TripleLift

Senior Application Security Engineer

TripleLift
Apply
about 5 hours ago
London, United KingdomSenior
H1B Sponsor

Responsibilities

  • Build and maintain a global security compliance program based on NIST CSF.
  • Develop automated SAST, DAST, and code-review security testing and scale its adoption across engineering.
  • Promote secure software development practices and coordinate secure coding remediation activities.
  • Build and maintain CI/CD pipeline integrations for automated vulnerability scanning.
  • Administer and drive adoption of GitHub Advanced Security code scanning, secret scanning, and dependency review.
  • Conduct threat modeling and architecture reviews to identify and mitigate security risks early.
  • Develop and implement vulnerability management and threat-hunting activities.
  • Own internal penetration testing and vulnerability assessments and validate third-party penetration test findings.
  • Monitor and respond to application-layer threats including API abuse, business logic flaws, and common web vulnerabilities.
  • Partner with engineering and product teams on authentication, authorization, data protection, and secure software architecture.
  • Support security incident handling, security education, secure coding guidelines, and developer training.
  • Evaluate and improve security program maturity through security tools and processes.

Requirements

  • At least five years of experience in application security, secure software development, security engineering, or a similar role.
  • Strong understanding of secure coding practices and the ability to guide developers on remediation strategies.
  • Experience with GitHub Advanced Security, including code scanning, secret scanning, and dependency review.
  • Proficiency with SAST, DAST, and SCA tools such as CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, or Veracode.
  • Hands-on experience integrating security testing tools into CI/CD pipelines and designing pipeline workflows.
  • Hands-on penetration testing or offensive security experience across web applications, APIs, or cloud infrastructure.
  • Knowledge of OWASP Top 10, CWE, business logic flaws, API security, and related mitigations.
  • Ability to perform threat modeling and participate in application and service architecture reviews.
  • Experience conducting security code reviews across languages such as Python, Java, TypeScript, and Go.
  • Understanding of cybersecurity and compliance frameworks, particularly NIST CSF, with familiarity with PCI, SOC 2, HITRUST, or ISO 27001/2 preferred.
  • Strong understanding of AWS security services and controls, including IAM, VPC, KMS, GuardDuty, and CloudTrail.
  • Experience in ad-tech, programmatic advertising, or another high-scale real-time environment is preferred.
  • Familiarity with AI/LLM-based tools such as Claude for threat intelligence, alert triage, or security automation is preferred.
  • A cybersecurity certification such as OSCP, GWAPT, CISSP, or CISA is preferred.
TripleLift

About TripleLift

201-500 employees

TripleLift is the Creative SSP that transforms digital advertising through creative technology and innovative ad formats. We help publishers, advertisers, and agencies achieve measurable outcomes while enhancing user experiences. Discover how we bring creativity and results together.