Senior Application Security Engineer
Core
Drive application security maturity and secure software development across engineering teams, embedding security into the SDLC, CI/CD pipelines, and cloud infrastructure.
Role type
Senior Application Security Engineer (IC)
Builds
Automated security testing tooling, CI/CD security integrations, and a global security compliance program.
Domain
Ad-tech / Programmatic advertising
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security engineering, Secure coding practices, SAST/DAST/SCA tooling, CI/CD pipeline security, Penetration testing, Threat modeling, OWASP Top 10, Cloud security (AWS), Security code reviews
Preferred skills
Ad-tech industry experience, AI/LLM-based security tools, Cybersecurity certifications (OSCP, CISSP, etc.)
Technologies
GitHub Advanced Security (GHAS), CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode, AWS (IAM, VPC, GuardDuty, CloudTrail)
Responsibilities
Develop automated security testing utilizing enterprise SAST, DAST, and code-review tools; Automate security testing in CI/CD pipelines; Administer and drive adoption of GitHub Advanced Security; Participate in threat modeling and design/architecture spec reviews; Conduct internal penetration testing and vulnerability assessments; Monitor and respond to application-layer security threats; Collaborate with teams to implement authentication, authorization, and data protection mechanisms; Evangelize security best practices and conduct secure development training.
Seniority
Senior, hands-on IC
