Now hiring

Senior Application Security Engineer @ TripleLift

Upper Grosvenor Street 48, LondonOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Salary: £53,000 - 93,000 per year

Requirements: We require at least 5 years of experience in application security, secure software development, security engineering, or a similar role.We need strong understanding of secure coding practices and the ability to guide developers on remediation strategies.We require experience with GitHub Advanced Security (GHAS), including Code Scanning, Secret Scanning, and Dependency Review.We need proficiency with SAST, DAST, and SCA tools such as CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, or Veracode.We require hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows.We need hands-on penetration testing or offensive security experience across web applications, APIs, or cloud infrastructure.We require knowledge of common application security vulnerabilities and mitigations, including OWASP Top 10, CWE, business logic flaws, and API security.We need the ability to perform threat modeling and participate in design and architecture spec reviews to assess security risks in applications and services.We require experience conducting security code reviews across programming languages such as Python, Java, TypeScript, and Go.We need understanding of security fundamentals related to cybersecurity and compliance frameworks, particularly NIST CSF, and also PCI, SOC2, HITRUST, ISO 27001/2, or similar.We require strong understanding of AWS security services and controls, including IAM, VPC, KMS, GuardDuty, and CloudTrail, plus experience securing cloud-native environments and workloads.We need the ability to deploy security tools within cloud environments.We require ownership, independence, and the ability to deliver results in a fast-paced environment while balancing multiple priorities.We need a continuous learner who values correctness, efficiency, and constructive feedback.Preferred: experience in the ad-tech or programmatic advertising industry, or another high-scale, real-time environment.Preferred: familiarity with AI/LLM-based tools such as Claude or similar for threat intelligence, alert triage, or security automation.Preferred: a cybersecurity certification such as OSCP, GWAPT, CISSP, or CISA. Responsibilities: We play a critical role in building and maintaining a global security compliance program based on NIST CSF.We scale application security by developing automated security testing using enterprise SAST, DAST, and code-review tools.We champion SDLC practices to promote secure application development and infrastructure deployment, and we facilitate secure coding remediation activities.We automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations themselves.We administer and drive adoption of GitHub Advanced Security across engineering repositories.We participate in threat modeling and design and architecture spec reviews to identify and mitigate security risks early in the SDLC.We coordinate with stakeholders to develop and implement a vulnerability management program and perform threat-hunting activities.We own and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate findings from third-party pentest engagements.We monitor and respond to application-layer security threats such as API abuses, business logic flaws, and common web vulnerabilities.We collaborate with product and engineering teams to ensure security is a key consideration in software design and architecture.We enhance application security posture by helping implement proper authentication, authorization, and data protection mechanisms.We enhance and facilitate security incident handling activities.We evangelize security best practices and provide education and awareness to employees.We develop and implement secure coding guidelines and conduct secure development training for engineers.We evaluate and continuously improve the maturity of the security program through security tools and processes. Technologies: AIAPIAWSCI/CDCloudGitHubIAMJavaLLMOWASPPythonSecurityTypeScriptWebEmbedded More:

We are TripleLift, an advertising platform focused on elevating digital advertising through beautiful creative, quality publishers, actionable data, and smart targeting. Through over 1 trillion monthly ad transactions, we help publishers and platforms monetize their businesses, and our technology helps leading brands reach audiences across online video, connected television, display, and native ads. We are part of the Vista Equity Partners portfolio, NMSDC certified, qualified for diverse spending goals, and committed to economic inclusion. This Senior Application Security Engineer role sits within our Engineering and Security organization and offers the opportunity to help build and scale our application security program in a fast-moving ad-tech environment. We are a collaborative, compassionate team that values innovation, curiosity, and belonging, and we invest in people, culture, and community so everyone can thrive.

last updated 36 week of 2026

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores