Application Security and Risk Engineer
Lumin Digital
The Senior Application Security Engineer is a hands-on technical leader responsible for securing Lumin Digital’s B2B2C SaaS platform across the full software development lifecycle. This role exists at the intersection of application security and AI-augmented engineering: the ideal candidate actively uses AI-powered tools such as Claude Code and Claude Security in their daily workflow to find vulnerabilities faster, automate remediation, and scale security coverage beyond what traditional approaches allow. As AI rapidly transforms how code is written, reviewed, and deployed, this engineer will lead the effort to secure AI-integrated applications, harden CI/CD pipelines, and establish governance for responsible AI adoption across product and engineering teams. Success in this role requires deep technical fluency, a bias toward building and doing over advising, and the ability to operate independently in a fast-moving, remote-first environment.
Lead security architecture reviews for new and existing applications, ensuring secure-by-design principles are embedded from initial design through deployment and ongoing operation.
Develop, enforce, and continuously refine secure coding standards across engineering teams through a combination of automated security scans (SAST, DAST, SCA), AI-assisted code review using tools such as Claude Code, periodic manual code audits, and targeted secure development training.
Own the design, implementation, and evolution of Application Security Posture Management (ASPM) capabilities, integrating signals from static analysis, dynamic testing, software composition analysis, and runtime telemetry to build risk-scoring models that balance exploitability, data sensitivity, and business impact.
Continuously improve threat modeling frameworks across application components, third-party integrations, cloud-native architectures, and AI/LLM-powered features, leveraging tools such as Claude Security for accelerated threat model generation and scenario analysis.
Develop custom security automation tools and scripts to improve detection and response capabilities across cloud environments, including AI-assisted vulnerability auto-fix workflows and integration of AI-powered security tooling into CI/CD pipelines.
Own and operate the company’s bug bounty program end-to-end: define program strategy and scope, triage and validate external researcher submissions, assess severity, and maintain productive engagement with the security research community.
Manage vulnerability triage and prioritization processes, ensuring vulnerabilities are assessed based on exploitability, business impact, and compliance requirements, and that remediation timelines align with organizational risk tolerance.
Influence product roadmaps by identifying and advocating for security enhancements aligned with evolving regulatory requirements, industry best practices, and the emerging threat landscape for AI-integrated applications.
Mentor security engineers and developers through hands-on guidance in secure coding, vulnerability remediation, and effective use of AI-augmented security workflows.
Present security findings, risk assessments, and program metrics to senior leadership, clients, auditors, and regulators in a clear, actionable manner.
Individuals with a disability who are otherwise able to perform the essential functions of the job may request reasonable accommodation through the Human Resources department.
Bachelor’s in Computer Science, Cybersecurity, Information Assurance, Software Engineering, or a related field, or an equivalent combination of education and experience.
Seven (7+) years of progressive experience in application security, software security engineering, or a closely related domain within production SaaS environments.
Extensive hands-on experience in secure software development, DevSecOps pipeline design, and security testing methodologies (SAST, DAST, SCA, penetration testing).
Demonstrated experience securing large-scale cloud-native applications, APIs, and microservices architectures.
Experience leading application security initiatives, defining program strategy, and mentoring engineering teams on secure development practices.
Demonstrated, regular hands-on use of AI-powered security and development tools (e.g., Claude Code, Claude Security, or comparable coding/security assistants) as part of daily security engineering workflows, not solely in an evaluative, advisory, or training capacity.
Experience assessing AI-specific attack surfaces in LLM-integrated applications, including prompt injection, context leakage, insecure tool use, and model denial-of-service.
Deep expertise in AWS security, Kubernetes security, and cloud-native application security best practices.
Strong programming proficiency with the ability to review and assess security risks in one or more of: Java, C#, JavaScript/TypeScript, Python, Swift, or Kotlin.
Hands-on proficiency with AI-augmented security workflows, including daily use of AI tools (e.g., Claude Code, Claude Security) for vulnerability discovery, remediation assistance, threat modeling, and security automation across the SDLC.
Strong understanding of OWASP Top 10, OWASP Top 10 for LLM Applications, SANS 25, CVSS/EPSS scoring, and MITRE ATT&CK framework.
Ability to identify, assess, and mitigate prompt injection vulnerabilities (direct and indirect) in LLM-integrated applications through input validation, output sanitization, instruction hierarchy enforcement, and adversarial prompt testing.
Experience with secure context window management in AI-powered products, including preventing sensitive data leakage, enforcing context isolation boundaries, and defining data classification policies for AI model inputs.
Hands-on experience with security automation and scripting (Python, Bash, or equivalent).
Proficiency in penetration testing methodologies, including automated and manual security testing of web applications, APIs, and mobile platforms.
Ability to communicate complex security concepts to both technical and non-technical audiences, and to present risk assessments to senior leadership and external stakeholders.
Demonstrated ability to work independently in a remote setting while maintaining high performance and accountability.
Experience evaluating the security posture of AI providers (API security reviews, data residency assessments, vendor risk questionnaires, and contractual security requirements).
Familiarity with AI model access controls and secrets hygiene in AI pipelines, including least-privilege principles for LLM tool integrations and securing model inference endpoints.
Experience with SIEM, WAF, and security monitoring tools.
Familiarity with cloud security controls in AWS, including IAM, security groups, KMS, Lambda security, and cloud monitoring.
Strong project management abilities and experience collaborating across product, engineering, and compliance teams.
Travel:
LIFE AT LUMIN DIGITAL
Lumin Digital is a trailblazer in digital banking solutions, driven by a unique approach to technology, service, and people. We empower credit unions and banks by creating cutting-edge digital experiences that continuously serve, engage, and grow their membership base — and as a 100% cloud-native company, we're purpose-built to unlock the full advantages of the cloud for financial institutions and their users.
Benefits Include We take care of our people with medical, dental, and vision insurance, a 401(k) with company match, flexible PTO plus 12 paid holidays, paid sick leave, and paid parental and family leave. We also offer a lifestyle spending account, tuition reimbursement, and a cell phone stipend. Lumin Digital is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender identity, or any other legally protected basis.
Lead security architecture reviews for new and existing applications, ensuring secure-by-design principles are embedded from initial design through deployment and ongoing operation.
Develop, enforce, and continuously refine secure coding standards across engineering teams through a combination of automated security scans (SAST, DAST, SCA), AI-assisted code review using tools such as Claude Code, periodic manual code audits, and targeted secure development training.
Own the design, implementation, and evolution of Application Security Posture Management (ASPM) capabilities, integrating signals from static analysis, dynamic testing, software composition analysis, and runtime telemetry to build risk-scoring models that balance exploitability, data sensitivity, and business impact.
Continuously improve threat modeling frameworks across application components, third-party integrations, cloud-native architectures, and AI/LLM-powered features, leveraging tools such as Claude Security for accelerated threat model generation and scenario analysis.
Develop custom security automation tools and scripts to improve detection and response capabilities across cloud environments, including AI-assisted vulnerability auto-fix workflows and integration of AI-powered security tooling into CI/CD pipelines.
Own and operate the company’s bug bounty program end-to-end: define program strategy and scope, triage and validate external researcher submissions, assess severity, and maintain productive engagement with the security research community.
Manage vulnerability triage and prioritization processes, ensuring vulnerabilities are assessed based on exploitability, business impact, and compliance requirements, and that remediation timelines align with organizational risk tolerance.
Influence product roadmaps by identifying and advocating for security enhancements aligned with evolving regulatory requirements, industry best practices, and the emerging threat landscape for AI-integrated applications.
Mentor security engineers and developers through hands-on guidance in secure coding, vulnerability remediation, and effective use of AI-augmented security workflows.
Present security findings, risk assessments, and program metrics to senior leadership, clients, auditors, and regulators in a clear, actionable manner.
Individuals with a disability who are otherwise able to perform the essential functions of the job may request reasonable accommodation through the Human Resources department.
Bachelor’s in Computer Science, Cybersecurity, Information Assurance, Software Engineering, or a related field, or an equivalent combination of education and experience.
Seven (7+) years of progressive experience in application security, software security engineering, or a closely related domain within production SaaS environments.
Extensive hands-on experience in secure software development, DevSecOps pipeline design, and security testing methodologies (SAST, DAST, SCA, penetration testing).
Demonstrated experience securing large-scale cloud-native applications, APIs, and microservices architectures.
Experience leading application security initiatives, defining program strategy, and mentoring engineering teams on secure development practices.
Demonstrated, regular hands-on use of AI-powered security and development tools (e.g., Claude Code, Claude Security, or comparable coding/security assistants) as part of daily security engineering workflows, not solely in an evaluative, advisory, or training capacity.
Experience assessing AI-specific attack surfaces in LLM-integrated applications, including prompt injection, context leakage, insecure tool use, and model denial-of-service.
Deep expertise in AWS security, Kubernetes security, and cloud-native application security best practices.
Strong programming proficiency with the ability to review and assess security risks in one or more of: Java, C#, JavaScript/TypeScript, Python, Swift, or Kotlin.
Hands-on proficiency with AI-augmented security workflows, including daily use of AI tools (e.g., Claude Code, Claude Security) for vulnerability discovery, remediation assistance, threat modeling, and security automation across the SDLC.
Strong understanding of OWASP Top 10, OWASP Top 10 for LLM Applications, SANS 25, CVSS/EPSS scoring, and MITRE ATT&CK framework.
Ability to identify, assess, and mitigate prompt injection vulnerabilities (direct and indirect) in LLM-integrated applications through input validation, output sanitization, instruction hierarchy enforcement, and adversarial prompt testing.
Experience with secure context window management in AI-powered products, including preventing sensitive data leakage, enforcing context isolation boundaries, and defining data classification policies for AI model inputs.
Hands-on experience with security automation and scripting (Python, Bash, or equivalent).
Proficiency in penetration testing methodologies, including automated and manual security testing of web applications, APIs, and mobile platforms.
Ability to communicate complex security concepts to both technical and non-technical audiences, and to present risk assessments to senior leadership and external stakeholders.
Demonstrated ability to work independently in a remote setting while maintaining high performance and accountability.
Experience evaluating the security posture of AI providers (API security reviews, data residency assessments, vendor risk questionnaires, and contractual security requirements).
Familiarity with AI model access controls and secrets hygiene in AI pipelines, including least-privilege principles for LLM tool integrations and securing model inference endpoints.
Experience with SIEM, WAF, and security monitoring tools.
Familiarity with cloud security controls in AWS, including IAM, security groups, KMS, Lambda security, and cloud monitoring.
Strong project management abilities and experience collaborating across product, engineering, and compliance teams.
Travel:
LIFE AT LUMIN DIGITAL
Lumin Digital is a trailblazer in digital banking solutions, driven by a unique approach to technology, service, and people. We empower credit unions and banks by creating cutting-edge digital experiences that continuously serve, engage, and grow their membership base — and as a 100% cloud-native company, we're purpose-built to unlock the full advantages of the cloud for financial institutions and their users.
Benefits Include We take care of our people with medical, dental, and vision insurance, a 401(k) with company match, flexible PTO plus 12 paid holidays, paid sick leave, and paid parental and family leave. We also offer a lifestyle spending account, tuition reimbursement, and a cell phone stipend. Lumin Digital is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender identity, or any other legally protected basis.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Application Security and Risk Engineer in New York, NY vacancy
$200k - $250k
...Hudson River Trading (HRT) is seeking a Security Governance, Risk, and Compliance Engineer to join our growing Information Security team. This function... ...security architecture reviews for internally developed applications Translate compliance requirements into concrete...ApplicationWork at officeLocal areaImmediate start$405k
...Security Risk Engineer Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial... ...you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems...ApplicationVisa sponsorship- ...Infrastructure & Information Security About Core Education Core Education... ...staff and our own engineers. Standards, reference architectures... .... Partnership with peers in Application Services, Data & Analytics,... ...'s portfolio; report status, risks, incidents, and financials to...ApplicationContract workFor contractorsRemote work
- ...iPaaS and helping enterprises unify data, applications, processes, and AI into a single,... ...orchestration at scale. With enterprise-grade security and continuous innovation at its core,... ...feedback loops with Product and Engineering teams Influence & Scale (Days 60-90)...ApplicationRemote workFlexible hoursShift work
- ...providing a wide range of investment banking, securities, investment management and wealth... ...and simulation software, comprehensive risk and security systems, and robust client-... ...these systems and tools. Our insights, our applications and infrastructure give a competitive...ApplicationWork at officeRemote workWorldwide
- ...Cloud Security Engineer We are seeking a Cloud Security Engineer to join our cybersecurity team. This role is... ...candidate will work closely with cloud engineering, application, and network teams to identify security risks, improve cloud security controls, and support...ApplicationWork experience placement
- ...frameworks, tools, and technologies while recommending the most suitable one. Architect, design and develop secure, high performance, scalable and maintainable applications using appropriate architectural patterns. Creating high-level product’s technical specifications,...Application
- ...Department: Security Management Services Reports to: Sr. Consultant & Sr. Manager Ethical Hacker, Infosec Auditor (L1/2 Consultant)... ...Systems (Windows, Linux, Unix), Databases (MSSQL, Oracle, MySQL), Applications (IIS, Apache, Tomcat), SAP, Virtualization Softwares (Vmware,...Application
- 210438 Security Administrator Procom is a leading provider of professional... ...staffing expertise include: Application Development, Project... ...Infrastructure & Network Services, Risk Management & Compliance,... ...to the Monitoring and Engineering Team Assist users with problems...ApplicationPermanent employmentContract workFor contractorsH1bWork at office
$120k - $135k
...Are you looking to expand and apply your security knowledge in a real environment with... ..., Network+, or equivalent); Network engineering or security experience in complex environments... ...é and cover letter for consideration. Applications will be considered on a rolling basis....ApplicationFull timeCasual workRemote work- ...Con Ed is seeking a Cloud Security Specialist to lead the implementation and management... ...directly manage a team of cloud security engineers, ensuring secure architectures and... ...while working closely with DevOps and application teams. Knowledge of secure private connectivity...Application
$70 - $90 per hour
...Only (USC/GC) Position Title: Cloud Security Engineer (Azure, AWS, GCP, Oracle Cloud)... ...functional teams to identify security risks, enhance security controls, and shape... ...expertise will support securing cloud-hosted applications, containers, and networks, while...ApplicationFor contractorsRemote work- ...The Cloud Security Specialist is a senior technical and leadership position responsible... ...candidate will lead a team of cloud security engineers, develop secure architectures, and... ...with cloud service, DevOps, and application teams to design secure deployments, enforce...Application
- Job Title: EUC Engineer - Endpoint Security & ThreatLocker Location: New York, NY (Hybrid) Job Type: Long-Term Contract A leading alternative... ...in enterprise environments, specifically around application whitelisting, ringfencing, storage control, and endpoint...ApplicationLong term contract
- ...Senior Cloud Security Engineer At BNY, our culture allows us to run our company better and enables... ...technologies and their practical application in cyber security. It is responsible... ...driven capabilities for threat detection, risk analysis, automation, incident response...ApplicationWorldwide
- ...Solutions is looking for a Senior OCI Infrastructure & DevOps Engineer to manage and optimize Oracle Cloud Infrastructure (OCI) environments... ...Linux, middleware technologies, and CI/CD pipelines to ensure seamless application deployment and system reliability. #J-18808-Ljbffr...Application
- ...overall delivery of network, security & cloud based projects utilizing... ...to identify potential risk, audit and vulnerabilities assessment... ..., Manage Identity Services Engine(ISE), Authentication and... ...public/private DNS management. Applications Integration and migration from...ApplicationRemote work
- ...combination of inventive research, design, and engineering. Our organization is very flat, and our... ...company. You'll work closely with Security and Engineering to implement zero-trust... ...access across dozens of SaaS applications via SCIM and API integrations. Build...ApplicationFull timeWork at office
- ...service plans to control customer's source of risk, loss and/or costs. Monitors and... ...Bachelor's degree with coursework in math, engineering or related areas (or equivalent) and at... ...information using various proprietary software applications and create/modify documents and complex...ApplicationFull timeWork at office
- ...Application Security Engineer - Vulnerability Operations (Mid-Level) Position: Contract Location: NJ/TX/NC Duration: 12... ...classes (OWASP Top 10, API Security Top 10, supply chain risks). ~ Hands-on experience with SAST, DAST, SCA, or related...ApplicationContract work
$250k - $350k
...CAST technology can see inside custom applications with MRI-like precision, automatically... ...readiness, structural flaws, legal and security risks. It's becoming essential for faster... ...the speed and efficiency of Software Engineering, better open source risk control, and...ApplicationLocal areaRemote work- ...leader in mobile device and app security, offering real-time, on-... ...patented z9 machine learning‑based engine. As part of our fast growing... ...- Understands mobile applications, SaaS based delivery models and... ...customer. Customer Satisfaction & Risk Management - Maintain a high...ApplicationLocal area
- ...Part-time hourly contractor Overview We are seeking an Azure Security Engineer to ensure proper configuration standards are met and... ...Engineer, you will help deploy and configure a secure cloud application infrastructure that aligns with business needs. You will be...ApplicationHourly payPart timeFor contractorsRemote work
- ...Senior Detection Engineer (SIEM / Security Observability) Remote, US Description Keeper Security is... ...standards across cloud infrastructure, applications, endpoints, and identity systems... ...intelligence, threat hunting, and emerging risks Collaborate with cloud,...ApplicationRemote work
- ...forefront of innovation, providing a broad array of AI, Security, and Managed Services. Our mission is to equip... ...administration and working closely with Coretek and Microsoft engineers on more complex application issues. Responsibilities Provide technical support for...ApplicationRemote workFlexible hoursNight shift
- Responsibilities Perform on-site risk engineering surveys and desktop reviews for conventional power and renewable energy risks. Assess operational... .... Demonstrated ability to effectively use required software applications, such as Microsoft Office Suite. Ability to create and...ApplicationWork at office
- ...provider of digital platform engineering and development services. We... ..., ensuring adherence to security and compliance standards and... ...organizational protocols Coordinate with application, security, workplace, and... ...Track progress, identify risks, and prepare status reports...Application
$110k - $140k
...Description Tyto Athene is hiring a Cloud Security Engineer (AWS & GCP) to join our team of cloud, security, and compliance experts. This... ...compliance monitoring. Troubleshoot issues across network, compute, application, and identity layers by reviewing logs, collecting data, and...ApplicationRemote work- ...Application Security Engineer We are seeking an Application Security Engineer who will support our client with ensuring security is integrated into all stages of software development. This role will be responsible for designing and building secure applications while...Application
$200k - $300k
Hudson River Trading (HRT) is seeking a Risk Engineer to join our Risk team in New York City. In this role, you will focus on building... ...state-of-the-art performance analytics and risk decomposition applications Work with developers to productionize risk models and risk...ApplicationWork at officeLocal areaImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security and Risk Engineer. Be the first to apply!
Related searches
- technical application engineer New York, NY
- application operations engineer New York, NY
- senior application support engineer New York, NY
- application engineer New York, NY
- field applications engineer New York, NY
- hydraulic application engineer New York, NY
- application support engineer New York, NY
- application engineering manager New York, NY
- cnc applications engineer New York, NY
- network applications engineer New York, NY


