
Senior Application Security Engineer
Arrowstreet Capital, L.P.1 day ago
Boston, MA, USASenior
Base Salary
$110k - $315k/yr
Responsibilities
- Build and enhance a modern DevSecOps ecosystem and strengthen application and pipeline security throughout the software development lifecycle.
- Modernize vulnerability management with AI-driven risk analysis, prioritization, and remediation recommendations.
- Lead threat modeling and security reviews for AI-enabled systems and define security metrics for AI application risk exposure.
- Define and maintain secure SDLC policies, procedures, workflows, and actionable technical requirements.
- Implement CI/CD security controls including SAST, DAST, SCA, secret detection, container scanning, and API testing.
- Collaborate with development teams to explain vulnerabilities and guide risk-based remediation.
- Advance software supply chain security through dependency governance, artifact integrity, SBOM adoption, and third-party risk management.
- Build automated vulnerability and risk measurement with promotion guardrails that balance security and delivery speed.
- Develop dashboards, reporting, secure coding guidance, technical documentation, and training for engineering and business stakeholders.
- Support incident response for application and pipeline security events.
Requirements
- Experience in application security, DevSecOps, secure SDLC, vulnerability management, or security engineering.
- Ability to use frontier AI models for secure code scanning, vulnerability discovery, and application penetration testing.
- Experience building dashboards that communicate risk indicators, trends, and actionable insights.
- Hands-on experience collaborating with developers to remediate vulnerabilities.
- Proficiency with CI/CD platforms and source control tools such as GitHub, GitLab, Azure DevOps, and Jenkins.
- Experience with application security testing tools and security reviews of application architectures and APIs.
- Programming or scripting experience with Python, PowerShell, Bash, C#, Java, JavaScript/TypeScript, or Ruby.
- Working knowledge of AWS and Azure cloud security concepts.
- Familiarity with application security frameworks, secure coding, threat modeling, and standards including NIST, CIS, ISO 27001, SOC 2, PCI DSS, OWASP Top 10, and CWE/SANS 25.
- Experience with containers and cloud-native platforms such as Docker, Kubernetes, ECS, EKS, AKS, or OpenShift is desired.
- Experience leading or maturing application security or DevSecOps programs, software supply chain security, threat modeling methodologies, and secure coding training is a plus.
- Relevant certifications such as CSSLP, CISSP, GWAPT, GWEB, OSWE, AWS Security, or Azure Security are an asset.
- Strong communication, collaboration, analytical, problem-solving, project management, independent leadership, and risk-based decision-making skills.
Benefits
- Base salary plus annual discretionary bonuses and a robust benefits package.
- Boston-based systematic investment firm environment with a merit-based compensation culture.
- Reasonable accommodations are available for qualified individuals with disabilities and disabled veterans.
Tech Stack
Categories
About Arrowstreet Capital, L.P.
Arrowstreet Capital, L.P. is a Boston-based quantitative investment manager that builds systematic, research-driven equity strategies for institutional investors such as pensions, endowments, and foundations. Its products span global and international equity portfolios, including long-only and alternative mandates, with revenues from management and performance fees. Founded in 1999 as a privately held partnership, the firm leverages data science and modern infrastructure to power its investment and risk processes.