812,549open jobs
52,293companies
130,976added this week
Browse all
Salary
≈ $124k – $247k per year (Estimated)
Location
In office (New York)
Seniority
Senior · 5+ years exp

Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Jul 30, 2026. TripleLift scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Turn fragmented media into a coordinated system. TripleLift connects data, creative, and supply to drive measurable advertising outcomes.

About TripleLift

We're TripleLift, an advertising platform on a mission to elevate digital advertising through beautiful creative, quality publishers, actionable data and smart targeting. Through over 1 trillion monthly ad transactions, we help publishers and platforms monetize their businesses. Our technology is where the world's leading brands find audiences across online video, connected television, display and native ads. Brand and enterprise customers choose us because of our innovative solutions, premium formats, and supportive experts dedicated to maximizing their performance.

As part of the Vista Equity Partners portfolio, we are NMSDC certified, qualify for diverse spending goals and are committed to economic inclusion. Find out how TripleLift raises up the programmatic ecosystem attriplelift.com.

Overview

The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift's Engineering and Security organization, directly influencing how we protect our advertising platforms and the trust our publishers and advertisers place in us. In this position, you will partner closely with Engineering, Platform, Cloud Infrastructure, and Security teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security, ensuring security is embedded into how we design, build, deploy, and operate our products.This is an exciting opportunity for someone who wants to build and scale an application security program at a company operating at the center of a rapidly evolving, high-stakes ad-tech landscape, while contributing meaningfully to the long-term security posture and resilience of the organization.

Responsibilities

  • Play a critical role in building and maintaining a global security compliance program based on NIST CSF.
  • Scale application security by developing automated security testing utilizing enterprise SAST, DAST, and code-review tools.
  • Champion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities.
  • Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations themselves.
  • Administer and drive adoption of GitHub Advanced Security (GHAS) : code scanning, secret scanning, and dependency review across engineering repositories.
  • Participate in threat modeling and design/architecture spec reviews to identify and mitigate security risks early in the SDLC.
  • Coordinate with stakeholders to develop and implement a vulnerability management program and to perform threat-hunting activities.
  • Own and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate findings from third-party pentest engagements.
  • Monitor and respond to application-layer security threats like API abuses, business logic flaws, and common web vulnerabilities.
  • Collaborate with product and engineering teams to ensure security is a key consideration in software design and architecture.
  • Enhance application security posture by working with cross-functional teams to implement proper authentication, authorization, and data protection mechanisms.
  • Enhance and facilitate security incident handling activities.
  • Evangelize security best practices and provide education and awareness to company employees. Develop and implement secure coding guidelines and conduct secure development training for engineers.
  • Evaluate and continuously improve the maturity of the security program through the deployment and management of various security tools and processes.

Education & Requirements

  • 5 years minimum of experience in application security, secure software development, security engineering, or a similar role. 
  • Strong understanding of secure coding practices and ability to guide developers on remediation strategies.
  • Experience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review.
  • Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode).
  • Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows.
  • Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure.
  • Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security).
  • Ability to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and services.
  • Experience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go).
  • Understanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similar.
  • Strong understanding of AWS security services and controls (IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, with the ability to deploy security tools within them.
  • Takes ownership of projects, works independently with minimal oversight, and delivers results in a fast-paced environment while balancing multiple priorities.
  • Continuously learns, adapts, and values correctness, efficiency, and constructive feedback.

Preferred:

  • Experience in the ad-tech / programmatic advertising industry, or another high-scale, real-time environment.
  • Preferred: Familiarity with using AI/LLM-based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automation.
  • Holds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc.

US Jobs:  The base salary range represents the low and high end of the TripleLift US salary range for this position. Actual salaries will vary depending on factors including but not limited to experience and performance. The range listed is just one component of TripleLift’s total compensation package for employees. Other rewards may include bonuses, an open Paid Time Off policy, and many region-specific benefits.

Pay is based on various non-discriminatory factors including but not limited to experience, education, and skills.

Benefits Available to Eligible Employees Include the following*:

  • Medical, Dental & Vision Plans
  • Flexible PTO
  • 401k w/ employer match

*Full-time employees are eligible for comprehensive benefits (subject to the terms of applicable plans/policies/agreements, which will be made available to you after commencing employment).

Salary range transparency

$160,000—$200,000 USD

Life at TripleLift

At TripleLift, we’re a team of great people who like who they work with and want to make everyone around them better. This means being positive, collaborative, and compassionate. We hustle harder than the competition and are continuously innovating.

Learn more about TripleLift and our culture by visiting our LinkedIn Life page.

Establishing People, Culture and Community Initiatives

At TripleLift, we are committed to building a culture where people feel connected, supported, and empowered to do their best work. We invest in our people and foster a workplace that encourages curiosity, celebrates shared values, and promotes meaningful connections across teams and communities. We want to ensure the best talent of every background, viewpoint, and experience has an opportunity to be hired, belong, and develop at TripleLift. Through our People, Culture, and Community initiatives, we aim to create an environment where everyone can thrive and feel a true sense of belonging.

Privacy Policy

Please see our Privacy Policies on our TripleLift and 1plusX websites.

TripleLift does not accept unsolicited resumes from any type of recruitment search firm. Any resume submitted in the absence of a signed agreement will become the property of TripleLift and no fee shall be due.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
812,549 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
New York
≈ $25k – $59k per year (Estimated) • In office • 3+ years exp • Master's Degree • Bengaluru
Python
SQL
PowerShell
DevOps
Linux
Windows
TCP/IP
DNS
Cybersecurity
Active Directory
PKI
Apply
≈ $33k – $75k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Bengaluru
DevOps
Incident Management
Apply
≈ $28k – $62k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Hyderabad
SQL
Apply
≈ $34k – $76k per year (Estimated) • Remote (India) • Full-Time • 8+ years exp • India • Pakistan
Python
Go
JavaScript
TypeScript
C#
DevOps
Azure
CI/CD
AWS
Shift-Left
Cybersecurity
ISO 27001
OWASP Top 10
SOC 2
Shift-Left Security
Threat Modeling
Apply
≈ $35k – $78k per year (Estimated) • In office • 8+ years exp • Bengaluru
DevOps
Platform Engineering
Cybersecurity
SIEM
Apply
$112k – $147k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Arlington Heights
Python
JavaScript
Java
TypeScript
PowerShell
C#
Node JS
C#
.NET
Databases
PostgreSQL
DynamoDB
ActiveMQ
Amazon Aurora
AI/ML
Copilot
Claude
AI Agents
Frontend
Angular
DevOps
GCP
Azure DevOps
Azure
CI/CD
Git
AWS
Kubernetes
AWS Lambda
Amazon EC2
GitHub
Amazon S3
Amazon ECS
Amazon CloudWatch
AWS Step Functions
API Gateway
Management
Confluence
Jira
Agile
Scrum
Apply
Hybrid • 3+ years exp • Bachelor's Degree • Portsmouth
JavaScript
Java
TypeScript
SQL
Node JS
Java
Spring Boot
AI/ML
Copilot
Claude Code
Prompt Engineering
AWS Bedrock
LLM
RAG
OpenAI
Frontend
React.js
DevOps
GitHub Actions
Azure
CI/CD
AWS
AWS Lambda
Amazon S3
Management
Agile
Scrum
Apply
Hybrid • 3+ years exp • Bachelor's Degree • Boston
Python
Java
SQL
Perl
Databases
Snowflake
AI/ML
Hadoop
Analytics
Power BI
ETL/ELT
Management
Confluence
Jira
Apply
$134k – $279k per year • In office • Secret • 8+ years exp • Bachelor's Degree • Fort Belvoir
Python
Go
JavaScript
TypeScript
Node JS
Frontend
React.js
DevOps
CI/CD
Apply
$122k – $200k per year • In office • Bachelor's Degree • Colorado Springs
Python
JavaScript
Rust
TypeScript
DevOps
Terraform
Ansible
Helm
Kustomize
GitLab CI
SLURM
Azure
CI/CD
AWS
Kubernetes
SRE
Platform Engineering
Configuration Management
Nexus Repository
GitLab
HPC
Linux
Windows
Cybersecurity
SonarQube
Trivy
CIS Benchmarks
CVE
CWE
CVSS
SLSA
Sonatype Nexus IQ
Sigstore
Cosign
KICS
OWASP
QA
Cypress
Playwright
Pytest
Vitest
Apply
≈ $92k – $197k per year (Estimated) • In office • 5+ years exp • Toronto
Python
Java
TypeScript
AI/ML
Claude
LLM
DevOps
CI/CD
AWS
GitHub
IAM
Cybersecurity
Burp Suite
Snyk
OWASP ZAP
Checkmarx
ISO 27001
CodeQL
NIST CSF
OWASP Top 10
SOC 2
CWE
Threat Modeling
Veracode
Apply
≈ $73k – $179k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Toronto
Python
Java
SQL
Scala
Databases
ClickHouse
InfluxDB
Apache Kafka
OpenSearch
AI/ML
Spark
MLFlow
Ray
Feast
DevOps
ArgoCD
Kubernetes
Apply
≈ $127k – $246k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • New York
Python
Java
SQL
Scala
Databases
ClickHouse
InfluxDB
Apache Kafka
OpenSearch
AI/ML
Spark
MLFlow
Ray
Feast
DevOps
ArgoCD
Kubernetes
Apply
≈ $165k – $310k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • New York
Java
Databases
Redis
Snowflake
RabbitMQ
Apache Kafka
AI/ML
Copilot
Cursor
Spark
Claude Code
AI Agents
DevOps
AWS
Apply
Senior Cloud Engineer 15 days ago
≈ $123k – $238k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • New York
Python
Go
Java
Scala
Databases
MySQL
PostgreSQL
Snowflake
Databricks
Aerospike
Apache Kafka
Redpanda
AI/ML
Spark
dbt
DevOps
Terraform
Puppet
Helm
GitHub Actions
OpenTelemetry
Terragrunt
Consul
Kustomize
Nomad
PagerDuty
ArgoCD
AWS
Kubernetes
Grafana
Amazon EC2
Amazon S3
Analytics
Fivetran
Apply
≈ $112k – $255k per year (Estimated) • In office • New York
Python
JavaScript
Cybersecurity
OWASP Top 10
Apply
$60k – $80k per year • In office • Internship • New York
AI/ML
Model Context Protocol
Design
Canva
Apply
$110k – $140k per year • Equity 0.1–0.3% • In office • Full-Time • New York
Design
Canva
Apply
$150k – $240k per year • Equity 0.1–0.3% • In office • Full-Time • 6+ years exp • New York
AI/ML
Claude
Apply
Account Executive 1 day ago
$250k – $315k per year • In office • Full-Time • 3+ years exp • New York
Apply
See all jobs
This is one of many
812,549 more open roles from verified company boards, updated every day.