See all jobs on JobTailor
Search thousands of fresh jobs every day.
- Fresh listings
- Fast filters
- No subscription required

Staff Application Security Engineer
NBCUniversalStaff Application Security Engineer building AppSec automation, secure developer workflows, and AI guardrails for NBCUniversal’s media and streaming businesses. Scaling vulnerability management and software supply chain security across the enterprise.
Core Competencies
Role fitUse this summary to align your resume positioning with the role.
Demonstrates extensive expertise in Application Security, Secure Software Development, and Vulnerability Management, with a strong focus on building security automations and integrations. Proficient in leveraging AI and automation to enhance developer workflows and security practices across cloud-native applications and software supply chains.
ATS Keywords
Tailor your resumeTip: use these terms in your resume and cover letter to boost ATS matches.
Tech Stack
Tools & technologiesAbout the role
Key responsibilities & impact- Design, build, and improve application security capabilities supporting secure software development across NBCUniversal
- Build reusable security automations, integrations, APIs, workflows, and developer tools
- Implement secure-by-default golden paths, paved roads, and engineering patterns
- Design and implement scalable security solutions across source code, open source dependencies, containers, cloud-native applications, CI/CD pipelines, infrastructure as code, developer platforms, and software supply chains
- Partner with Cloud Security on application and cloud security capabilities
- Improve vulnerability prioritization, triage, remediation, validation, reporting, and speed to remediation
- Build security patterns and guardrails for AI-assisted development tools, coding assistants, and agentic workflows
- Use automation and AI-enabled techniques to improve vulnerability triage, remediation planning, developer guidance, and workflow efficiency
- Build integrations between application security platforms, GitHub, CI/CD systems, developer portals, ticketing systems, reporting platforms, and other engineering tools
- Create telemetry, dashboards, and reporting pipelines for application risk, coverage, and remediation progress
- Serve as a senior technical expert in application security engineering, secure software development, software supply chain security, and secure AI development
- Partner with architects, platform engineers, cloud security engineers, and development teams to implement technical solutions
- Mentor engineers and improve engineering practices, automation skills, and technical depth
Requirements
What you’ll need- 8+ years of experience in Application Security, Security Engineering, DevSecOps, Software Engineering, or a related technical field
- Deep experience with secure software development, application security, vulnerability management, and software supply chain security
- Hands-on experience building security automations, integrations, APIs, platforms, developer tooling, or similar engineering solutions
- Strong software engineering and scripting skills using Python or similar languages
- Hands-on experience integrating SAST, SCA, secrets detection, container security, CI/CD security, and vulnerability management into developer workflows
- Ability to solve complex, ambiguous technical problems and influence adoption through implementation, documentation, and collaboration
- Familiarity with AI-assisted development, agentic workflows, and related security considerations
- Experience with Snyk, Wiz Code, GitHub Advanced Security, Checkmarx, Veracode, or similar application security platforms
- Experience building secure developer platforms, internal tools, paved roads, golden paths, or reusable engineering services
- Experience across AppSec and CloudSec domains, including cloud-native architectures, containers, Kubernetes, infrastructure as code, CI/CD security, CSPM, CNAPP, or related technologies
- Experience with software supply chain security, SBOM capabilities, dependency risk workflows, or artifact security processes
- Experience using AI to improve vulnerability management, remediation workflows, security operations, or developer productivity
Benefits
Comp & perks- Company sponsored medical insurance
- Dental insurance
- Vision insurance
- 401(k)
- Paid leave
- Tuition reimbursement
- A variety of other discounts and perks
- Bonus eligible