TripleLift is hiring a Senior Application Security Engineer to strengthen secure software development across engineering, platform, cloud infrastructure, and security.
Responsibilities
- Build and maintain a global security compliance program aligned to NIST CSF .
- Scale application security by developing automated security testing using enterprise SAST , DAST , and code-review tools.
- Promote an SDLC that supports secure application development and infrastructure deployment, including secure coding remediation activities.
- Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations.
- Administer and drive adoption of GitHub Advanced Security (GHAS) across engineering repositories, including:
- Code scanning
- Secret scanning
- Dependency review
- Participate in threat modeling and design or architecture specification reviews to identify and mitigate risks early in the SDLC.
- Coordinate stakeholders to develop and implement a vulnerability management program and support threat-hunting activities.
- Own and conduct internal penetration testing and vulnerability assessments for applications and infrastructure, and validate outcomes from third-party pentest engagements.
- Monitor and respond to application-layer threats, including API abuse , business logic flaws , and common web vulnerabilities.
- Collaborate with product and engineering teams to ensure security is built into software design and architecture.
- Improve application security posture by implementing authentication , authorization , and data protection mechanisms.
- Enhance and facilitate security incident handling activities.
- Evangelize security best practices by providing education and awareness for employees; develop and implement secure coding guidelines and run secure development training for engineers.
- Evaluate and continuously improve security program maturity by deploying and managing security tools and processes.
Requirements
- 5 years minimum experience in application security, secure software development, security engineering, or a related role.
- Strong understanding of secure coding practices and ability to guide developers through remediation strategies.
- Experience with GitHub Advanced Security (GHAS) including:
- Code Scanning (SAST)
- Secret Scanning
- Dependency Review
- Proficiency with SAST , DAST , and SCA tools (examples include CodeQL , Burp Suite , OWASP ZAP , Snyk , Checkmarx , Veracode ).
- Hands‑on experience integrating security testing tools into CI/CD pipelines for automated scanning, including designing and building pipeline workflows.
- Hands‑on penetration testing and offensive security experience across web applications , APIs , or cloud infrastructure .
- Knowledge of common application security vulnerabilities and mitigations including OWASP Top 10 and CWE , with a focus on business logic flaws and API security .
- Ability to perform threat modeling and participate in design or architecture spec reviews to assess security risks.
- Experience conducting security code reviews across programming languages such as Python , Java , TypeScript , and Go .
- Security fundamentals mapped to cybersecurity and compliance frameworks, especially NIST CSF (also includes PCI , SOC2 , HITRUST , ISO 27001/2 , or similar).
- Strong understanding of AWS security services and controls (including IAM , VPC , KMS , GuardDuty , CloudTrail ) and experience securing cloud-native environments and workloads, including deploying security tools within them.
- Ownership mindset with the ability to work independently with minimal oversight, delivering results in a fast‑paced environment while balancing multiple priorities.
- Continually learns and adapts, valuing correctness , efficiency , and constructive feedback.
Technologies
- NIST CSF
- GitHub Advanced Security (GHAS): Code Scanning, Secret Scanning, Dependency Review
- SAST, DAST, SCA
- CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode
- CI/CD
- OWASP Top 10, CWE
- Python, Java, TypeScript, Go
- PCI, SOC2, HITRUST, ISO 27001/2
- AWS: IAM, VPC, KMS, GuardDuty, CloudTrail
- OSCP, GWAPT, CISSP, CISA
- Claude
Preferred
- Experience in ad-tech or programmatic advertising, or another high‑scale real‑time environment.
- Familiarity with using AI/LLM-based tools (for example, Claude or similar) for threat intelligence, alert triage, or security automation.
- Cybersecurity certification such as OSCP, GWAPT, CISSP, CISA, etc.
Location and Compensation
- Location: Hoboken, NJ (onsite)
- Salary: USD 160,000 - 200,000 per year
Life at TripleLift
- Team culture focused on people who like who they work with and aim to help everyone around them improve.
- Continuous innovation and fast‑moving execution.
- Learn more via TripleLift’s LinkedIn Life page.
People, Culture and Community Initiatives
- Commitment to building a culture that helps people feel connected, supported, and empowered.
- Investment in employees and encouragement of curiosity, shared values, and meaningful connections across teams and communities.
- Focus on ensuring talent of every background, viewpoint, and experience can be hired, belong, and develop.
- People, Culture, and Community initiatives designed to help everyone thrive and feel a sense of belonging.
Privacy Policy
- See TripleLift and 1plusX websites for Privacy Policies.
- TripleLift does not accept unsolicited resumes from recruitment search firms.
Senior Application Security Engineer in hoboken at Unknown Company
This position is listed as full time and onsite.