Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Security and Risk Engineer

Lumin Digital

The Senior Application Security Engineer is a hands-on technical leader responsible for securing Lumin Digital’s B2B2C SaaS platform across the full software development lifecycle. This role exists at the intersection of application security and AI-augmented engineering: the ideal candidate actively uses AI-powered tools such as Claude Code and Claude Security in their daily workflow to find vulnerabilities faster, automate remediation, and scale security coverage beyond what traditional approaches allow. As AI rapidly transforms how code is written, reviewed, and deployed, this engineer will lead the effort to secure AI-integrated applications, harden CI/CD pipelines, and establish governance for responsible AI adoption across product and engineering teams. Success in this role requires deep technical fluency, a bias toward building and doing over advising, and the ability to operate independently in a fast-moving, remote-first environment.
Lead security architecture reviews for new and existing applications, ensuring secure-by-design principles are embedded from initial design through deployment and ongoing operation.
Develop, enforce, and continuously refine secure coding standards across engineering teams through a combination of automated security scans (SAST, DAST, SCA), AI-assisted code review using tools such as Claude Code, periodic manual code audits, and targeted secure development training.
Own the design, implementation, and evolution of Application Security Posture Management (ASPM) capabilities, integrating signals from static analysis, dynamic testing, software composition analysis, and runtime telemetry to build risk-scoring models that balance exploitability, data sensitivity, and business impact.
Continuously improve threat modeling frameworks across application components, third-party integrations, cloud-native architectures, and AI/LLM-powered features, leveraging tools such as Claude Security for accelerated threat model generation and scenario analysis.
Develop custom security automation tools and scripts to improve detection and response capabilities across cloud environments, including AI-assisted vulnerability auto-fix workflows and integration of AI-powered security tooling into CI/CD pipelines.
Own and operate the company’s bug bounty program end-to-end: define program strategy and scope, triage and validate external researcher submissions, assess severity, and maintain productive engagement with the security research community.
Manage vulnerability triage and prioritization processes, ensuring vulnerabilities are assessed based on exploitability, business impact, and compliance requirements, and that remediation timelines align with organizational risk tolerance.
Influence product roadmaps by identifying and advocating for security enhancements aligned with evolving regulatory requirements, industry best practices, and the emerging threat landscape for AI-integrated applications.
Mentor security engineers and developers through hands-on guidance in secure coding, vulnerability remediation, and effective use of AI-augmented security workflows.
Present security findings, risk assessments, and program metrics to senior leadership, clients, auditors, and regulators in a clear, actionable manner.
Individuals with a disability who are otherwise able to perform the essential functions of the job may request reasonable accommodation through the Human Resources department.
Bachelor’s in Computer Science, Cybersecurity, Information Assurance, Software Engineering, or a related field, or an equivalent combination of education and experience.
Seven (7+) years of progressive experience in application security, software security engineering, or a closely related domain within production SaaS environments.
Extensive hands-on experience in secure software development, DevSecOps pipeline design, and security testing methodologies (SAST, DAST, SCA, penetration testing).
Demonstrated experience securing large-scale cloud-native applications, APIs, and microservices architectures.
Experience leading application security initiatives, defining program strategy, and mentoring engineering teams on secure development practices.
Demonstrated, regular hands-on use of AI-powered security and development tools (e.g., Claude Code, Claude Security, or comparable coding/security assistants) as part of daily security engineering workflows, not solely in an evaluative, advisory, or training capacity.
Experience assessing AI-specific attack surfaces in LLM-integrated applications, including prompt injection, context leakage, insecure tool use, and model denial-of-service.
Deep expertise in AWS security, Kubernetes security, and cloud-native application security best practices.
Strong programming proficiency with the ability to review and assess security risks in one or more of: Java, C#, JavaScript/TypeScript, Python, Swift, or Kotlin.
Hands-on proficiency with AI-augmented security workflows, including daily use of AI tools (e.g., Claude Code, Claude Security) for vulnerability discovery, remediation assistance, threat modeling, and security automation across the SDLC.
Strong understanding of OWASP Top 10, OWASP Top 10 for LLM Applications, SANS 25, CVSS/EPSS scoring, and MITRE ATT&CK framework.
Ability to identify, assess, and mitigate prompt injection vulnerabilities (direct and indirect) in LLM-integrated applications through input validation, output sanitization, instruction hierarchy enforcement, and adversarial prompt testing.
Experience with secure context window management in AI-powered products, including preventing sensitive data leakage, enforcing context isolation boundaries, and defining data classification policies for AI model inputs.
Hands-on experience with security automation and scripting (Python, Bash, or equivalent).
Proficiency in penetration testing methodologies, including automated and manual security testing of web applications, APIs, and mobile platforms.
Ability to communicate complex security concepts to both technical and non-technical audiences, and to present risk assessments to senior leadership and external stakeholders.
Demonstrated ability to work independently in a remote setting while maintaining high performance and accountability.
Experience evaluating the security posture of AI providers (API security reviews, data residency assessments, vendor risk questionnaires, and contractual security requirements).
Familiarity with AI model access controls and secrets hygiene in AI pipelines, including least-privilege principles for LLM tool integrations and securing model inference endpoints.
Experience with SIEM, WAF, and security monitoring tools.
Familiarity with cloud security controls in AWS, including IAM, security groups, KMS, Lambda security, and cloud monitoring.
Strong project management abilities and experience collaborating across product, engineering, and compliance teams.
Travel:
LIFE AT LUMIN DIGITAL
Lumin Digital is a trailblazer in digital banking solutions, driven by a unique approach to technology, service, and people. We empower credit unions and banks by creating cutting-edge digital experiences that continuously serve, engage, and grow their membership base — and as a 100% cloud-native company, we're purpose-built to unlock the full advantages of the cloud for financial institutions and their users.
Benefits Include We take care of our people with medical, dental, and vision insurance, a 401(k) with company match, flexible PTO plus 12 paid holidays, paid sick leave, and paid parental and family leave. We also offer a lifestyle spending account, tuition reimbursement, and a cell phone stipend. Lumin Digital is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender identity, or any other legally protected basis.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Application Security and Risk Engineer in New York, NY vacancy
  • $200k - $250k

     ...Hudson River Trading (HRT) is seeking a Security Governance, Risk, and Compliance Engineer to join our growing Information Security team. This function...  ...security architecture reviews for internally developed applications Translate compliance requirements into concrete... 
    Application
    Work at office
    Local area
    Immediate start

    Hudson River Trading

    New York, NY
    4 days ago
  • $405k

     ...Security Risk Engineer Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial...  ...you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems... 
    Application
    Visa sponsorship

    Colorwave Inc

    New York, NY
    3 days ago
  •  ...Infrastructure & Information Security About Core Education Core Education...  ...staff and our own engineers. Standards, reference architectures...  .... Partnership with peers in Application Services, Data & Analytics,...  ...'s portfolio; report status, risks, incidents, and financials to... 
    Application
    Contract work
    For contractors
    Remote work

    Core Education

    New York, NY
    3 days ago
  •  ...iPaaS and helping enterprises unify data, applications, processes, and AI into a single,...  ...orchestration at scale. With enterprise-grade security and continuous innovation at its core,...  ...feedback loops with Product and Engineering teams Influence & Scale (Days 60-90)... 
    Application
    Remote work
    Flexible hours
    Shift work

    Workato

    New York, NY
    27 days ago
  •  ...providing a wide range of investment banking, securities, investment management and wealth...  ...and simulation software, comprehensive risk and security systems, and robust client-...  ...these systems and tools. Our insights, our applications and infrastructure give a competitive... 
    Application
    Work at office
    Remote work
    Worldwide

    ALLTECH CONSULTING SVC INC

    New York, NY
    3 days ago
  •  ...Cloud Security Engineer We are seeking a Cloud Security Engineer to join our cybersecurity team. This role is...  ...candidate will work closely with cloud engineering, application, and network teams to identify security risks, improve cloud security controls, and support... 
    Application
    Work experience placement

    Crossfire Consulting

    New York, NY
    2 days ago
  •  ...frameworks, tools, and technologies while recommending the most suitable one. Architect, design and develop secure, high performance, scalable and maintainable applications using appropriate architectural patterns. Creating high-level product’s technical specifications,... 
    Application

    Govserviceshub

    New York, NY
    4 days ago
  •  ...Department: Security Management Services Reports to: Sr. Consultant & Sr. Manager Ethical Hacker, Infosec Auditor (L1/2 Consultant)...  ...Systems (Windows, Linux, Unix), Databases (MSSQL, Oracle, MySQL), Applications (IIS, Apache, Tomcat), SAP, Virtualization Softwares (Vmware,... 
    Application

    Vista InfoSec

    New York, NY
    5 days ago
  • 210438 Security Administrator Procom is a leading provider of professional...  ...staffing expertise include: Application Development, Project...  ...Infrastructure & Network Services, Risk Management & Compliance,...  ...to the Monitoring and Engineering Team Assist users with problems... 
    Application
    Permanent employment
    Contract work
    For contractors
    H1b
    Work at office

    Procom

    Jersey City, NJ
    2 days ago
  • $120k - $135k

     ...Are you looking to expand and apply your security knowledge in a real environment with...  ..., Network+, or equivalent); Network engineering or security experience in complex environments...  ...é and cover letter for consideration. Applications will be considered on a rolling basis.... 
    Application
    Full time
    Casual work
    Remote work

    The Chapin School

    New York, NY
    4 days ago
  •  ...Con Ed is seeking a Cloud Security Specialist to lead the implementation and management...  ...directly manage a team of cloud security engineers, ensuring secure architectures and...  ...while working closely with DevOps and application teams. Knowledge of secure private connectivity... 
    Application

    Con Ed

    New York, NY
    4 days ago
  • $70 - $90 per hour

     ...Only (USC/GC) Position Title: Cloud Security Engineer (Azure, AWS, GCP, Oracle Cloud)...  ...functional teams to identify security risks, enhance security controls, and shape...  ...expertise will support securing cloud-hosted applications, containers, and networks, while... 
    Application
    For contractors
    Remote work

    Seneca

    New York, NY
    3 days ago
  •  ...The Cloud Security Specialist is a senior technical and leadership position responsible...  ...candidate will lead a team of cloud security engineers, develop secure architectures, and...  ...with cloud service, DevOps, and application teams to design secure deployments, enforce... 
    Application

    Con Ed

    New York, NY
    4 days ago
  • Job Title: EUC Engineer - Endpoint Security & ThreatLocker Location: New York, NY (Hybrid) Job Type: Long-Term Contract A leading alternative...  ...in enterprise environments, specifically around application whitelisting, ringfencing, storage control, and endpoint... 
    Application
    Long term contract

    Atlas Search

    New York, NY
    3 days ago
  •  ...Senior Cloud Security Engineer At BNY, our culture allows us to run our company better and enables...  ...technologies and their practical application in cyber security. It is responsible...  ...driven capabilities for threat detection, risk analysis, automation, incident response... 
    Application
    Worldwide

    BNY

    New York, NY
    a month ago
  •  ...Solutions is looking for a Senior OCI Infrastructure & DevOps Engineer to manage and optimize Oracle Cloud Infrastructure (OCI) environments...  ...Linux, middleware technologies, and CI/CD pipelines to ensure seamless application deployment and system reliability. #J-18808-Ljbffr... 
    Application

    Pansoft Data Solutions

    New York, NY
    4 days ago
  •  ...overall delivery of network, security & cloud based projects utilizing...  ...to identify potential risk, audit and vulnerabilities assessment...  ..., Manage Identity Services Engine(ISE), Authentication and...  ...public/private DNS management. Applications Integration and migration from... 
    Application
    Remote work

    ALLTECH CONSULTING SVC INC

    New York, NY
    1 day ago
  •  ...combination of inventive research, design, and engineering. Our organization is very flat, and our...  ...company. You'll work closely with Security and Engineering to implement zero-trust...  ...access across dozens of SaaS applications via SCIM and API integrations. Build... 
    Application
    Full time
    Work at office

    Anysphere, Inc

    New York, NY
    1 day ago
  •  ...service plans to control customer's source of risk, loss and/or costs. Monitors and...  ...Bachelor's degree with coursework in math, engineering or related areas (or equivalent) and at...  ...information using various proprietary software applications and create/modify documents and complex... 
    Application
    Full time
    Work at office

    InsurAnswers

    New York, NY
    3 days ago
  •  ...Application Security Engineer - Vulnerability Operations (Mid-Level) Position: Contract Location: NJ/TX/NC Duration: 12...  ...classes (OWASP Top 10, API Security Top 10, supply chain risks). ~ Hands-on experience with SAST, DAST, SCA, or related... 
    Application
    Contract work

    Lorven Technologies

    Jersey City, NJ
    5 days ago
  • $250k - $350k

     ...CAST technology can see inside custom applications with MRI-like precision, automatically...  ...readiness, structural flaws, legal and security risks. It's becoming essential for faster...  ...the speed and efficiency of Software Engineering, better open source risk control, and... 
    Application
    Local area
    Remote work

    Remote Jobs

    New York, NY
    3 days ago
  •  ...leader in mobile device and app security, offering real-time, on-...  ...patented z9 machine learning‑based engine. As part of our fast growing...  ...- Understands mobile applications, SaaS based delivery models and...  ...customer. Customer Satisfaction & Risk Management - Maintain a high... 
    Application
    Local area

    Zimperium

    New York, NY
    3 days ago
  •  ...Part-time hourly contractor Overview We are seeking an Azure Security Engineer to ensure proper configuration standards are met and...  ...Engineer, you will help deploy and configure a secure cloud application infrastructure that aligns with business needs. You will be... 
    Application
    Hourly pay
    Part time
    For contractors
    Remote work

    HUGONET LLC

    New York, NY
    3 days ago
  •  ...Senior Detection Engineer (SIEM / Security Observability) Remote, US Description Keeper Security is...  ...standards across cloud infrastructure, applications, endpoints, and identity systems...  ...intelligence, threat hunting, and emerging risks Collaborate with cloud,... 
    Application
    Remote work

    Keeper Security

    New York, NY
    3 days ago
  •  ...forefront of innovation, providing a broad array of AI, Security, and Managed Services. Our mission is to equip...  ...administration and working closely with Coretek and Microsoft engineers on more complex application issues. Responsibilities Provide technical support for... 
    Application
    Remote work
    Flexible hours
    Night shift

    Coretek Services

    New York, NY
    4 days ago
  • Responsibilities Perform on-site risk engineering surveys and desktop reviews for conventional power and renewable energy risks. Assess operational...  .... Demonstrated ability to effectively use required software applications, such as Microsoft Office Suite. Ability to create and... 
    Application
    Work at office

    Liberty Mutual Insurance

    New York, NY
    3 days ago
  •  ...provider of digital platform engineering and development services. We...  ..., ensuring adherence to security and compliance standards and...  ...organizational protocols Coordinate with application, security, workplace, and...  ...Track progress, identify risks, and prepare status reports... 
    Application

    EPAM Systems Inc

    New York, NY
    3 days ago
  • $110k - $140k

     ...Description Tyto Athene is hiring a Cloud Security Engineer (AWS & GCP) to join our team of cloud, security, and compliance experts. This...  ...compliance monitoring. Troubleshoot issues across network, compute, application, and identity layers by reviewing logs, collecting data, and... 
    Application
    Remote work

    Tyto Athene, LLC

    New York, NY
    3 days ago
  •  ...Application Security Engineer We are seeking an Application Security Engineer who will support our client with ensuring security is integrated into all stages of software development. This role will be responsible for designing and building secure applications while... 
    Application

    Damco

    Brooklyn, NY
    7 days ago
  • $200k - $300k

    Hudson River Trading (HRT) is seeking a Risk Engineer to join our Risk team in New York City. In this role, you will focus on building...  ...state-of-the-art performance analytics and risk decomposition applications Work with developers to productionize risk models and risk... 
    Application
    Work at office
    Local area
    Immediate start

    Hudson River Trading

    New York, NY
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Security and Risk Engineer. Be the first to apply!