Senior Application Security Engineer (Adtech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Application Security Engineer (Adtech): Driving secure software development and application security maturity for high-scale advertising platforms with an accent on automated security testing, CI/CD integration, and vulnerability management. Focus on building a global compliance program based on NIST CSF, conducting penetration tests, and mitigating application-layer threats in AWS cloud-native environments.
Location: London, UK or New York, US
Salary: $125,000 - $165,000 USD
Company
is an advertising platform helping publishers and platforms monetize through programmatic ad transactions using smart targeting and premium creative formats.
What you will do
- Build and maintain a global security compliance program based on NIST CSF.
- Scale application security by developing automated testing utilizing enterprise SAST, DAST, and GHAS.
- Integrate security scanning into CI/CD pipelines to detect vulnerabilities early in the SDLC.
- Conduct internal penetration testing and vulnerability assessments of applications and infrastructure.
- Perform threat modeling and review design/architecture specs to mitigate security risks.
- Collaborate with engineering teams to implement robust authentication, authorization, and data protection.
Requirements
- 5+ years of experience in application security, secure software development, or security engineering.
- Proficiency with GitHub Advanced Security (GHAS) and SAST/DAST/SCA tools like CodeQL, Burp Suite, or Snyk.
- Hands-on experience with penetration testing across web applications, APIs, and cloud infrastructure.
- Deep knowledge of OWASP Top 10 and AWS security services (IAM, VPC, KMS, GuardDuty).
- Experience with cybersecurity frameworks such as NIST CSF, SOC2, or ISO 27001.
- Ability to perform security code reviews in Python, Java, TypeScript, or Go.
Nice to have
- Experience in the ad-tech industry or high-scale real-time environments.
- Familiarity with AI/LLM-based tools for threat intelligence and security automation.
- Relevant cybersecurity certifications such as OSCP, GWAPT, or CISSP.
Culture & Benefits
- Comprehensive medical, dental, and vision plans.
- Flexible Paid Time Off (PTO) policy.
- 401k plan with employer match.
- Collaborative, innovative, and compassionate team environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →