The Trade Desk logo
The Trade DeskPosted 1 month ago

Sr Application Security Engineer

$113,500–$208,100 year

On-siteBellevue, Washington, United States

Full TimeSenior LevelLargeTECH

Job Summary

Extend and own scalable application security tooling across SAST/DAST pipelines, vulnerability management, and threat modeling frameworks. Validate findings end-to-end by triaging scanner output and contextualizing risk for engineering teams. Review new features and APIs, conducting security-focused code reviews and application-layer penetration tests in C#, Java, JavaScript, or similar. Write production-quality security automation that ships alongside security guidance, and assess AI/ML systems including LLM integrations and GenAI attack surfaces. Drive security culture through direct engineering partnership, advising on secure-by-design patterns and raising the security floor across hundreds of engineers. Participate in governance-first frameworks to develop standards, guidelines, and secure baselines.

Required Qualifications

  • BS degree or equivalent years of experience in related field
  • 6-8+ years in application security with a track record of building tooling and automation, not just operating it
  • Active software development experience — you write clean, production-ready code in at least one of: C#, Java, Python, Go, or JavaScript
  • Hands-on experience with SAST, DAST, SCA, and secrets management tooling, including configuration, tuning, and CI/CD integration (GitHub Actions, GitLab, Jenkins, ArgoCD, or similar)
  • Practical threat modeling experience (STRIDE, PASTA, or equivalent) — producing engineering-useful outputs, not just risk documentation
  • Experience with vulnerability management workflows: aggregation, triage, risk-based prioritization, and driving remediation at scale
  • Working knowledge of Kubernetes and container security (Docker, Helm, Istio) and cloud security fundamentals across at least one major platform (AWS, GCP, or Azure)
  • Experience in AI/ML security — securing AI pipelines, assessing LLM integrations, understanding GenAI attack surfaces, or building AI-assisted security tooling

Desired Qualifications

  • Strong written and verbal communication skills — able to translate technical risk into terms that resonate with engineering teams, product leadership, and the broader customer-first mindset that drives decisions at The Trade Desk
  • Certifications such as OSWE, GWAPT, CSSLP, OSCP, or cloud security certifications (AWS, GCP, or Azure) are a plus
  • Experience in ad tech, large-scale SaaS, or other high-throughput consumer or enterprise platforms is a plus

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce