1,097,669open jobs
63,892companies
187,136added this week
Browse all
Salary
≈ $90k – $206k per year (Estimated)
Location
In office (Toronto)
Seniority
Senior · 5+ years exp

Confirmed on the employer's own hiring board on Oct 2, 2026. First seen by Alion on Aug 12, 2026. TripleLift scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Turn fragmented media into a coordinated system. TripleLift connects data, creative, and supply to drive measurable advertising outcomes.

About TripleLift

We're TripleLift, an advertising platform on a mission to elevate digital advertising through beautiful creative, quality publishers, actionable data and smart targeting. Through over 1 trillion monthly ad transactions, we help publishers and platforms monetize their businesses. Our technology is where the world's leading brands find audiences across online video, connected television, display and native ads. Brand and enterprise customers choose us because of our innovative solutions, premium formats, and supportive experts dedicated to maximizing their performance.

As part of the Vista Equity Partners portfolio, we are NMSDC certified, qualify for diverse spending goals and are committed to economic inclusion. Find out how TripleLift raises up the programmatic ecosystem attriplelift.com.

Overview

The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift's Engineering and Security organization, directly influencing how we protect our advertising platforms and the trust our publishers and advertisers place in us. In this position, you will partner closely with Engineering, Platform, Cloud Infrastructure, and Security teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security, ensuring security is embedded into how we design, build, deploy, and operate our products.This is an exciting opportunity for someone who wants to build and scale an application security program at a company operating at the center of a rapidly evolving, high-stakes ad-tech landscape, while contributing meaningfully to the long-term security posture and resilience of the organization.

Responsibilities

  • Play a critical role in building and maintaining a global security compliance program based on NIST CSF.
  • Scale application security by developing automated security testing utilizing enterprise SAST, DAST, and code-review tools.
  • Champion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities.
  • Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations themselves.
  • Administer and drive adoption of GitHub Advanced Security (GHAS) : code scanning, secret scanning, and dependency review across engineering repositories.
  • Participate in threat modeling and design/architecture spec reviews to identify and mitigate security risks early in the SDLC.
  • Coordinate with stakeholders to develop and implement a vulnerability management program and to perform threat-hunting activities.
  • Own and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate findings from third-party pentest engagements.
  • Monitor and respond to application-layer security threats like API abuses, business logic flaws, and common web vulnerabilities.
  • Collaborate with product and engineering teams to ensure security is a key consideration in software design and architecture.
  • Enhance application security posture by working with cross-functional teams to implement proper authentication, authorization, and data protection mechanisms.
  • Enhance and facilitate security incident handling activities.
  • Evangelize security best practices and provide education and awareness to company employees. Develop and implement secure coding guidelines and conduct secure development training for engineers.
  • Evaluate and continuously improve the maturity of the security program through the deployment and management of various security tools and processes.

Education & Requirements

  • 5 years minimum of experience in application security, secure software development, security engineering, or a similar role. 
  • Strong understanding of secure coding practices and ability to guide developers on remediation strategies.
  • Experience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review.
  • Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode).
  • Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows.
  • Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure.
  • Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security).
  • Ability to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and services.
  • Experience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go).
  • Understanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similar.
  • Strong understanding of AWS security services and controls (IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, with the ability to deploy security tools within them.
  • Takes ownership of projects, works independently with minimal oversight, and delivers results in a fast-paced environment while balancing multiple priorities.
  • Continuously learns, adapts, and values correctness, efficiency, and constructive feedback.

Preferred:

  • Experience in the ad-tech / programmatic advertising industry, or another high-scale, real-time environment.
  • Preferred: Familiarity with using AI/LLM-based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automation.
  • Holds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc.

Life at TripleLift

At TripleLift, we’re a team of great people who like who they work with and want to make everyone around them better. This means being positive, collaborative, and compassionate. We hustle harder than the competition and are continuously innovating.

Learn more about TripleLift and our culture by visiting our LinkedIn Life page.

Establishing People, Culture and Community Initiatives

At TripleLift, we are committed to building a culture where people feel connected, supported, and empowered to do their best work. We invest in our people and foster a workplace that encourages curiosity, celebrates shared values, and promotes meaningful connections across teams and communities. We want to ensure the best talent of every background, viewpoint, and experience has an opportunity to be hired, belong, and develop at TripleLift. Through our People, Culture, and Community initiatives, we aim to create an environment where everyone can thrive and feel a true sense of belonging.

Privacy Policy

Please see our Privacy Policies on our TripleLift and 1plusX websites.

TripleLift does not accept unsolicited resumes from any type of recruitment search firm. Any resume submitted in the absence of a signed agreement will become the property of TripleLift and no fee shall be due.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,097,669 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Toronto
$51k – $60k per year • Hybrid • 5+ years exp • Banff
DevOps
IAM
DNS
DHCP
Cybersecurity
ISO 27001
Microsoft Defender
Active Directory
OWASP
Apply
$51k – $60k per year • Hybrid • 5+ years exp • Banff
DevOps
IAM
DNS
DHCP
Cybersecurity
ISO 27001
Microsoft Defender
Active Directory
OWASP
Apply
$39k – $84k per year • Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • Mississauga
Python
Java
PowerShell
Bash
DevOps
Rest API
CI/CD
Windows
Analytics
Power BI
Apply
≈ $91k – $208k per year (Estimated) • In office • 10+ years exp • Calgary
DevOps
Azure
Cybersecurity
Wiz
Zero Trust
Microsoft Entra ID
Apply
$84k – $98k per year • In office • Secret • 8+ years exp • Bachelor's Degree • Pickering
Apply
≈ $17k – $37k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Pune • Chennai • Bengaluru
JavaScript
Java
TypeScript
SQL
Java
Maven
Spring Boot
Databases
MySQL
PostgreSQL
Oracle
Frontend
React.js
DevOps
Rest API
CI/CD
Git
AWS
Docker
Kubernetes
Management
Agile
Scrum
Apply
≈ $32k – $69k per year (Estimated) • Equity • Hybrid • Full-Time • 1+ year exp • Kraków
Java
Kotlin
TypeScript
SQL
Kotlin
Mockito
Mobile
JUnit
DevOps
GCP
Azure
AWS
Platform Engineering
Web3
Abstract
Apply
$83k – $99k per year • Hybrid • Full-Time • 5+ years exp • Kraków
Python
Java
Kotlin
Databases
Apache Kafka
DevOps
Terraform
GCP
AWS
Docker
Kubernetes
Amazon S3
Analytics
ETL/ELT
Apply
Hybrid • 4+ years exp
Python
JavaScript
TypeScript
Python
FastAPI
Databases
PostgreSQL
Frontend
Next.js
React.js
DevOps
GCP
Azure
Apply
≈ $18k – $39k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Chennai
Java
Java
Spring Boot
DevOps
Rest API
GCP
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Management
Agile
Apply
≈ $21k – $45k per year (Estimated) • In office • 5+ years exp • New York
Python
Java
TypeScript
AI/ML
Claude
LLM
DevOps
CI/CD
AWS
GitHub
IAM
Cybersecurity
Burp Suite
Snyk
OWASP ZAP
Checkmarx
ISO 27001
CodeQL
NIST CSF
OWASP Top 10
SOC 2
CWE
Threat Modeling
Veracode
Apply
Senior Data Engineer 10 days ago
≈ $81k – $161k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Toronto
Python
Java
SQL
Scala
Databases
ClickHouse
InfluxDB
Apache Kafka
OpenSearch
AI/ML
Spark
MLFlow
Ray
Feast
DevOps
ArgoCD
Kubernetes
Apply
Senior Data Engineer 10 days ago
≈ $129k – $252k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • New York
Python
Java
SQL
Scala
Databases
ClickHouse
InfluxDB
Apache Kafka
OpenSearch
AI/ML
Spark
MLFlow
Ray
Feast
DevOps
ArgoCD
Kubernetes
Apply
Senior Staff Engineer 14 days ago
≈ $173k – $313k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • New York
Java
Databases
Redis
Snowflake
RabbitMQ
Apache Kafka
AI/ML
Copilot
Cursor
Spark
Claude Code
AI Agents
DevOps
AWS
Apply
≈ $111k – $213k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • Zurich
Java
Java
Netty
Databases
Redis
Snowflake
Aerospike
RabbitMQ
Couchbase
Apache Kafka
AI/ML
Copilot
Cursor
Spark
Claude Code
Computer Vision
AI Agents
LLM
DevOps
AWS
Apply
≈ $53k – $97k per year (Estimated) • In office • 4+ years exp • Toronto
DevOps
Incident Management
Management
Microsoft Office
Apply
$39k – $60k per year • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Toronto
Python
JavaScript
SQL
Databases
Apache Kafka
AI/ML
Airflow
Frontend
Bootstrap
JQuery
Mobile
JUnit
DevOps
Rest API
Cybersecurity
Keycloak
Analytics
Apache NiFi
Management
Agile
Scrum
Apply
In office • Full-Time • 5+ years exp • Bachelor's Degree • Toronto
COBOL
COBOL
VSAM
JCL
Databases
Db2
IMS
DevOps
CI/CD
Incident Management
GitHub
Management
Agile
Scrum
Apply
≈ $57k – $159k per year (Estimated) • Hybrid • Full-Time • Toronto
Analytics
Power BI
Microsoft Excel
Management
Microsoft Office
Apply
≈ $75k – $141k per year (Estimated) • In office • 6+ years exp • Master's Degree • Toronto
Apply
See all jobs
This is one of many
1,097,669 more open roles from verified company boards, updated every day.