FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Application Security Engineer
Savvy WealthSenior Application Security Engineer at AI-driven wealth management firm. Addressing vulnerabilities and enhancing security for AI-assisted development processes.
Posted 7/21/2026full-timeNew York City • New York • 🇺🇸 United StatesSenior💰 $220,000 - $235,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in vulnerability management, application security, and SaaS security, with a strong focus on integrating security practices into engineering workflows. Proficient in cloud security across AWS and GCP, and skilled in leveraging modern AppSec tools to enhance security hygiene and risk management.
Highest-signal resume keywords
Vulnerability ManagementApplication SecuritySaaS SecurityCloud Security (AWS, GCP)AppSec Toolchain (SAST, SCA, Secrets Scanning)
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Vulnerability ManagementApplication SecuritySaaS SecurityCloud SecuritySecrets ScanningSCA/Dependency ScanningSASTConfiguration HardeningOAuth ReviewCI/CD Security Integration
Soft Skills
Excellent Communication SkillsIndependent WorkFast-Paced AdaptabilityStrong Writing Skills
Tools & Technologies
AWSGCPCloudflareGitHubGoogle WorkspaceRipplingSlack
Industry Keywords
Risk-Based MindsetAI-Assisted Development SecuritySecurity Hygiene StandardsIncident ResponseCross-Functional Collaboration
Tech Stack
Tools & technologiesAWSCloudGoogle Cloud Platform
About the role
Key responsibilities & impact- Own vulnerability management end to end: identify, triage, prioritize by real-world risk, and drive remediation to closure across our product, codebases, and cloud infrastructure (AWS, GCP, Cloudflare)
- Build and operate our AppSec tooling pipeline: secrets scanning in CI and at the git layer, SCA/dependency scanning with triage SLAs, and SAST rollout on our most sensitive repos, tuned for signal over noise
- Set and enforce security hygiene standards within our codebases, including code review standards that explicitly account for AI-generated code (authorship transparency, mandatory human review on security-sensitive paths)
- Partner with our internal AI team to design guardrails that keep AI-assisted development, including vibe coding by non-technical builders, safe by default: sanctioned tooling, data handling boundaries, dependency vetting, and secure defaults for AI-built integrations
- Secure the SaaS stack: harden configurations, review OAuth grants and third-party integrations, reduce misconfiguration risk across platforms like Google Workspace, GitHub, Rippling, and Slack
- Help establish conditional access and identity-layer controls in partnership with IT (SSO, phishing-resistant MFA, managed-device posture)
- Define cloud and SaaS configuration baselines for the infrastructure footprint we operate
- Contribute to detection and response readiness: high-signal detections (new OAuth grants, mass code-host downloads, credential anomalies) and participate in incident response when needed
- Work cross-functionally with Engineering, IT, and the internal AI team; clearly articulate risk, remediation paths, and tradeoffs to both technical and non-technical stakeholders
Requirements
What you’ll need- 5+ years of hands-on security engineering experience, with significant time in application security or product security
- Strong software engineering fundamentals; comfortable reading, writing, and remediating code, not just filing findings
- Deep experience with the modern AppSec toolchain: secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration (GitHub-centric)
- Practical experience securing SaaS environments: OAuth and third-party app review, configuration hardening, and least-privilege access design
- Working knowledge of cloud security across AWS and/or GCP, and edge/CDN security (Cloudflare)
- A pragmatic, risk-based mindset: you prioritize by what actually gets exploited, ship iteratively, and avoid drowning teams in noise
- Strong perspective on AI-assisted development security: you understand how AI coding tools change the shape of AppSec risk (hallucinated dependencies, leaked secrets, insecure patterns at scale) and how to build guardrails without killing velocity
- Track record of partnering with engineering teams as an enabler, embedding security into existing workflows rather than bolting it on
- Excellent communication skills and ability to work independently in a fast-paced environment
- Strong writing skills; Savvy is a written culture.
Benefits
Comp & perks- Competitive salary and equity package
- Unlimited PTO + paid company holidays
- Access to holistic medical, dental, and vision plans
- Company 401(k), Commuter, and HSA/FSA plans
- NYC office in the heart of Manhattan
- Lunch and snacks provided in the office
- Access to virtual mental health care (Spring Health), vision related benefits (XP Health), and health concierge (Rightway) to help you find the right care
- Access to counseling for stress management, dependent care, nutrition, fitness, legal, and financial issues (Guardian WorkLifeMatters EAP)