Zeta Global logo
Zeta GlobalPosted 1 month ago

Lead Application Security Engineer

$140,000–$180,000 year

RemoteUnited States or New York City, New York, United States

Full TimeSenior LevelLargeMarketing Technology

Job Summary

Conduct AI-driven threat modeling and security validation by leveraging automated tools to evaluate architecture, code, APIs, and data flows for gaps. Embed AI-native security into the SDLC by building automation that provides real-time feedback during design, coding, testing, and deployment. Monitor emerging threats including prompt injection and model abuse while designing proactive defense mechanisms across applications and AI systems. Collaborate with Engineering, DevOps, QA, and Product teams to foster a security-first culture using metrics to measure control effectiveness and developer adoption.

Required Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience
  • 5+ years of experience in Application Security, DevSecOps, Secure Software Development, or Security Engineering
  • Strong understanding of OWASP Top 10, SANS CWE Top 25, secure design principles, and application threat modeling
  • Familiarity with AI/ML security concepts such as prompt injection, data poisoning, adversarial testing, model integrity, model abuse, and AI supply-chain risks
  • Experience building or integrating AI-assisted security workflows, security bots, automated triage systems, or risk scoring models
  • Experience using AI-assisted or automation-driven approaches to improve security testing, vulnerability analysis, code review, or risk prioritization
  • Experience with modern application frameworks and architectures such as React, Node.js, Django, FastAPI, or similar technologies
  • Knowledge of securing APIs, microservices, authentication, and authorization mechanisms such as OAuth2, OIDC, JWT, and service-to-service authentication
  • Experience with cloud platforms such as AWS, GCP, or Azure, and containerized environments such as Docker and Kubernetes
  • Working knowledge of security testing and automation tools such as Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security, or similar tools
  • Ability to analyze security findings, correlate risk context, and drive practical remediation guidance for engineering teams
  • Strong collaboration and communication skills with the ability to work across Engineering, Product, QA, DevOps, and Security teams

Desired Qualifications

  • Experience with policy-as-code, infrastructure-as-code security, CI/CD security controls, and automated governance
  • Experience with automation frameworks and scripting for security testing, vulnerability validation, and remediation workflows
  • Relevant certifications such as OSCP, GWAPT, CSSLP, cloud security certifications, or AI/ML-specific security certifications

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce