Savvy Wealth

Senior Application Security Engineer

Savvy Wealth
Apply
2 months ago

Base Salary

$220k - $235k/yr

Responsibilities

  • Own vulnerability management end to end across the product, codebases, and cloud infrastructure, from identification and triage through remediation closure.
  • Build and operate the AppSec tooling pipeline for secrets scanning, SCA/dependency scanning, and SAST.
  • Set and enforce codebase security hygiene and code review standards that account for AI-generated code.
  • Partner with the internal AI team to create guardrails for AI-assisted development and integrations.
  • Secure the SaaS stack by hardening configurations, reviewing OAuth grants and third-party integrations, and reducing misconfiguration risk.
  • Help establish conditional access and identity controls, including SSO, phishing-resistant MFA, and managed-device posture.
  • Define cloud and SaaS configuration baselines for the company’s infrastructure footprint.
  • Improve detection and incident response readiness with high-signal detections and incident response participation.
  • Work cross-functionally with Engineering, IT, and the internal AI team to communicate risks, remediation paths, and tradeoffs.

Requirements

  • At least 5 years of hands-on security engineering experience, including significant application security or product security work.
  • Strong software engineering fundamentals and the ability to read, write, and remediate code.
  • Deep experience with secrets scanning, SCA/dependency scanning, SAST, and GitHub-centric security integration.
  • Practical experience securing SaaS environments through OAuth and third-party application review, configuration hardening, and least-privilege access design.
  • Working knowledge of cloud security across AWS and/or GCP and edge/CDN security with Cloudflare.
  • Understanding of security risks in AI-assisted development and experience designing practical guardrails.
  • Experience embedding security into engineering workflows and partnering with engineering teams as an enabler.
  • Excellent communication, writing, independent-working, and risk-based prioritization skills.
  • Preferred: experience building security programs at an early- to mid-stage company.
  • Preferred: experience with SaaS security posture management, CSPM, or identity threat detection.
  • Preferred: familiarity with securing LLM-based tooling, agentic workflows, or internal AI platforms.
  • Preferred: detection engineering experience, including SIEM/MDR and high-signal alerting.
  • Preferred: fintech or financial services experience.
  • Preferred: offensive security experience such as penetration testing, bug bounty, or red teaming.

Benefits

  • Unlimited PTO and paid company holidays
  • Medical, dental, and vision plans
  • 401(k), commuter, and HSA/FSA plans
  • NYC office in Manhattan
  • Lunch and snacks provided in the office
  • Virtual mental health care, vision-related benefits, and health concierge services
  • Employee assistance counseling for stress management, dependent care, nutrition, fitness, legal, and financial issues
  • Competitive salary and equity package

Tech Stack

Categories

Savvy Wealth

About Savvy Wealth

51-200 employees

Savvy Wealth is the trusted partner for independent financial advisors, combining infrastructure, service, and intelligent tools to make great advice easier to deliver. Disclosure: Savvy Wealth, Inc. is a tech company and the parent company of Savvy Advisors, Inc. All advisory services are offered through Savvy Advisors, Inc., an investment advisor registered with the Securities and Exchange Commission (“SEC”). The AI used on Savvy Wealth’s advisor platform is not intended to replace human advice. The AI technology efficiently automates and streamlines processes like new account onboarding, ongoing financial planning and personalized communications across multiple marketing channels. The AI is not intended to interact with retail clients of Savvy Advisors, nor does the AI provide client-facing investment advice or investment decisions.

Contact me