TripleLift

Senior Application Security Engineer

TripleLift
Apply
2 months ago
London, United Kingdom or New York, NY, USASenior
H1B sponsor

Base Salary

$125k - $165k/yr

Responsibilities

  • Build and maintain a global security compliance program based on NIST CSF.
  • Scale application security through automated SAST, DAST, and code-review testing.
  • Champion secure software development practices and support secure coding remediation.
  • Automate security testing in CI/CD pipelines and build and maintain pipeline integrations.
  • Administer and drive adoption of GitHub Advanced Security across engineering repositories.
  • Conduct threat modeling and design and architecture reviews to identify security risks early.
  • Develop and implement vulnerability management and threat-hunting activities.
  • Own internal penetration testing and vulnerability assessments for applications and infrastructure, and validate third-party penetration test findings.
  • Monitor and respond to application-layer threats including API abuse, business logic flaws, and common web vulnerabilities.
  • Partner with product and engineering teams on authentication, authorization, data protection, and secure software architecture.
  • Facilitate security incident handling, security education, secure coding guidelines, and developer training.
  • Evaluate and improve security program maturity through security tools and processes.

Requirements

  • At least 5 years of experience in application security, secure software development, security engineering, or a similar role.
  • Strong understanding of secure coding practices and the ability to guide developers on remediation strategies.
  • Experience with GitHub Advanced Security, including code scanning, secret scanning, and dependency review.
  • Proficiency with SAST, DAST, and SCA tools such as CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, and Veracode.
  • Hands-on experience integrating security testing tools into CI/CD pipelines and designing pipeline workflows.
  • Hands-on penetration testing and offensive security experience across web applications, APIs, or cloud infrastructure.
  • Knowledge of application security vulnerabilities and mitigations, including OWASP Top 10, CWE, business logic flaws, and API security.
  • Ability to perform threat modeling and participate in design and architecture reviews.
  • Experience conducting security code reviews across languages such as Python, Java, TypeScript, and Go.
  • Understanding of cybersecurity and compliance frameworks, particularly NIST CSF, with familiarity with PCI, SOC 2, HITRUST, or ISO 27001/2 preferred.
  • Strong understanding of AWS security services and controls, including IAM, VPC, KMS, GuardDuty, and CloudTrail, plus experience securing cloud-native environments.
  • Preferred experience in ad tech, programmatic advertising, or another high-scale, real-time environment.
  • Familiarity with AI/LLM-based tools such as Claude for threat intelligence, alert triage, or security automation is preferred.
  • A cybersecurity certification such as OSCP, GWAPT, CISSP, or CISA is preferred.
  • Ability to take ownership, work independently with minimal oversight, balance multiple priorities, and continuously learn.

Benefits

  • Medical, dental, and vision plans are available to eligible employees.
  • Flexible paid time off is available.
  • 401(k) with employer match is available.
  • Full-time employees are eligible for comprehensive benefits subject to applicable plan terms.
  • Additional rewards may include bonuses and region-specific benefits.
TripleLift

About TripleLift

201-500 employees

TripleLift is a creative supply-side platform that supports programmatic advertising across online video, connected TV, display, and native formats for publishers, advertisers, and agencies. It provides a marketplace and ad-tech tools to monetize inventory and execute media buying, earning transaction-based fees. Founded in 2012 and headquartered in New York, the company is owned by Vista Equity Partners and handles over 1 trillion ad transactions each month.

Contact me