Jobs · Information Technology · New York

Senior Application Security Engineer

Savvy Wealth · New York, NY · Yesterday
HybridInformation Technology$220k–$235k/yrFull-time

Responsibilities

  • Own vulnerability management end to end: identify, triage, prioritize by real-world risk, and drive remediation to closure across our product, codebases, and cloud infrastructure (AWS, GCP, Cloudflare)
  • Build and operate our AppSec tooling pipeline: secrets scanning in CI and at the git layer, SCA/dependency scanning with triage SLAs, and SAST rollout on our most sensitive repos, tuned for signal over noise
  • Set and enforce security hygiene standards within our codebases, including code review standards that explicitly account for AI-generated code (authorship transparency, mandatory human review on security-sensitive paths)
  • Partner with our internal AI team to design guardrails that keep AI-assisted development, including vibe coding by non-technical builders, safe by default: sanctioned tooling, data handling boundaries, dependency vetting, and secure defaults for AI-built integrations
  • Secure the SaaS stack: harden configurations, review OAuth grants and third-party integrations, reduce misconfiguration risk across platforms like Google Workspace, GitHub, Rippling, and Slack
  • Define cloud and SaaS configuration baselines for the infrastructure footprint we operate
  • Contribute to detection and response readiness: high-signal detections (new OAuth grants, mass code-host downloads, credential anomalies) and participate in incident response when needed
  • Work cross-functionally with Engineering, IT, and the internal AI team; clearly articulate risk, remediation paths, and tradeoffs to both technical and non-technical stakeholders

Requirements

  • 5+ years of hands-on security engineering experience, with significant time in application security or product security
  • Strong software engineering fundamentals; comfortable reading, writing, and remediating code, not just filing findings
  • Deep experience with the modern AppSec toolchain: secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration (GitHub-centric)
  • Practical experience securing SaaS environments: OAuth and third-party app review, configuration hardening, and least-privilege access design
  • Working knowledge of cloud security across AWS and/or GCP, and edge/CDN security (Cloudflare)
  • A pragmatic, risk-based mindset: you prioritize by what actually gets exploited, ship iteratively, and avoid drowning teams in noise
  • A strong perspective on AI-assisted development security: you understand how AI coding tools change the shape of AppSec risk (hallucinated dependencies, leaked secrets, insecure patterns at scale) and how to build guardrails without killing velocity
  • A track record of partnering with engineering teams as an enabler, embedding security into existing workflows rather than bolting it on
  • Excellent communication skills and ability to work independently in a fast-paced environment
  • Strong writing skills; Savvy is a written culture

Qualifications

  • Experience building security programs at an early-to-mid stage company, taking a function from reactive to systematic
  • Experience with SaaS security posture management, CSPM, or identity threat detection
  • Familiarity with securing LLM-based tooling, agentic workflows, or internal AI platforms
  • Detection engineering experience (SIEM/MDR, high-signal alerting)
  • Fintech or financial services environment experience
  • Offensive security background (pentesting, bug bounty, red team) that informs how you defend

Similar jobs