Sr Application Security Engineer
$113,500–$208,100 year
On-siteBellevue, Washington, United States
Job Summary
Extend and own scalable application security tooling across SAST/DAST pipelines, vulnerability management, and threat modeling frameworks. Validate findings end-to-end by triaging scanner output and contextualizing risk for engineering teams. Review new features and APIs, conducting security-focused code reviews and application-layer penetration tests in C#, Java, JavaScript, or similar. Write production-quality security automation that ships alongside security guidance, and assess AI/ML systems including LLM integrations and GenAI attack surfaces. Drive security culture through direct engineering partnership, advising on secure-by-design patterns and raising the security floor across hundreds of engineers. Participate in governance-first frameworks to develop standards, guidelines, and secure baselines.
Required Qualifications
- BS degree or equivalent years of experience in related field
- 6-8+ years in application security with a track record of building tooling and automation, not just operating it
- Active software development experience — you write clean, production-ready code in at least one of: C#, Java, Python, Go, or JavaScript
- Hands-on experience with SAST, DAST, SCA, and secrets management tooling, including configuration, tuning, and CI/CD integration (GitHub Actions, GitLab, Jenkins, ArgoCD, or similar)
- Practical threat modeling experience (STRIDE, PASTA, or equivalent) — producing engineering-useful outputs, not just risk documentation
- Experience with vulnerability management workflows: aggregation, triage, risk-based prioritization, and driving remediation at scale
- Working knowledge of Kubernetes and container security (Docker, Helm, Istio) and cloud security fundamentals across at least one major platform (AWS, GCP, or Azure)
- Experience in AI/ML security — securing AI pipelines, assessing LLM integrations, understanding GenAI attack surfaces, or building AI-assisted security tooling
Desired Qualifications
- Strong written and verbal communication skills — able to translate technical risk into terms that resonate with engineering teams, product leadership, and the broader customer-first mindset that drives decisions at The Trade Desk
- Certifications such as OSWE, GWAPT, CSSLP, OSCP, or cloud security certifications (AWS, GCP, or Azure) are a plus
- Experience in ad tech, large-scale SaaS, or other high-throughput consumer or enterprise platforms is a plus
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.