
Senior Application Security Engineer
TripleLift2 months ago
London, United KingdomSenior
Responsibilities
- Build and maintain a global security compliance program based on NIST CSF.
- Develop automated security testing with enterprise SAST, DAST, and code-review tools.
- Promote secure application development and coordinate secure coding remediation activities.
- Automate security testing in CI/CD pipelines and maintain the related pipeline integrations.
- Administer and drive adoption of GitHub Advanced Security across engineering repositories.
- Participate in threat modeling and design and architecture reviews.
- Develop and implement vulnerability management and threat-hunting activities.
- Conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate third-party penetration test findings.
- Monitor and respond to application-layer threats including API abuse, business logic flaws, and common web vulnerabilities.
- Help teams implement authentication, authorization, and data protection mechanisms.
- Facilitate security incident handling and provide secure development training and security awareness education.
- Evaluate and improve security program maturity through security tools and processes.
Requirements
- At least five years of experience in application security, secure software development, security engineering, or a similar role.
- Strong understanding of secure coding practices and ability to guide developers on remediation strategies.
- Experience with GitHub Advanced Security, including Code Scanning, Secret Scanning, and Dependency Review.
- Proficiency with SAST, DAST, and SCA tools such as CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, and Veracode.
- Hands-on experience integrating security testing tools into CI/CD pipelines and designing and building pipeline workflows.
- Hands-on penetration testing and offensive security experience across web applications, APIs, or cloud infrastructure.
- Knowledge of OWASP Top 10, CWE, business logic flaws, and API security.
- Experience with threat modeling, architecture reviews, and security code reviews across programming languages such as Python, Java, TypeScript, and Go.
- Understanding of NIST CSF and other cybersecurity or compliance frameworks such as PCI, SOC2, HITRUST, and ISO 27001/2.
- Strong understanding of AWS security services and controls, including IAM, VPC, KMS, GuardDuty, and CloudTrail, plus experience securing cloud-native environments.
- Preferred experience in ad-tech, programmatic advertising, or another high-scale real-time environment.
- Preferred familiarity with AI/LLM-based tools such as Claude for threat intelligence, alert triage, or security automation.
- Cybersecurity certification such as OSCP, GWAPT, CISSP, or CISA is preferred.
Benefits
- Collaborative and inclusive workplace culture with People, Culture, and Community initiatives.
- Opportunities to work cross-functionally with Engineering, Platform, Cloud Infrastructure, Security, product, and engineering teams.
- The role supports a global security program in a high-scale, real-time advertising technology environment.
About TripleLift
TripleLift is a creative supply-side platform that supports programmatic advertising across online video, connected TV, display, and native formats for publishers, advertisers, and agencies. It provides a marketplace and ad-tech tools to monetize inventory and execute media buying, earning transaction-based fees. Founded in 2012 and headquartered in New York, the company is owned by Vista Equity Partners and handles over 1 trillion ad transactions each month.