Senior Application Security Engineer
Savvy Wealth · New York, NY · Yesterday
HybridInformation Technology$220k–$235k/yrFull-time
Responsibilities
- Own vulnerability management end to end: identify, triage, prioritize by real-world risk, and drive remediation to closure across our product, codebases, and cloud infrastructure (AWS, GCP, Cloudflare)
- Build and operate our AppSec tooling pipeline: secrets scanning in CI and at the git layer, SCA/dependency scanning with triage SLAs, and SAST rollout on our most sensitive repos, tuned for signal over noise
- Set and enforce security hygiene standards within our codebases, including code review standards that explicitly account for AI-generated code (authorship transparency, mandatory human review on security-sensitive paths)
- Partner with our internal AI team to design guardrails that keep AI-assisted development, including vibe coding by non-technical builders, safe by default: sanctioned tooling, data handling boundaries, dependency vetting, and secure defaults for AI-built integrations
- Secure the SaaS stack: harden configurations, review OAuth grants and third-party integrations, reduce misconfiguration risk across platforms like Google Workspace, GitHub, Rippling, and Slack
- Define cloud and SaaS configuration baselines for the infrastructure footprint we operate
- Contribute to detection and response readiness: high-signal detections (new OAuth grants, mass code-host downloads, credential anomalies) and participate in incident response when needed
- Work cross-functionally with Engineering, IT, and the internal AI team; clearly articulate risk, remediation paths, and tradeoffs to both technical and non-technical stakeholders
Requirements
- 5+ years of hands-on security engineering experience, with significant time in application security or product security
- Strong software engineering fundamentals; comfortable reading, writing, and remediating code, not just filing findings
- Deep experience with the modern AppSec toolchain: secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration (GitHub-centric)
- Practical experience securing SaaS environments: OAuth and third-party app review, configuration hardening, and least-privilege access design
- Working knowledge of cloud security across AWS and/or GCP, and edge/CDN security (Cloudflare)
- A pragmatic, risk-based mindset: you prioritize by what actually gets exploited, ship iteratively, and avoid drowning teams in noise
- A strong perspective on AI-assisted development security: you understand how AI coding tools change the shape of AppSec risk (hallucinated dependencies, leaked secrets, insecure patterns at scale) and how to build guardrails without killing velocity
- A track record of partnering with engineering teams as an enabler, embedding security into existing workflows rather than bolting it on
- Excellent communication skills and ability to work independently in a fast-paced environment
- Strong writing skills; Savvy is a written culture
Qualifications
- Experience building security programs at an early-to-mid stage company, taking a function from reactive to systematic
- Experience with SaaS security posture management, CSPM, or identity threat detection
- Familiarity with securing LLM-based tooling, agentic workflows, or internal AI platforms
- Detection engineering experience (SIEM/MDR, high-signal alerting)
- Fintech or financial services environment experience
- Offensive security background (pentesting, bug bounty, red team) that informs how you defend