Full job description
Lead Application Security Engineer role at Zeta Global focused on advancing application and platform security using AI-native security practices, automation, and scalable engineering. Responsibilities include AI-driven threat modeling, automated security reviews, embedding security into SDLC, monitoring emerging threats, and promoting security awareness and standards. Requires 5+ years in Application Security or related fields, strong knowledge of OWASP Top 10, AI/ML security concepts, modern app frameworks (React, Node.js, Django, FastAPI), cloud platforms (AWS, GCP, Azure), container tech (Docker, Kubernetes), and security tools (Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security). Benefits include unlimited PTO, medical/dental/vision coverage, employee equity, discounts, wellness classes, and pet insurance. Salary range $140,000 - $180,000. Remote US position.
What you'll do
- Use AI-assisted threat modeling to identify security risks early in design and development
- Leverage automated security review tools to evaluate architecture, design, code, APIs, and data flows for security gaps
- Drive AI-assisted code security reviews using SAST, DAST, SCA, secrets detection, IaC scanning, container scanning, and contextual risk analysis
- Assess third-party libraries, APIs, vendor integrations, and open-source dependencies for security, compliance, and supply-chain risk
- Support AI-enabled red team, blue team, and incident response simulations
- Embed AI-driven security testing and automated risk detection into CI/CD pipelines
- Build and improve security automation providing real-time feedback to developers
- Use AI-assisted analysis to review architecture and design artifacts and recommend secure implementation patterns
- Contribute to intelligent security checkpoints to reduce manual review effort and improve developer velocity
- Design scalable guardrails, reusable security controls, and policy-as-code capabilities
- Monitor evolving application, cloud, API, AI/ML, and data security risks using AI-assisted threat intelligence
- Identify and evaluate AI-specific threats such as prompt injection, data poisoning, model abuse, and sensitive data exposure
- Design and deploy proactive defense mechanisms across applications, APIs, data platforms, and AI-powered systems
- Use automated signals, telemetry, and risk scoring to support investigations and continuous improvement
- Translate recurring vulnerabilities and incidents into feedback loops to improve threat models and SDLC controls
- Promote secure coding and design practices through AI-assisted guidance, playbooks, automated recommendations, and documentation
- Contribute to internal security standards, secure engineering patterns, and AI-native security playbooks
- Help teams adopt security self-service capabilities to reduce manual AppSec review dependency
- Collaborate with Engineering, DevOps, QA, Product, and AI platform teams to foster a security-first and automation-first culture
- Use metrics and insights to measure control effectiveness, remediation trends, developer adoption, and security maturity
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or related field, or equivalent practical experience
- 5+ years of experience in Application Security, DevSecOps, Secure Software Development, or Security Engineering
- Strong understanding of OWASP Top 10, SANS CWE Top 25, secure design principles, and application threat modeling
- Familiarity with AI/ML security concepts such as prompt injection, data poisoning, adversarial testing, model integrity, model abuse, and AI supply-chain risks
- Experience building or integrating AI-assisted security workflows, security bots, automated triage systems, or risk scoring models
- Experience using AI-assisted or automation-driven approaches to improve security testing, vulnerability analysis, code review, or risk prioritization
- Experience with modern application frameworks and architectures such as React, Node.js, Django, FastAPI, or similar
- Knowledge of securing APIs, microservices, authentication, and authorization mechanisms such as OAuth2, OIDC, JWT, and service-to-service authentication
- Experience with cloud platforms such as AWS, GCP, or Azure, and containerized environments such as Docker and Kubernetes
- Working knowledge of security testing and automation tools such as Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security, or similar tools
- Ability to analyze security findings, correlate risk context, and drive practical remediation guidance for engineering teams
- Strong collaboration and communication skills with ability to work across Engineering, Product, QA, DevOps, and Security teams
Tech stack
AISASTDASTSCAsecrets detectionIaC scanningcontainer scanningReactNode.jsDjangoFastAPIOAuth2OIDCJWTAWSGCPAzureDockerKubernetesSemgrepSonarQubeBurp SuiteOWASP ZAPTrivySnykGitHub Advanced SecurityCI/CDpolicy-as-codeinfrastructure-as-code
Benefits
Unlimited PTOExcellent medical, dental, and vision coverageEmployee EquityEmployee DiscountsVirtual Wellness ClassesPet Insurance