security program at a company operating at the center of a rapidly evolving, high-stakes ad-tech landscape, while contributing meaningfully to the long‑term security posture and resilience of the organization
  • Play a critical role in building and maintaining a global security compliance program based on NIST CSF
  • Scale application security by developing automated security testing utilizing enterprise SAST, DAST, and code‑review tools
  • Champion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities
  • Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations themselves
  • Administer and drive adoption of Git Hub Advanced Security (GHAS) : code scanning, secret scanning, and dependency review across engineering repositories
  • Participate in threat modeling and design/architecture spec reviews to identify and mitigate security risks early in the SDLC
  • Coordinate with stakeholders to develop and implement a vulnerability management program and to perform threat‑hunting activities
  • Own and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate findings from third‑party pentest engagements
  • Monitor and respond to application‑layer security threats like API abuses, business logic flaws, and common web vulnerabilities
  • Collaborate with product and engineering teams to ensure security is a key consideration in software design and architecture
  • Enhance application security posture by working with cross‑functional teams to implement proper authentication, authorization, and data protection mechanisms
  • Enhance and facilitate security incident handling activities
  • Evangelize security best practices and provide education and awareness to company employees. Develop and implement secure coding guidelines and conduct secure development training for engineers
  • Evaluate and continuously improve the maturity of the security program through the deployment and management of various security tools and processes
Benefits
  • Medical, Dental & Vision Plans
  • Unlimited PTO
  • 401k w/ employer match

Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure

Experience with Git Hub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security)
Experience conducting security code reviews across various programming languages (e.g., Python, Java, Type Script, Go)
Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows

Strong understanding of secure coding practices and ability to guide developers on remediation strategies5+ years of experience in application security, secure software development, security engineering, or a similar role Ability to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and services

Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode)
Continuously learns, adapts, and values correctness, efficiency, and constructive feedback

Strong understanding of AWS security services and controls (IAM, VPC, KMS,…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary