Senior Application Security Engineer
Job description
About the role
TripleLift is seeking a Senior Application Security Engineer to safeguard the integrity of our advertising technology stack and infrastructure. In this role, you will act as the primary technical authority on application security, working within the engineering organization to identify vulnerabilities and implement robust defenses across our programmatic platforms. You will own the design and execution of security initiatives that span the entire application lifecycle, ensuring security controls align with business objectives while keeping pace with rapid development cycles. This position demands a proactive mindset to anticipate emerging threats and mitigate risks before they impact production systems.
Location: UK
Engagement: Full-time
What you'll do
- Execute comprehensive security assessments of internal applications and multi-cloud environments to uncover hidden weaknesses and ensure resilience against sophisticated malicious actors.
- Collaborate with software engineers to embed security best practices directly into the software development lifecycle from inception, integrating security as a foundational component of engineering workflows.
- Lead structured threat modeling sessions for new product features to identify attack vectors, evaluate risks, and design effective mitigations early in the development process.
- Orchestrate the response to security incidents, coordinating with engineering teams to perform thorough root cause analysis and implementing measures to prevent recurrence.
- Oversee vulnerability scanning programs and drive remediation efforts across the organization to reduce the overall risk posture and maintain a strong security position.
- Design and implement security controls that protect advertising technology systems, ensuring the integrity, confidentiality, and availability of critical platforms and data.
- Evaluate third-party integrations and dependencies for security risks, assessing potential impacts on the integrity and reliability of our platforms.
- Develop security metrics and reporting to provide leadership with clear visibility into risk exposure, remediation progress, and the effectiveness of security initiatives.
- Partner with operations teams to ensure that security configurations are consistently applied across all environments, maintaining compliance and reducing misconfigurations.
- Champion the adoption of secure coding standards and automated security testing within engineering teams, fostering a culture of security awareness and continuous improvement.
Requirements
- Demonstrate professional experience in application security or a similar engineering role with a proven track record of securing complex software systems and delivering measurable security outcomes.
- Show proficiency in identifying and mitigating common web vulnerabilities, including but not limited to injection attacks, cross-site scripting (XSS), and broken authentication mechanisms.
- Prove ability to write secure code and conduct thorough reviews of existing codebases to uncover security flaws, logic vulnerabilities, and potential exploitation paths.
- Establish hands-on experience with cloud infrastructure security, including identity and access management, network segmentation, data protection, and encryption strategies.
- Exhibit strong communication skills to translate technical security concepts into clear, actionable guidance for non-security engineering teams, enabling effective collaboration and implementation.
- Display understanding of secure software development lifecycle (SDLC) principles and the ability to integrate security activities seamlessly into each phase of software delivery, from planning through deployment and maintenance.
- Provide evidence of experience with web application security testing methodologies, including manual and automated testing approaches, using tools and frameworks to assess application resilience.
- Apply knowledge of cloud security principles to design resilient architectures that meet industry standards and best practices, ensuring security is built into the foundation of system designs.
Nice to have
- Experience with threat modeling frameworks and the ability to operationalize findings into actionable security tasks, ensuring risks are addressed systematically and efficiently.
- Familiarity with vulnerability management tools and workflows used to track, prioritize, and remediate security findings at scale across distributed systems.
- Knowledge of advertising technology ecosystems and the unique security challenges inherent in digital advertising, including fraud prevention, data privacy, and supply chain risks.
- Engagement with open source security tools and contributions to security-focused communities, demonstrating a commitment to improving the broader security landscape.
- Understanding of regulatory frameworks that impact digital advertising and data protection requirements, ensuring compliance and mitigating legal risks.
Practical notes
This is a full-time position with roles based in London, England, United Kingdom, and New York, New York, United States. The successful candidate will work closely with cross-functional teams to drive security initiatives and ensure the continued protection of TripleLift's platforms and customers.