Senior Application Security Engineer
Senior
Application Security
Code Scanning
Cybersecurity Tools
Dependency Scanning
DevSecOps
Dynamic Application Security Testing
Information Security
InfoSec
Secret Scanning
Security Automation
Security Compliance
Security Standards
Security Testing
Software Security
Static Application Security Testing
Static Code Analysis
Job Description
TripleLift is looking for a Senior Application Security Engineer in Hoboken, NJ to help strengthen the company’s application security and secure development practices. In partnership with Engineering, Platform, Cloud Infrastructure, and Security teams, you will scale application security through automated testing, CI/CD integrations, vulnerability management, threat modeling, and security incident handling.
What you will do
- Build and maintain a global security compliance program based on NIST CSF.
- Scale application security by developing automated security testing using enterprise SAST, DAST, and code-review tools.
- Champion SDLC practices to support secure application development and infrastructure deployment, including facilitating secure coding remediation.
- Automate security testing in CI/CD pipelines to detect vulnerabilities earlier, including building and maintaining the pipeline integrations.
- Administer and drive adoption of GitHub Advanced Security (GHAS), including code scanning, secret scanning, and dependency review across engineering repositories.
- Participate in threat modeling and design and architecture specification reviews to identify and mitigate security risks early in the SDLC.
- Coordinate with stakeholders to develop and implement a vulnerability management program and perform threat-hunting activities.
- Own and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, including validating findings from third-party pentest engagements.
- Monitor and respond to application-layer threats such as API abuses, business logic flaws, and common web vulnerabilities.
- Collaborate with product and engineering teams to ensure security is a key consideration in software design and architecture.
- Improve the application security posture by implementing mechanisms for authentication, authorization, and data protection.
- Enhance and facilitate security incident handling activities.
- Evangelize security best practices through education and awareness, including developing secure coding guidelines and conducting secure development training for engineers.
- Evaluate and continuously improve program maturity by deploying and managing security tools and processes.
Qualifications
- 5 years minimum of experience in application security, secure software development, security engineering, or a similar role.
- Strong secure coding knowledge and the ability to guide developers on remediation strategies.
- Experience with GitHub Advanced Security (GHAS): Code Scanning (SAST), Secret Scanning, and Dependency Review.
- Proficiency with SAST, DAST, and SCA tools, including examples such as CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, and Veracode.
- Hands-on experience integrating security testing tools into CI/CD pipelines, including designing and building pipeline workflows.
- Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure.
- Knowledge of common application security vulnerabilities and mitigations such as OWASP Top 10 and CWE, including business logic flaws and API security.
- Ability to perform threat modeling and participate in design and architecture spec reviews.
- Experience conducting security code reviews across languages including Python, Java, TypeScript, and Go.
- Security fundamentals aligned to compliance frameworks, particularly NIST CSF, and optionally PCI, SOC2, HITRUST, ISO 27001/2, or similar.
- Strong understanding of AWS security services and controls including IAM, VPC, KMS, GuardDuty, and CloudTrail, with experience securing cloud-native environments and deploying security tools in them.
- Ownership mindset with the ability to work independently with minimal oversight, delivering results in a fast-paced environment while balancing multiple priorities.
- Commitment to continuous learning and improvement, with focus on correctness, efficiency, and constructive feedback.
Technologies
- NIST CSF
- GitHub Advanced Security (GHAS)
- Code Scanning, Secret Scanning, Dependency Review
- SAST, DAST, SCA
- CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode
- CI/CD
- OWASP Top 10, CWE
- Python, Java, TypeScript, Go
- PCI, SOC2, HITRUST, ISO 27001/2
- AWS, IAM, VPC, KMS, GuardDuty, CloudTrail
- OSCP, GWAPT, CISSP, CISA
- Claude
Preferred qualifications
- Experience in the ad-tech or programmatic advertising industry, or another high-scale, real-time environment.
- Preferred familiarity with using AI or LLM-based tools (for example, Claude or similar) for threat intelligence, alert triage, or security automation.
- Cybersecurity certification such as OSCP, GWAPT, CISSP, CISA, or similar.
Life at TripleLift
- At TripleLift, the team values great people who like working with one another and who help everyone around them improve.
- There is an emphasis on working with high drive and continuous innovation.
- Learn more about TripleLift and culture via its LinkedIn Life page.
People, Culture, and Community initiatives
- TripleLift is committed to building a culture where people feel connected, supported, and empowered.
- The company invests in people and encourages curiosity, shared values, and meaningful connections across teams and communities.
- There is a commitment to hiring and developing the best talent from every background, viewpoint, and experience.
- The goal is an environment where everyone can thrive and feel a true sense of belonging.
Location and compensation
- Location: Hoboken, NJ (onsite)
- Salary: USD 160,000 - 200,000 per year
Privacy policy
- Please see TripleLift’s Privacy Policies on its TripleLift and 1plusX websites.
- TripleLift does not accept unsolicited resumes from any type of recruitment search firm.