Overview
As Senior Application Security Engineer, you will scale and mature TripleLift’s secure development program across Engineering and Security. You’ll partner with cross-functional teams to embed security into design, build, and operations of advertising platforms. You’ll drive automated testing, threat modeling, and vulnerability remediation to protect publishers and advertisers. This role offers impact at scale in a high-stakes ad-tech environment and opportunities to shape security culture and tooling.
Responsibilities
- Build and maintain a global security compliance program based on NIST CSF
- Develop automated security testing using SAST, DAST, and code-review tools across CI/CD
- Drive secure SDLC practices and secure coding remediation
- Automate security testing in CI/CD pipelines and maintain pipeline integrations
- Administer GitHub Advanced Security (GHAS) across repositories
- Conduct threat modeling and design/architecture reviews to mitigate risks
- Manage vulnerability program and threat-hunting activities with stakeholders
- Perform internal penetration testing and validate third-party pentest findings
- Monitor and respond to application-layer threats (APIs, business logic, common vulnerabilities)
- Collaborate with product/engineering to embed security in software design and architecture
- Implement authentication, authorization, and data protection measures
- Enhance security incident handling and provide security education and awareness
- Develop secure coding guidelines and training for engineers
- Improve security program maturity via tools and processes
Key requirements
- 5+ years in application security or related roles
- Strong secure coding guidance for developers
- Experience with GHAS (Code Scanning, Secret Scanning, Dependency Review)
- Proficiency with SAST/DAST/SCA tools (CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode)
- Hands-on integration of security tools into CI/CD pipelines
- Penetration testing across web apps, APIs, or cloud infrastructure
- Knowledge of OWASP Top 10, CWE, business logic, API security
- Ability to threat model and review design/architecture for security risks
- Experience code reviewing in Python, Java, TypeScript, Go
- Security fundamentals aligned with frameworks (NIST CSF, PCI, SOC2, HITRUST, ISO 27001/2)
- Strong AWS security knowledge (IAM, VPC, KMS, GuardDuty, CloudTrail)
- ownership and independence
- fast-paced adaptability
- clear communication
- GHAS
- CodeQL
- Burp Suite
…
