TripleLift

Senior Application Security Engineer

TripleLift
Apply
about 5 hours ago
Toronto, CanadaSenior
H1B Sponsor

Responsibilities

  • Build and maintain a global security compliance program based on NIST CSF.
  • Scale application security through automated SAST, DAST, and code-review testing.
  • Promote secure software development and coordinate secure coding remediation activities.
  • Build and maintain security-testing integrations and automated scanning workflows in CI/CD pipelines.
  • Administer and drive adoption of GitHub Advanced Security across engineering repositories.
  • Conduct threat modeling and architecture reviews to identify and mitigate security risks early.
  • Develop and implement vulnerability management and threat-hunting activities.
  • Own internal penetration testing and vulnerability assessments and validate third-party penetration-test findings.
  • Monitor and respond to application-layer threats including API abuse, business logic flaws, and common web vulnerabilities.
  • Partner with product and engineering teams on secure software design, authentication, authorization, and data protection.
  • Support security incident handling, security education, secure coding guidelines, and secure development training.
  • Evaluate and improve security-program maturity through security tools and processes.

Requirements

  • At least five years of experience in application security, secure software development, security engineering, or a similar role.
  • Strong secure coding knowledge and the ability to guide developers on remediation strategies.
  • Experience with GitHub Advanced Security, including code scanning, secret scanning, and dependency review.
  • Proficiency with SAST, DAST, and SCA tools such as CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, or Veracode.
  • Hands-on experience integrating security testing into CI/CD pipelines and designing pipeline workflows.
  • Hands-on penetration testing and offensive security experience across web applications, APIs, or cloud infrastructure.
  • Knowledge of OWASP Top 10, CWE, business logic flaws, and API security.
  • Ability to conduct threat modeling and participate in application and service architecture reviews.
  • Security code review experience across languages such as Python, Java, TypeScript, and Go.
  • Understanding of cybersecurity and compliance frameworks, particularly NIST CSF, PCI, SOC 2, HITRUST, and ISO 27001/2.
  • Strong understanding of AWS security services and controls, including IAM, VPC, KMS, GuardDuty, and CloudTrail.
  • Preferred experience in ad-tech, programmatic advertising, or another high-scale real-time environment.
  • Preferred familiarity with AI/LLM-based tools such as Claude for threat intelligence, alert triage, or security automation.
  • Preferred cybersecurity certification such as OSCP, GWAPT, CISSP, or CISA.
TripleLift

About TripleLift

201-500 employees

TripleLift is the Creative SSP that transforms digital advertising through creative technology and innovative ad formats. We help publishers, advertisers, and agencies achieve measurable outcomes while enhancing user experiences. Discover how we bring creativity and results together.