Senior Application Security Engineer
TripleLift · New York, New York, United States
Posted about 2 months ago
or apply directly on TripleLift 's site. We never take the application ourselves.
Is this posting real?
- This role has been open
- 53 days TripleLift 's roles stay open a median of 53 days
- Reposted
- No
- Salary listed
- No 0% of TripleLift 's roles list one
- Ghost-job risk at TripleLift
- high 21 stale, 0 reposted of 33 open
- Hiring momentum
- 43 roles opened in the last 90 days ↑ up vs. the prior 90 days
- Last confirmed on the employer's board
- 2026-09-25
Measured from postings appearing on and disappearing from TripleLift 's own greenhouse board since 2026-08-03. Full hiring picture for TripleLift .
About this role
The Senior Application Security Engineer at TripleLift is responsible for enhancing the security of software development and application security practices. This role involves collaborating with various teams to implement secure coding practices, automate security testing in CI/CD pipelines, and conduct vulnerability assessments. The engineer will also educate staff on security best practices and continuously improve the organization's security posture.
- benefits
- 2/5
- freshness
- 1/5
- career value
- 4/5
- role clarity
- 5/5
- pay transparency
- 0/5
Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of TripleLift as an employer.
What you need
- 5 years minimum of experience in application security, secure software development, security engineering, or a similar role
- Strong understanding of secure coding practices and ability to guide developers on remediation strategies
- Experience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review
- Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode)
- Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning
- Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure
Nice to have
- Experience in the ad-tech / programmatic advertising industry, or another high-scale, real-time environment
- Familiarity with using AI/LLM-based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automation
- Holds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc.
What you get
- Medical, Dental & Vision Plans
- Flexible PTO
- 401k w/ employer match
Worth weighing
- No specific mention of remote work options
- Salary range transparency indicates a wide range, actual pay may vary significantly based on experience and performance
- The role involves a high level of responsibility and independence, which may not suit all candidates
Summarised from TripleLift 's posting. Read the full original.
Listed by TripleLift on their greenhouse job board, last confirmed open on 2026-09-25. PitchMeAI is not the employer.
More roles at TripleLift
- Trading SpecialistNew York, New York, United States
- Senior Staff EngineerNew York, New York, United States
- Product Marketing DirectorNew York, New York, United States
- Cloud EngineerNew York, New York, United States
- Senior Software EngineerZürich, Zürich, Switzerland
- Team Lead, Employee ExperienceNew York, New York, United States
- Associate Account ManagerNew York, New York, United States
- Associate Account ManagerChicago, IL, United States