GrepJob
TripleLift

Senior Application Security Engineer

TripleLift
Apply
about 4 hours ago
London, United Kingdom or New York, NY, USASenior
H1B Sponsor

Base Salary

$125k - $165k/yr

Responsibilities

  • Build and maintain a global security compliance program based on NIST CSF.
  • Develop automated security testing using enterprise SAST, DAST, and code-review tools.
  • Promote secure application development and facilitate secure coding remediation activities.
  • Automate security testing in CI/CD pipelines to detect vulnerabilities early.
  • Administer and drive adoption of GitHub Advanced Security across engineering repositories.
  • Participate in threat modeling and design/architecture spec reviews.
  • Coordinate with stakeholders to develop and implement a vulnerability management program.
  • Conduct internal penetration testing and vulnerability assessments.
  • Monitor and respond to application-layer security threats.
  • Collaborate with product and engineering teams to ensure security in software design.
  • Enhance application security posture with proper authentication and data protection mechanisms.
  • Facilitate security incident handling activities.
  • Evangelize security best practices and provide education to employees.
  • Evaluate and improve the maturity of the security program.

Requirements

  • 5+ years of experience in application security or a similar role.
  • Strong understanding of secure coding practices.
  • Experience with GitHub Advanced Security, including code scanning and secret scanning.
  • Proficiency in SAST, DAST, and SCA tools.
  • Hands-on experience integrating security testing tools into CI/CD pipelines.
  • Experience in penetration testing across web applications and APIs.
  • Knowledge of common application security vulnerabilities and mitigations.
  • Ability to perform threat modeling and participate in design reviews.
  • Experience conducting security code reviews across various programming languages.
  • Understanding of security fundamentals related to cybersecurity frameworks.
  • Strong understanding of AWS security services and controls.
  • Ability to work independently and deliver results in a fast-paced environment.
  • Continuous learner who values correctness and constructive feedback.

Benefits

  • Medical, Dental & Vision Plans.
  • Flexible PTO.
  • 401k with employer match.