Arrowstreet Capital, L.P.

Senior Application Security Engineer

Arrowstreet Capital, L.P.
Apply
1 day ago
Boston, MA, USASenior

Base Salary

$110k - $315k/yr

Responsibilities

  • Build and enhance a modern DevSecOps ecosystem and strengthen application and pipeline security throughout the software development lifecycle.
  • Modernize vulnerability management with AI-driven risk analysis, prioritization, and remediation recommendations.
  • Lead threat modeling and security reviews for AI-enabled systems and define security metrics for AI application risk exposure.
  • Define and maintain secure SDLC policies, procedures, workflows, and actionable technical requirements.
  • Implement CI/CD security controls including SAST, DAST, SCA, secret detection, container scanning, and API testing.
  • Collaborate with development teams to explain vulnerabilities and guide risk-based remediation.
  • Advance software supply chain security through dependency governance, artifact integrity, SBOM adoption, and third-party risk management.
  • Build automated vulnerability and risk measurement with promotion guardrails that balance security and delivery speed.
  • Develop dashboards, reporting, secure coding guidance, technical documentation, and training for engineering and business stakeholders.
  • Support incident response for application and pipeline security events.

Requirements

  • Experience in application security, DevSecOps, secure SDLC, vulnerability management, or security engineering.
  • Ability to use frontier AI models for secure code scanning, vulnerability discovery, and application penetration testing.
  • Experience building dashboards that communicate risk indicators, trends, and actionable insights.
  • Hands-on experience collaborating with developers to remediate vulnerabilities.
  • Proficiency with CI/CD platforms and source control tools such as GitHub, GitLab, Azure DevOps, and Jenkins.
  • Experience with application security testing tools and security reviews of application architectures and APIs.
  • Programming or scripting experience with Python, PowerShell, Bash, C#, Java, JavaScript/TypeScript, or Ruby.
  • Working knowledge of AWS and Azure cloud security concepts.
  • Familiarity with application security frameworks, secure coding, threat modeling, and standards including NIST, CIS, ISO 27001, SOC 2, PCI DSS, OWASP Top 10, and CWE/SANS 25.
  • Experience with containers and cloud-native platforms such as Docker, Kubernetes, ECS, EKS, AKS, or OpenShift is desired.
  • Experience leading or maturing application security or DevSecOps programs, software supply chain security, threat modeling methodologies, and secure coding training is a plus.
  • Relevant certifications such as CSSLP, CISSP, GWAPT, GWEB, OSWE, AWS Security, or Azure Security are an asset.
  • Strong communication, collaboration, analytical, problem-solving, project management, independent leadership, and risk-based decision-making skills.

Benefits

  • Base salary plus annual discretionary bonuses and a robust benefits package.
  • Boston-based systematic investment firm environment with a merit-based compensation culture.
  • Reasonable accommodations are available for qualified individuals with disabilities and disabled veterans.

Tech Stack

AWSAzureBashC#DockerJavaJavaScriptJenkinsKubernetesOpenShiftPowerShellPythonRubyTypeScript

Categories

Arrowstreet Capital, L.P.

About Arrowstreet Capital, L.P.

501-1,000 employees

Arrowstreet Capital, L.P. is a Boston-based quantitative investment manager that builds systematic, research-driven equity strategies for institutional investors such as pensions, endowments, and foundations. Its products span global and international equity portfolios, including long-only and alternative mandates, with revenues from management and performance fees. Founded in 1999 as a privately held partnership, the firm leverages data science and modern infrastructure to power its investment and risk processes.

Contact me