Senior Application Security Engineer at TripleLift | AdTechTalent
Home / Jobs / Senior Application Security Engineer Engineering 2 months ago On-site
TripleLift
Senior Application Security Engineer
application security security engineering SAST DAST CI/CD GitHub Advanced Security penetration testing OWASP AWS security threat modeling vulnerability management secure coding ad-tech programmatic security automation Python Java TypeScript Go
Ready to apply?
$160K – $200K
Join TripleLift and work on a role built for experienced AdTech operators.
Key details Location
New York, US; Pune, India
Full job description Senior Application Security Engineer responsible for driving secure software development and application security maturity. Collaborate with Engineering, Platform, Cloud Infrastructure, and Security teams to embed security in design, build, deployment, and operation of products. Build and maintain security compliance program based on NIST CSF. Develop automated security testing using SAST, DAST, and code-review tools. Promote secure SDLC practices and automate security testing in CI/CD pipelines. Administer GitHub Advanced Security features. Conduct threat modeling, vulnerability management, penetration testing, and respond to application-layer security threats. Collaborate on authentication, authorization, and data protection. Provide security training and evangelize best practices. Requires minimum 5 years experience in application security or related roles, proficiency with security tools and AWS security services, and ability to work independently. Preferred experience in ad-tech and cybersecurity certifications. Salary range $160,000 - $200,000 USD. Locations in New York, USA and Pune, India.
What you'll do Build and maintain a global security compliance program based on NIST CSF Similar jobs
More roles worth a look Related opportunities based on specialty and working model so candidates can keep momentum.
TripleLift
New York, US • 5 months ago
$90K – $120K
data science machine learning python
TripleLift
Los Angeles, United States • 5 months ago
$290K – $350K
sales leadership programmatic CTV
TripleLift
Quick snapshot
New York, US; Pune, India
Full-time
Develop automated security testing using enterprise SAST, DAST, and code-review tools
Promote secure application development and infrastructure deployment through SDLC
Automate security testing in CI/CD pipelines and maintain pipeline integrations
Administer and drive adoption of GitHub Advanced Security features across engineering repositories
Participate in threat modeling and design/architecture spec reviews to identify and mitigate security risks
Develop and implement a vulnerability management program and perform threat-hunting activities
Conduct internal penetration testing and vulnerability assessments; validate third-party pentest findings
Monitor and respond to application-layer security threats such as API abuses and business logic flaws
Collaborate with product and engineering teams to ensure security in software design and architecture
Implement proper authentication, authorization, and data protection mechanisms
Enhance and facilitate security incident handling activities
Evangelize security best practices and provide education and awareness to employees
Develop and implement secure coding guidelines and conduct secure development training
Continuously improve security program maturity through deployment and management of security tools and processes Requirements Minimum 5 years experience in application security, secure software development, security engineering, or similar role Strong understanding of secure coding practices and ability to guide developers on remediation strategies Experience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode) Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security) Ability to perform threat modeling and participate in design/architecture spec reviews Experience conducting security code reviews across various programming languages (Python, Java, TypeScript, Go) Understanding of security fundamentals related to cybersecurity and compliance frameworks, particularly NIST CSF Strong understanding of AWS security services and controls and experience securing cloud-native environments Ability to work independently with minimal oversight and deliver results in a fast-paced environment Continuous learner who values correctness, efficiency, and constructive feedback Preferred: Experience in ad-tech / programmatic advertising or high-scale real-time environment Preferred: Familiarity with AI/LLM-based tools for threat intelligence, alert triage, or security automation Preferred: Holds cybersecurity certification (e.g., OSCP, GWAPT, CISSP, CISA) Tech stack GitHub Advanced Security (GHAS) CodeQL Burp Suite OWASP ZAP Snyk Checkmarx Veracode Python Java TypeScript Go AWS IAM AWS VPC AWS KMS AWS GuardDuty AWS CloudTrail CI/CD pipelines
Benefits Medical, Dental & Vision Plans Flexible PTO 401k with employer match Open Paid Time Off policy Region-specific benefits
Apply now Ready to take the next step in your career? Click the button below to continue to the application process.
Company
TripleLift TripleLift is the Creative SSP that transforms digital advertising through creative technology and innovative ad formats. We help publishers, advertisers, and agencies achieve measurable outcomes while enhancing user experiences.
Industry
Programmatic advertising
Website
https://triplelift.com/
Posted
2 months ago
Category: Engineering
New York, US • 5 months ago
product management CTV programmatic