Senior Application Security Engineer
Job description
About the role
We are seeking a Senior Application Security Engineer to join Savvy, where you will play a pivotal role in safeguarding our innovative AI-driven wealth management platform. This position is hands-on and involves identifying and addressing vulnerabilities within our products and internal tools. You will be responsible for implementing robust security strategies that ensure our fast-paced AI-enhanced development processes remain secure and efficient.
Key facts
What you'll do
- Oversee the entire lifecycle of vulnerability management, from detection to resolution, across our product offerings, codebases, and cloud infrastructure, including AWS, GCP, and Cloudflare.
- Design and manage our Application Security tooling pipeline, which encompasses secrets scanning, Software Composition Analysis (SCA), and Static Application Security Testing (SAST).
- Set and uphold security standards across our codebases, particularly in relation to code generated by AI.
- Collaborate closely with our internal AI development team to establish secure frameworks for AI-assisted programming.
- Strengthen the security posture of our SaaS applications by refining configurations and assessing third-party integrations for potential risks.
- Partner with the IT department to implement conditional access and identity management controls.
- Define and document baseline security configurations for our cloud and SaaS environments to ensure compliance and security.
- Contribute to our incident response readiness by developing high-signal alerts and enhancing our detection capabilities.
- Work in conjunction with Engineering, IT, and the AI team, effectively communicating security risks and proposing actionable solutions.
Requirements
- A minimum of 5 years of practical experience in security engineering, with a strong emphasis on application or product security.
- Proficient software engineering skills, with the ability to read, write, and debug code effectively.
- Extensive familiarity with contemporary Application Security tools, including secrets scanning, SCA, SAST, and security within CI/CD pipelines, particularly in GitHub environments.
- Hands-on experience securing SaaS platforms, including a solid understanding of OAuth review processes and configuration hardening.
- Knowledge of cloud security principles, particularly within AWS and/or GCP, as well as edge and CDN security practices, such as those offered by Cloudflare.
- A risk-based mindset towards security, focusing on real-world exploits and iterative improvements.
- Strong grasp of security risks associated with AI-assisted development and the ability to implement effective protective measures.
- Proven capability to integrate security practices into engineering workflows, enhancing overall productivity.
- Excellent verbal and written communication skills, with the ability to work autonomously in a dynamic environment.
- Strong writing skills are essential, as we maintain a culture that values clear documentation and communication.
Nice to have
- Experience in establishing security programs within early to mid-stage companies.
- Familiarity with SaaS security posture management, Cloud Security Posture Management (CSPM), or identity threat detection.
- Knowledge of securing large language model (LLM)-based tools, agentic workflows, or internal AI systems.
- Experience in detection engineering, including SIEM/MDR and high-signal alerting methodologies.
- A background in the Fintech sector or financial services is a plus.
- Offensive security experience, such as penetration testing, bug bounty programs, or red teaming, to inform and enhance defensive strategies.
Skills & tools
- AWS
- GCP
- Cloudflare
- GitHub
- Google Workspace
- Rippling
- Slack
- Claude
Practical notes
This is a full-time hybrid position based in our NYC office. We offer a competitive salary along with equity options, unlimited paid time off, and comprehensive health benefits including medical, dental, and vision coverage. Additionally, we provide a 401(k) plan, commuter benefits, Health Savings Accounts (HSA)/Flexible Spending Accounts (FSA), and in-office meals. Employees also have access to mental health support and Employee Assistance Programs (EAP) to ensure well-being and work-life balance.
About the company
WEALTH: Wealth management is a $545 billion industry in the US, yet remains archaic and inefficient with low technology penetration. 75% of financial advisors don't offer digital communication beyond email, and 62% still build financial plans manually in Excel.