Senior Application Security Engineer
$220,000–$235,000 year
On-siteNew York City, New York, United States
Job Summary
Own vulnerability management end to end: identify, triage, prioritize by real-world risk, and drive remediation across our product, codebases, and cloud infrastructure on AWS, GCP, and Cloudflare. Build and operate the AppSec tooling pipeline, including secrets scanning in CI, SCA/dependency scanning with triage SLAs, and SAST rollout on sensitive repos. Set and enforce security hygiene standards within codebases, explicitly accounting for AI-generated code through authorship transparency and mandatory human review on security-sensitive paths. Partner with the internal AI team to design guardrails that keep AI-assisted development safe by default, covering sanctioned tooling, data handling boundaries, and dependency vetting. Secure the SaaS stack by hardening configurations, reviewing OAuth grants, and reducing misconfiguration risk across platforms like Google Workspace, GitHub, Rippling, and Slack. Establish conditional access and identity-layer controls in partnership with IT, including SSO, phishing-resistant MFA, and managed-device posture. Define cloud and SaaS configuration baselines for the infrastructure footprint. Contribute to detection and response readiness by developing high-signal detections and participating in incident response when needed. Work cross-functionally with Engineering, IT, and the internal AI team to articulate risk and remediation paths to both technical and non-technical stakeholders.
Required Qualifications
- 5+ years of hands-on security engineering experience
- significant time in application security or product security
- Strong software engineering fundamentals
- comfortable reading, writing, and remediating code
- Deep experience with the modern AppSec toolchain
- secrets scanning
- SCA/dependency scanning
- SAST
- CI/CD security integration
- GitHub-centric toolchain
- Practical experience securing SaaS environments
- OAuth and third-party app review
- configuration hardening
- least-privilege access design
- Working knowledge of cloud security across AWS and/or GCP
- edge/CDN security
- Cloudflare
- A pragmatic, risk-based mindset
- Strong perspective on AI-assisted development security
- Track record of partnering with engineering teams as an enabler
- Excellent communication skills
- ability to work independently in a fast-paced environment
- Strong writing skills
Desired Qualifications
- Experience building security programs at an early-to-mid stage company
- taking a function from reactive to systematic
- Experience with SaaS security posture management
- CSPM
- identity threat detection
- Familiarity with securing LLM-based tooling
- agentic workflows
- internal AI platforms
- Detection engineering experience
- SIEM/MDR
- high-signal alerting
- Fintech or financial services environment experience
- Offensive security background
- pentesting
- bug bounty
- red team
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.