Senior Application Security Engineer
TKO, LP
We are looking for a hands-on Director, Application Security Engineering to strengthen our cybersecurity posture and partner directly with teams building software across web, mobile, data, and AI-enabled workflows. This role will embed security into delivery practices, improve how we prevent and remediate risk, and communicate clearly with both technical and non-technical stakeholders.
This Director will work across software engineering, platform, DevOps, architecture, QA, infrastructure, compliance, and security teams to mature secure SDLC (i.e., SSDLC) practices, expand developer-friendly guardrails, and improve application and agent security. They should be comfortable moving between code review, tooling configuration, threat modeling, vulnerability management, automation, security enablement, and emerging AI security considerations. This is a hybrid role (3 days/week in-office). Preference given to candidates near a TKO office, including NYC, Stamford, Orlando, Austin, or Las Vegas.
The Role and What You’ll Do
The Director, Application Security Engineering will:
- Own and evolve application security practices across the SSDLC, emphasizing scalable, developer-aligned, shift-left controls
- Operate and improve SAST, SCA, secret scanning, code scanning, repository protections, and related controls across repositories and CI/CD pipelines
- Develop secure development enablement for citizen developers, vibe coding, and AI-assisted development, including practical guidance for tooling, code assurance, identity, observability, and enterprise standards
- Review application and code-level vulnerabilities, validate findings, reduce noise, and drive risk-based remediation plans
- Conduct threat modeling and security design reviews for new systems, major changes, integrations, APIs, and high-risk workflows
- Advise teams on secure coding, authentication and authorization, session management, secrets handling, logging, encryption, dependency hygiene, and data protection
- Improve security guardrails for build pipelines, containers, APIs, third-party components, and deployment practices across modern and legacy environments
- Mature risk-based vulnerability management across intake, validation, prioritization, remediation guidance, exception handling, and reporting
- Support secure adoption of AI-assisted development and agentic systems by assessing trust boundaries, data exposure paths, prompt and tool-invocation risks, and misuse scenarios
- Develop pragmatic standards, playbooks, reference architectures, documentation, and office-hour support that improve consistency without slowing teams down unnecessarily
- Track recurring weaknesses, recommend structural fixes, and help leadership understand where engineering investment will reduce risk most effectively
- Use AI productively and responsibly to accelerate analysis, triage, documentation, coding support, and security review while maintaining strong human judgment
Required Skills and Experience
- 5+ years of hands‑on experience in application security, product security, DevSecOps, and security engineering or a closely related software security role
- Proven experience working directly with engineering teams in fast‑moving delivery environments
- Hands‑on experience configuring, tuning, and operationalizing SAST, SCA, and related tooling such as SonarQube, Dependabot, GitHub, GitHub Advanced Security, or comparable platforms
- Ability to interpret and reason about code, identify meaningful risk, and provide specific, implementable remediation guidance to engineers
- Practical experience with SSDLC and shift‑left practices, including automated code review support, threat modeling, security design review, and vulnerability management
- Strong understanding of application and API security, including common software weaknesses, authN/authZ, secrets handling, dependency risk, injection, deserialization, and data protection
- Experience integrating reliable, scalable, and minimally disruptive security controls into CI/CD pipelines and developer workflows
- Hands‑on familiarity with cloud and modern software delivery patterns, including containers, IaC, and Git‑based workflows
- Strong judgment in vulnerability triage, balancing severity, exploitability, business impact, and engineering realities
- Ability to write clear guidance, standards, and technical documentation for technical and non‑technical audiences
- Bias toward automation, simplification, and scalable solutions over manual heroics
- Broad DevSecOps mindset across code, pipelines, dependencies, platforms, deployment, and operations
- Experience using AI tools responsibly to improve engineering and security outcomes
Preferred Skills and Experience
- Experience securing AI agents, LLM-enabled applications, copilots, or agentic workflows in production or near‑production environments
- Experience with DAST, API security testing, penetration testing coordination, red‑team support, or adversarial testing of application and AI systems
- Experience with policy‑as‑code, IaC scanning, container/image security, software supply‑chain security, SBOMs, provenance, attestation, and secrets management
- Familiarity with cloud security across AWS and/or GCP and the application‑layer implications of cloud‑native architectures
- Experience in regulated, audit‑sensitive, or event‑critical environments where evidence, controls, and operational rigor matter
- Experience building metrics, dashboards, or reporting that show AppSec posture and remediation progress
- Experience mentoring engineers and influencing secure engineering culture without direct people management responsibility
What Good Looks Like in This Role
- Engineering teams get faster, clearer, and more actionable security guidance as well as assistance with implementation and mechanics for a "teach a person to fish" approach
- Security tooling produces more trustworthy signals and leads to better adoption, not just more alerts
- Teams catch and remediate issues earlier in design and development rather than late in release cycles
- Application and agent-security risks are surfaced in practical terms with concrete mitigation paths
- Standards, playbooks, and tooling make secure delivery easier and more consistent
- Security becomes more embedded in day‑to‑day engineering execution and technical operations, and less dependent on last‑minute security scrambles and efforts
$160k - $200k
...Senior Application Security Engineer New York, New York, United States The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift's Engineering and Security organization...Senior$200k - $235k
...our New York City office to support collaborative team dynamics and innovative problem-solving. We are seeking a Senior Application Security Engineer to lead the technical execution of our product security strategy. This role focuses on securing high-growth FinTech...SeniorFull timeWork at officeWorldwide$140k - $200k
...wide range of simple, reliable, and secure crypto products and services to... ...reach, and impact. The Department: Application Security Gemini operates at the... ...and too expensive. The Role: Senior Application Security Engineer As a Senior Application Security...SeniorFull timeWork at officeRemote workFlexible hours$220k - $235k
...6) Fortune Best Workplaces in New York™ (2026) Great Place to Work Certified™ The Role We are seeking a Senior Application Security Engineer to join Savvy Wealth at our NYC headquarters as our first dedicated security hire. This is a hands-on, in-the-weeds...SeniorFull timeWork at office- The Estée Lauder Companies Inc. is seeking an experienced Application Security professional to evangelize our security strategy under the Global Head of Application Security. You will work on SDLC security, DevSecOps, and multi-cloud initiatives to deliver trusted software...Senior
- Estée Lauder Companies in New York seeks an experienced Application Security professional to lead secure SDLC initiatives, DevSecOps integration... ...and partners. This role emphasizes collaboration with IT, engineering, and security stakeholders to implement threat modeling,...Senior
$160k - $200k
Senior Application Security Engineer New York, New York, United States The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift's Engineering and Security organization, directly...Senior$121.4k - $166.7k
...the industry.Rockstar is on the lookout for a passionate Senior Security Platform Engineer who is skilled at diving into complex software designs... ...headquarters in Downtown Manhattan. WHAT WE DOThe Rockstar Games Application Security team partners with numerous development teams...SeniorFull timeWork at office- ...Senior Application Security Engineer with Hands on Python Location- Princeton, NJ & NYC, NY (Hybrid) We need a candidate with hands on Python automation and good exp in AI/ML & LLM 8-15+ years in software engineering and application security, with substantial...SeniorFull time
- Senior Application Security Engineer Seeking a Senior Application Security Engineer to join our NYC-based security team in a hybrid capacity. This role is designed for a technical expert with 5-6 years of experience in AppSec who is eager to spearhead the firm's transition...SeniorImmediate start
$150 per hour
A financial firm is looking for an Application Security Engineer to join their team in Iselin, NJ or NYC.Compensation: $150-200kResponsibilities:Perform Application Security scans (e.g. DAST and SCA) on applications and APIs to identify security vulnerabilities and weaknessesTriage...- Hi, we're Oscar. We're hiring a Senior Product Security Engineer 1 to join our Security Team.Oscar is the first health insurance company built around... .... You will work at the intersection of traditional application security and modern AI-driven engineering, ensuring that...SeniorFull timeWork experience placementWork at officeFlexible hours
$225k - $300k
CLEAR is building THE secure identity company of the future. Our mission is to... ...magic of frictionless experiences.As a Senior Product Security Engineer on our Product Security team you’ll... ..., infrastructure, endpoints, and applications. You’ll operate the tools that surface...SeniorCasual workWork at officeFlexible hours$244k - $305k
As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll define the frameworks, methodologies, and architectural patterns that engineering teams across Datadog adopt and apply independently...- %PDF-1.7%ÓôÌá1 0 obj /Metadata 50 0 R/ViewerPreferences 51 0 R endobj2 0 obj endobj3 0 obj /ExtGState /XObject /ProcSet[/PDF/Text/ImageB/ImageC/ImageI]/Annots[14 0 R 15 0 R]/MediaBox[0 0 612 792]/Contents 4 0 R/Group /Tabs/S/StructParents 0 endobj4 0 obj streamxœµÛnÛÆ...Senior
$90k - $110k
Position: Senior Applications/Manufacturing Engineer Location: Melville, NY Company/Industry: Well-established precision manufacturer Schedule: Mon-Fri On-Site Only Salary: $90,000 - $110,000/yr, depending on experience (flexible for the right candidate) + benefits Type...SeniorFlexible hours$225k - $300k
...CLEAR is building THE secure identity company of the future. Our mission is to... ...frictionless experiences. We are seeking a Senior Product Security Engineer to serve as a technical leader and... ...will drive the evolution of CLEAR’s application security posture by influencing...SeniorFull timeCasual workWork at officeFlexible hours$133k - $166k
...forward. What You'll Do We are seeking a Senior Application Engineer I to lead the advanced configuration, integration, and... ...vendors, and internal stakeholders to ensure applications are secure, scalable, and fully leveraged to meet complex business...SeniorWorldwideFlexible hours- Application Security Engineer Our client is looking for an experienced Cloud & Application Security Engineer to design, implement, validate, and operate security controls across our cloud infrastructure, applications, and software delivery pipelines. Individual will partner...
- MANDATORY SKILLS: • 1 5 years of experience in application security, with a proven track record of conducting vulnerability assessments, penetration... ...leading security teams or initiatives, mentoring junior engineers, and fostering a culture of security awareness within the...Flexible hours
$70 - $75 per hour
Role: Application Security Engineer Duration: 12 months contract with possibility of extension or C2H. Location: New York, NY (Hybrid) Pay rate range: $70 - $75/hr Job Description: About the Team: -The mission of the Cloud Security & Developer Enablement team is to implement...Contract workWork experience placementLocal area- AI Systems Security Specialist Client added a crucial skill that they are seeking expertise in here is securing AI systems.... ...Experience AWS cloud security architecture and services Cloud application security engineering Docker and Kubernetes security Infrastructure as Code (...
$85k - $105k
Application Security Engineer - Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States. This is a fantastic opportunity to join an established and well-...Full timeH1bLocal areaImmediate startRemote workVisa sponsorship$100k - $140k
...driven, and collaborative teammates, read on. Your Impact to our Mission Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence. In this...Flexible hours- Application Security Engineer One of our large financial clients is looking for an experienced Application Security Engineer to join their team. If the below requirements fit your skillset, feel free to apply. Duration: Long Term/Multi Year Contract Location: NYC or San...Long term contractRemote work
- Application Security Engineer Looking for an application security engineer with a background in Java development and good experience working with application development tools: whitebox, blackbox, contrast security, sonarqube... Needs some programming experience. Any scripting...
$170k - $200k
...Senior Application Engineer Gibson Dunn is a leading global law firm, advising clients on significant transactions and disputes. Our exceptional... ...portfolio, ensuring reliability, performance, security, and continuous improvement. This role involves administration...SeniorContract workWork at officeLocal areaFlexible hours$178k - $215k
...Job DescriptionAs a Mid-Level AI / Agent Application Engineer, you will be the core builder of the... ...Google ADK, LangGraph, CrewAI, etc.).Design secure "tool-calling" architectures, allowing... ...-timeFunction: ConsultingExperience level: Mid-Senior LevelIndustry: PharmaceuticalsSeniorLocal area$120k - $145k
...Overview NBCUniversal is seeking a Staff Cyber Systems Engineer to build and scale modern application security capabilities across the enterprise. This hands-on... .... Technical Leadership and Enablement Serve as a senior technical expert for application security...Local areaRemote work$52 - $85 per hour
Senior Applications Engineer Lead enterprise application support, system integration, automation, and compliance in regulated industrial environments. Job #135073 Power $52 - $85 an hour Remote Apply Now Talascend is currently seeking an Senior Applications Engineer...SeniorContract workWork experience placementRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!
- hydraulic application engineer New York, NY
- application system engineer New York, NY
- junior application support engineer New York, NY
- application engineer New York, NY
- application performance engineer New York, NY
- network applications engineer New York, NY
- project application engineer New York, NY
- application support engineer New York, NY
- application operations engineer New York, NY
- senior application support engineer New York, NY


