Arrowstreet Capital is hiring a Senior Application Security Engineer to embed application security controls across the software development lifecycle and CI/CD pipelines.
Responsibilities
- Manage and improve pipeline security posture by building a modern DevSecOps ecosystem that uses secure workflows and vulnerability management across the development lifecycle.
- Modernize vulnerability management by integrating AI-driven analysis that maps technical risk to business impact for more informed prioritization and remediation.
- Explore and implement responsible AI use to enhance vulnerability discovery, code review, threat modeling, risk prioritization, security monitoring, and remediation recommendations.
- Lead threat modeling and security reviews for AI-enabled systems , including risks such as prompt injection, insecure handling of model outputs, sensitive data disclosure, model abuse, excessive agency, and data or model poisoning.
- Define metrics and reporting that communicate the security posture and risk exposure of AI-enabled applications to technical teams and senior leadership.
- Define and maintain secure SDLC policies, procedures, and workflows , translating them into actionable technical requirements.
- Drive security controls in CI/CD pipelines , including SAST, DAST, SCA, secret detection, container scanning, and API testing .
- Partner with development teams to explain findings, risks, and remediation steps, guiding fixes using an internal risk matrix that ties attack vectors to business objectives.
- Advance software supply chain security with dependency governance, artifact integrity, SBOM adoption , and third-party risk management .
- Improve pipelines with automated vulnerability and risk measurement, and implement promotion guardrails that balance effective risk management with delivery speed.
- Support incident response for application and pipeline security events.
Requirements
- Ability to leverage frontier AI models to enhance secure code scanning, vulnerability discovery, and application penetration testing.
- Experience in application security , DevSecOps , secure SDLC , vulnerability management , or security engineering .
- Experience building advanced dashboards for key risk indicators, trends, and actionable insights for technical and business stakeholders.
- Hands-on experience collaborating with developers to remediate vulnerabilities .
- Proficiency with CI/CD platforms and source control tools, including GitHub, GitLab, Azure DevOps, Jenkins , etc.
- Use experience with application security testing tools: SAST, DAST, SCA, container scanning, API testing , etc.
- Experience conducting security reviews of application architectures and APIs to identify design weaknesses, vulnerabilities, and potential attack paths.
- Familiarity with modern architectures such as microservices , containers , APIs , and cloud-native apps .
- Programming/scripting experience: Python, PowerShell, Bash, C#, Java, JS/TS, Ruby , etc.
- Working knowledge of AWS/Azure cloud security concepts .
- Experience developing technical documentation and secure coding guides.
- Effective communication of technical security concepts.
- Strong collaboration and relationship-building skills.
- Ability to influence secure development practices and drive adoption.
- Adaptability to pivot strategy or priorities when facing technical challenges or evolving scope.
- Risk-based mindset that accounts for both business and delivery needs.
- Initiative and independent leadership with strong project management.
- Analytical and detail-oriented with excellent problem solving.
- Thrives in fast-paced, multi-team environments.
- Metrics-driven approach to program effectiveness.
- Clear written and verbal communication of vulnerabilities and remediation.
- Passion for enabling secure development through automation , training, and scalable processes.
- Familiarity with frameworks/standards: NIST, CIS, ISO 27001, SOC 2, PCI DSS .
- Some knowledge of application security risks and frameworks: OWASP Top 10 , CWE/SANS 25 , secure coding, and threat modeling.
- Developer-first tools and integration (pull requests, issue tracking, IDEs) preferred.
- Threat modeling methodologies such as STRIDE , attack trees , and agile models.
- Experience with containers and cloud-native platforms (desired): Docker, Kubernetes, ECS/EKS/AKS/OpenShift .
- Relevant certifications are an asset: CSSLP, CISSP, GWAPT, GWEB, OSWE, and AWS/Azure Security .
Technology Focus
- AI-driven analysis , frontier AI models
- SAST , DAST , SCA , secret detection, container scanning, API testing
- CI/CD pipelines , GitHub, GitLab, Azure DevOps, Jenkins
- Python, PowerShell, Bash, C#, Java, JS/TS, Ruby
- AWS/Azure cloud security concepts; microservices, containers, APIs, cloud-native apps
- SBOM , dependency governance, artifact integrity, third-party risk management
- NIST, CIS, ISO 27001, SOC 2, PCI DSS; OWASP Top 10, CWE/SANS 25
- Threat modeling: STRIDE, attack trees, agile models
- Docker, Kubernetes, ECS/EKS/AKS/OpenShift
Compensation
- $110,000 - $315,000 per year
Location
- Boston, MA (onsite)
Additional Information
- Total compensation approach includes base salaries, annual discretionary bonuses , and a benefits package .
- Base salary placement within the range varies based on relevant experience and qualifications, including relevant certifications/credentials/education, role scope, and other factors.
- The salary range is an estimate; additional compensation details will be communicated during recruitment.
- Arrowstreet Capital provides reasonable accommodations for qualified individuals with disabilities; contact them to discuss accommodation needs during the employment process.
Senior Application Security Engineer in boston at Unknown Company
This position is listed as full time and onsite.