Lead Application Security Engineer
$220k - $250kZeta Global
WHO WE ARE
Zeta Global (NYSE: ZETA) is the AI-Powered Marketing Cloud that leverages advanced artificial intelligence (AI) and trillions of consumer signals to make it easier for marketers to acquire, grow, and retain customers more efficiently. Through the Zeta Marketing Platform (ZMP), our vision is to make sophisticated marketing simple by unifying identity, intelligence, and omnichannel activation into a single platform – powered by one of the industry’s largest proprietary databases and AI. Our enterprise customers across multiple verticals are empowered to personalize experiences with consumers at an individual level across every channel, delivering better results for marketing programs. Zeta was founded in 2007 by David A. Steinberg and John Sculley and is headquartered in New York City with offices around the world. To learn more, go to About the Role We’re seeking a Lead Application Security Engineer to help advance Zeta Global’s application and platform security posture through AI-native security practices, intelligent automation, and scalable security engineering. You’ll play a critical role in embedding security throughout the software development lifecycle by using AI-driven tools, automated controls, and data-informed risk prioritization to ensure our systems, applications, and AI-powered platforms are built securely from the ground up. Zeta operates at massive scale, powering billions of consumer profiles and petabytes of data across real-time, AI-powered marketing platforms. In this role, you’ll collaborate with Engineering, Product, QA, DevOps, and AI platform teams to identify risks, design secure-by-default patterns, and build automated security capabilities that enable secure innovation at speed. This position offers significant technical scope, cross-functional visibility, and the opportunity to directly influence the company’s security maturity through AI-enabled threat modeling, automated validation, intelligent vulnerability management, and proactive defense. Key Responsibilities AI-Driven Threat Modeling & Security Validation Use AI-assisted threat modeling capabilities to identify application, platform, API, cloud, data, and AI/ML security risks early in the design and development process. Leverage automated security review tools to evaluate architecture, design documents, code changes, APIs, and data flows for security gaps and control weaknesses. Drive AI-assisted code security reviews using SAST, DAST, SCA, secrets detection, IaC scanning, container scanning, and contextual risk analysis. Use automation and intelligent correlation to assess third-party libraries, APIs, vendor integrations, and open-source dependencies for security, compliance, and supply-chain risk. Support AI-enabled red team, blue team, and incident response simulations to validate detection, prevention, and response capabilities. Embedding AI-Native Security into the SDLC Partner with developers and QA engineers to embed AI-driven security testing and automated risk detection into CI/CD pipelines. Build and improve security automation that provides real-time feedback to developers during design, coding, testing, release, and deployment. Use AI-assisted analysis to review architecture and design artifacts, identify risks earlier, and recommend secure implementation patterns. Contribute to intelligent security checkpoints that reduce manual review effort while improving consistency, traceability, and developer velocity. Help design scalable guardrails, reusable security controls, and policy-as-code capabilities across application and platform teams. Emerging Threat Monitoring & Proactive Defense Monitor evolving application, cloud, API, AI/ML, and data security risks using AI-assisted threat intelligence, vulnerability intelligence, and attack-pattern analysis. Identify and evaluate AI-specific threats such as prompt injection, data poisoning, model abuse, model leakage, insecure tool use, and sensitive data exposure. Assist in designing and deploying proactive defense mechanisms across applications, APIs, data platforms, and AI-powered systems. Use automated signals, telemetry, and risk scoring to support investigations, post-incident analysis, and continuous improvement of prevention and detection capabilities. Translate recurring vulnerabilities and incidents into feedback loops that improve threat models, secure design patterns, and SDLC controls. Security Awareness, Standards & Scalable Enablement Promote secure coding and secure design practices through AI-assisted guidance, reusable playbooks, automated recommendations, and developer-friendly documentation. Contribute to internal security standards, secure engineering patterns, and AI-native security playbooks. Help teams adopt security self-service capabilities that reduce dependency on manual AppSec review. Collaborate closely with Engineering, DevOps, QA, Product, and AI platform teams to foster a security-first and automation-first culture. Use metrics and insights to measure control effectiveness, remediation trends, developer adoption, and overall security maturity. What You Need to Succeed Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience. 5+ years of experience in Application Security, DevSecOps, Secure Software Development, or Security Engineering. Strong understanding of OWASP Top 10, SANS CWE Top 25, secure design principles, and application threat modeling. Familiarity with AI/ML security concepts such as prompt injection, data poisoning, adversarial testing, model integrity, model abuse, and AI supply-chain risks. Experience building or integrating AI-assisted security workflows, security bots, automated triage systems, or risk scoring models. Experience using AI-assisted or automation-driven approaches to improve security testing, vulnerability analysis, code review, or risk prioritization. Experience with modern application frameworks and architectures such as React, Node.js, Django, FastAPI, or similar technologies. Knowledge of securing APIs, microservices, authentication, and authorization mechanisms such as OAuth2, OIDC, JWT, and service-to-service authentication. Experience with cloud platforms such as AWS, GCP, or Azure, and containerized environments such as Docker and Kubernetes. Working knowledge of security testing and automation tools such as Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security, or similar tools. Ability to analyze security findings, correlate risk context, and drive practical remediation guidance for engineering teams. Strong collaboration and communication skills with the ability to work across Engineering, Product, QA, DevOps, and Security teams. Nice to Have Experience with policy-as-code, infrastructure-as-code security, CI/CD security controls, and automated governance. Experience with automation frameworks and scripting for security testing, vulnerability validation, and remediation workflows. Relevant certifications such as OSCP, GWAPT, CSSLP, cloud security certifications, or AI/ML-specific security certifications.BENEFITS & PERKS
Unlimited PTO Excellent medical, dental, and vision coverage Employee Equity Employee Discounts, Virtual Wellness Classes, and Pet Insurance And more!!SALARY RANGE
The salary range for this role is $220,000-$250,000 TC, depending on location and experience.PEOPLE & CULTURE AT ZETA
Zeta considers applicants for employment without regard to, and does not discriminate on the basis of an individual’s sex, race, color, religion, age, disability, status as a veteran, or national or ethnic origin; nor does Zeta discriminate on the basis of sexual orientation, gender identity or expression. We’re committed to building a workplace culture of trust and belonging, so everyone feels invited to bring their whole selves to work. We provide a forum for employees to celebrate, support and advocate for one another. Learn more about our commitment to diversity, equity and inclusion here:ZETA IN THE NEWS!
#LI-TS1 Zeta GlobalVacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Lead Application Security Engineer in New York, NY vacancy
$100k - $258k
...knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who... ...teammates.ABOUT THE ROLE:We are seeking a skilled and innovative Application Security Engineer to join ð Money. In this role, you will protect...SuggestedPermanent employmentTemporary work$150 per hour
A financial firm is looking for an Application Security Engineer to join their team in Iselin, NJ or NYC.Compensation: $150-200kResponsibilities:Perform Application Security scans (e.g. DAST and SCA) on applications and APIs to identify security vulnerabilities and weaknessesTriage...Suggested- ...SaaS Security Engineer 6–9 Month Contract | Potential Extension Hybrid – New York City | 2–3 Days/Week Onsite Overview Our client... ...help strengthen the security posture of its critical SaaS applications. This role will focus heavily on SaaS Security Posture...SuggestedContract work2 days per week3 days per week
- ...Financial Services firm in search for an Application Security professional to join their team.... ...10 Ability to define, initiate and lead an Application Security program Experience... ..., Information Management, Computer Engineering, Cybersecurity or equivalent Certifications...SuggestedFull timeVisa sponsorship
$244k - $305k
As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll define... ...team with meaningful, actionable security signals.Lead threat modeling and risk assessment for high-risk features...Suggested- ...Senior Application Security Engineer with Hands on Python Location- Princeton, NJ & NYC, NY (Hybrid) • 8-15+ years in software engineering and application security, with substantial hands-on development experience (not security-adjacent - you've shipped code...
- ...Application Security Engineer - Job Description (JD) Job Title Application Security Engineer (AppSec Engineer) Job Summary We are seeking an experienced Application Security Engineer to ensure the security of software applications throughout the Software...Remote work
- ...Application Security Engineer Using Python Location: NYC or Alpharetta, GA – Need locals only Nature of Job: 5 days onsite Duration: 12+ months Interview Mode: video and final in person interview What You’ll Do: Be part of a team of engineers to implement...Work experience placementLocal area
$150k - $180k
...The Position We are seeking a highly skilled Senior Application Security Engineer to help establish and mature our secure software development... ...Security & Secure Development Lifecycle (SDL) Lead and mature the organization's secure software development...Full time- ...Because at Valence, the work worth doing is the kind that redefines work itself. The Role We are seeking a seasoned Application Security Engineer to help us secure our products and platform that serve our Fortune 500 customers. In this pivotal role, you will be...Full timeFreelanceWork from home
$100.63k - $167.79k
...Sr. Application Security Engineer Where Ambition Meets Innovation Build a career that matches all your initiative with an impressive dose of innovation. From cutting-edge resources and a collaborative environment to the freedom to make an impact and more, you'll...Work from home$200k - $235k
...York City office to support collaborative team dynamics and innovative problem-solving. We are seeking a Senior Application Security Engineer to lead the technical execution of our product security strategy. This role focuses on securing high-growth FinTech and Web3...Full timeWork at officeWorldwide$60 - $65 per hour
...A client of Innova Solutions is immediately hiring for an Application Security Engineer Position type: Full-Time Contract (W2) Role: Application Security Engineer Duration: 6+ Months Contract Location : Remote The Application Security / DevSecOps...Hourly payFull timeContract workTemporary workFor contractorsWork experience placementImmediate startRemote workWorldwideFlexible hours$180k - $258k
...Product Security Engineer We are looking for a Product Security Engineer to join our team and... ...Responsibilities Security by Design: Lead threat modeling sessions during the... ...focusing on product security or application security. Technical Skills:...Shift work$1,000 per month
...Health reaches more than 170 million people worldwide through leading employers, health plans, and partners. As an AI-native... ...and our mission. Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team....Full timeWork experience placementRemote workWorldwide- ...best pay, diversity in tech, and best job-fit for every candidate we place. Our client, a leading financial services firm, is seeking a Lead Application Security Engineer to join their team in New York, NY! Responsibilities: Application Threat Modeling...Work at office
$165.2k - $295k
...thousands of connected devices. The Samsara Application Security team protects this vast footprint end-... .... As a Staff Application Security Engineer, you’ll drive the overarching technical... ...best. In this role, you will: Lead the ongoing strategy, operation, and continuous...Remote workFlexible hoursShift work$220k - $250k
...headquartered in New York City with offices around the world. To learn more, go to About The Role We’re seeking a Lead Application Security Engineer to help advance Zeta Global’s application and platform security posture through AI-native security practices,...$121.4k - $166.7k
...the lookout for a passionate Senior Security Platform Engineer who is skilled at diving into complex... ...Manhattan. WHAT WE DOThe Rockstar Games Application Security team partners with numerous... ...guidance to developers, team leads, and producers.Drive remediation efforts...Full timeWork at office- ...Job Title: Application Security Engineer Client: JPMC Employment Type: W2 Contract Location: Albany, NY Hybrid Job Summary JPMC is seeking an experienced Application Security Engineer to work closely with development teams on enterprise Java...Contract work
- ...SpaceXAI is seeking an Application Security Engineer to protect the security and integrity of payments and financial products across the software development lifecycle. You will oversee code security, secure CI/CD practices, and SBOM‑driven supply chain controls while...
$130k - $190k
...behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Application Security Engineer based in United States. This is a... ...is preferred. ~ Experience building or leading a Security Champions program is a plus....Remote workWork from homeHome office$169k - $220k
...lower cost through early diagnosis and longitudinal care management of chronic conditions. We are looking for a Senior Application Security Engineer to break Counterpart Assistant before anyone else does. This is a hands-on offensive security role on our Eng Core team,...Work experience placementWork at officeRemote workFlexible hours- The Estée Lauder Companies Inc. is seeking an experienced Application Security professional to evangelize our security strategy under the Global Head of Application Security. You will work on SDLC security, DevSecOps, and multi-cloud initiatives to deliver trusted software...
$190k - $237k
Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally... ..., among its board members. Role Overview The Senior Application Security Engineer is a senior individual contributor responsible for strengthening...WorldwideFlexible hours$192k - $240k
...support you need to grow your career. Engineering at Brex Engineering at Brex is about building... .... Our teams span Software, Data, Security, and IT, and operate with high autonomy... ...become leaders. What you’ll do As a Senior Application Security Engineer, you will focus on...Remote jobWork experience placement- ...rank among the leaders in areas like application development and AI/ML, and our people-... ...are looking for a Senior Application Security Engineer to strengthen secure coding and DevSecOps... ...include Fortune 500 enterprises and leading product brands. - Flextime: Tailor your...Work at officeWork from homeVisa sponsorshipWork visa
- Overview Application Security Engineer Remote within the US US Citizen Approximately 8 Month Contract (w/ possible extensions) Summary The Application Security Engineer candidate will have a strong background in cybersecurity and understanding of web application and zero...Contract workRemote work
$130k - $190k
...and customers helps us better serve their needs. The Senior Application Security Engineer serves as a hands-on technical authority for the security... ...application security requirements. Experience building or leading a Security Champions program. Experience developing AppSec...Remote workWork from homeWorldwideHome office$82k - $118k
...available while providing a level of professionalism and service unsurpassed in the lending industry. Position Summary The Application Security Engineer at Guild Mortgage supports the security of our applications, including AI-enabled applications and services. Working...Minimum wageWork at officeLocal areaWork from homeMonday to FridayShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Application Security Engineer. Be the first to apply!
Related searches
- lead algorithm engineer New York, NY
- lead engineer New York, NY
- lead operating engineer New York, NY
- lead network engineer New York, NY
- lead app. developer New York, NY
- lead infrastructure engineer New York, NY
- lead web developer New York, NY
- lead security engineer New York, NY
- lead system engineer New York, NY
- application security engineer New York, NY




