{"id":952621,"url":"https://alion.io/job/triplelift-senior-application-security-engineer-2","title":"Senior Application Security Engineer","company":{"id":685632,"name":"TripleLift","domain":"triplelift.com","url":"https://alion.io/company/triplelift","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"A","score":88,"open_postings":4,"ghost_share":0,"stale_share":0.5,"repost_share":0,"time_to_fill_p50_days":47,"computed_at":"2026-10-08T05:49:30Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["New York, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":20000,"max_usd":45000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":11},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Burp Suite","optional":false},{"name":"Checkmarx","optional":false},{"name":"CI/CD","optional":false},{"name":"Claude","optional":false},{"name":"CodeQL","optional":false},{"name":"CWE","optional":false},{"name":"GitHub","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"Java","optional":false},{"name":"LLM","optional":false},{"name":"NIST CSF","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"OWASP ZAP","optional":false},{"name":"Python","optional":false},{"name":"Snyk","optional":false},{"name":"SOC 2","optional":false},{"name":"Threat Modeling","optional":false},{"name":"TypeScript","optional":false},{"name":"Veracode","optional":false}],"status":"live","first_seen_at":"2026-07-30T20:03:47Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-10-09T01:51:50Z","board_verified":true,"closed_at":null,"days_open":70,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":70},"description":"About TripleLift\nWe're TripleLift, an advertising platform on a mission to elevate digital advertising through beautiful creative, quality publishers, actionable data and smart targeting. Through over 1 trillion monthly ad transactions, we help publishers and platforms monetize their businesses. Our technology is where the world's leading brands find audiences across online video, connected television, display and native ads. Brand and enterprise customers choose us because of our innovative solutions, premium formats, and supportive experts dedicated to maximizing their performance.\nAs part of the Vista Equity Partners portfolio, we are NMSDC certified, qualify for diverse spending goals and are committed to economic inclusion. Find out how TripleLift raises up the programmatic ecosystem attriplelift.com.\nOverview\nThe Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift's Engineering and Security organization, directly influencing how we protect our advertising platforms and the trust our publishers and advertisers place in us. In this position, you will partner closely with Engineering, Platform, Cloud Infrastructure, and Security teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security, ensuring security is embedded into how we design, build, deploy, and operate our products.This is an exciting opportunity for someone who wants to build and scale an application security program at a company operating at the center of a rapidly evolving, high-stakes ad-tech landscape, while contributing meaningfully to the long-term security posture and resilience of the organization.\nResponsibilities\nPlay a critical role in building and maintaining a global security compliance program based on NIST CSF.\nScale application security by developing automated security testing utilizing enterprise SAST, DAST, and code-review tools.\nChampion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities.\nAutomate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations themselves.\nAdminister and drive adoption of GitHub Advanced Security (GHAS) : code scanning, secret scanning, and dependency review across engineering repositories.\nParticipate in threat modeling and design/architecture spec reviews to identify and mitigate security risks early in the SDLC.\nCoordinate with stakeholders to develop and implement a vulnerability management program and to perform threat-hunting activities.\nOwn and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate findings from third-party pentest engagements.\nMonitor and respond to application-layer security threats like API abuses, business logic flaws, and common web vulnerabilities.\nCollaborate with product and engineering teams to ensure security is a key consideration in software design and architecture.\nEnhance application security posture by working with cross-functional teams to implement proper authentication, authorization, and data protection mechanisms.\nEnhance and facilitate security incident handling activities.\nEvangelize security best practices and provide education and awareness to company employees. Develop and implement secure coding guidelines and conduct secure development training for engineers.\nEvaluate and continuously improve the maturity of the security program through the deployment and management of various security tools and processes.\nEducation & Requirements\n5 years minimum of experience in application security, secure software development, security engineering, or a similar role. \nStrong understanding of secure coding practices and ability to guide developers on remediation strategies.\nExperience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review.\nProficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode).\nHands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows.\nHands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure.\nKnowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security).\nAbility to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and services.\nExperience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go).\nUnderstanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similar.\nStrong understanding of AWS security services and controls (IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, with the ability to deploy security tools within them.\nTakes ownership of projects, works independently with minimal oversight, and delivers results in a fast-paced environment while balancing multiple priorities.\nContinuously learns, adapts, and values correctness, efficiency, and constructive feedback.\nPreferred:\nExperience in the ad-tech / programmatic advertising industry, or another high-scale, real-time environment.\nPreferred: Familiarity with using AI/LLM-based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automation.\nHolds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc.\nUS Jobs: The base salary range represents the low and high end of the TripleLift US salary range for this position. Actual salaries will vary depending on factors including but not limited to experience and performance. The range listed is just one component of TripleLift’s total compensation package for employees. Other rewards may include bonuses, an open Paid Time Off policy, and many region-specific benefits.\nPay is based on various non-discriminatory factors including but not limited to experience, education, and skills.\nBenefits Available to Eligible Employees Include the following*:\nMedical, Dental & Vision Plans\nFlexible PTO\n401k w/ employer match\n*Full-time employees are eligible for comprehensive benefits (subject to the terms of applicable plans/policies/agreements, which will be made available to you after commencing employment).\nSalary range transparency\n$160,000—$200,000 USD\nLife at TripleLift\nAt TripleLift, we’re a team of great people who like who they work with and want to make everyone around them better. This means being positive, collaborative, and compassionate. We hustle harder than the competition and are continuously innovating.\nLearn more about TripleLift and our culture by visiting our LinkedIn Life page.\nEstablishing People, Culture and Community Initiatives\nAt TripleLift, we are committed to building a culture where people feel connected, supported, and empowered to do their best work. We invest in our people and foster a workplace that encourages curiosity, celebrates shared values, and promotes meaningful connections across teams and communities. We want to ensure the best talent of every background, viewpoint, and experience has an opportunity to be hired, belong, and develop at TripleLift. Through our People, Culture, and Community initiatives, we aim to create an environment where everyone can thrive and feel a true sense of belonging.\nPrivacy Policy\nPlease see our Privacy Policies on our TripleLift and 1plusX websites.\n TripleLift does not accept unsolicited resumes from any type of recruitment search firm. Any resume submitted in the absence of a signed agreement will become the property of TripleLift and no fee shall be due.","description_format":"text","description_chars":8036,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["401k plan","Equity"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Artificial Intelligence","Commerce","Sales & Marketing"],"lifecycle":[{"event":"open","at":"2026-09-16T02:11:40Z"}],"visa":[],"liveness":{"score":25,"band":"fade","label":"Fading","p_open":1,"p_active":0.579,"p_room":0.44,"age_days":69,"expected_fill_days":47,"reasons":["conf:0","win:tail","crowd:"],"computed_at":"2026-10-08T05:49:30Z"},"pay":null,"html_url":"https://alion.io/job/triplelift-senior-application-security-engineer-2","json_url":"https://alion.io/job/triplelift-senior-application-security-engineer-2.json","meta":{"generated_at":"2026-10-09T03:57:55Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3271,"day_limit":5000,"remaining_today":1729,"minute_limit":60,"resets_at":"2026-10-10T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":685632},"rest":"https://alion.io/mcp/rest/get_company?id=685632"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Ftriplelift-senior-application-security-engineer-2"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Ftriplelift-senior-application-security-engineer-2"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Ftriplelift-senior-application-security-engineer-2"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/triplelift-senior-application-security-engineer-2\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Ftriplelift-senior-application-security-engineer-2"}]}