Lead Application Security Engineer
Job description
About the role
Zeta Global is seeking a Lead Application Security Engineer to strengthen its security infrastructure across applications and platforms by implementing advanced security methodologies and automation techniques. This position will play a crucial role in embedding security throughout the software development lifecycle, leveraging AI-driven tools and automated processes to ensure that security considerations are integral to our systems from the outset.
Key facts
What you'll do
- Employ AI-enhanced threat modeling techniques to identify potential security vulnerabilities in applications, platforms, APIs, and data at the earliest stages of development.
- Deploy automated security review tools to scrutinize architecture, design documents, code changes, APIs, and data flows for any security weaknesses.
- Perform AI-assisted security evaluations of code using a variety of testing methodologies, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Infrastructure as Code (IaC) scanning.
- Assess third-party libraries and APIs for compliance with security standards and evaluate supply-chain risks through automated processes.
- Engage in red team and blue team simulations to test and improve incident response capabilities.
- Work closely with development and quality assurance teams to incorporate security testing into Continuous Integration/Continuous Deployment (CI/CD) pipelines.
- Create security automation tools that provide real-time feedback to developers throughout all phases of the development lifecycle.
- Analyze architectural designs with AI tools to uncover risks and propose secure implementation strategies.
- Develop scalable security controls and policy-as-code features tailored for application and platform teams.
- Keep abreast of emerging security threats by utilizing AI-driven intelligence and analyzing attack patterns.
- Design and execute proactive defense strategies for applications and data platforms.
- Examine recurring vulnerabilities to enhance threat models and refine security practices.
- Promote secure coding practices by providing guidance, creating playbooks, and developing developer documentation.
- Contribute to the formulation of internal security standards and AI-native security resources.
- Cultivate a culture of security and automation within the organization, collaborating with various teams to bolster security measures.
- Evaluate the effectiveness of security controls and monitor trends in remediation efforts and developer engagement.
Requirements
- A Bachelor's degree in Computer Science, Cybersecurity, or a related discipline, or equivalent professional experience.
- A minimum of 5 years of experience in Application Security, DevSecOps, or related fields.
- Comprehensive understanding of the OWASP Top 10 and principles of secure design.
- Knowledge of AI/ML security challenges, including issues like prompt injection and data poisoning.
- Proven experience in creating AI-assisted security workflows or automated systems for risk evaluation.
- Proficiency in contemporary application frameworks such as React, Node.js, or Django.
- Familiarity with API security, microservices architecture, and authentication protocols like OAuth2.
- Experience with cloud platforms such as AWS, GCP, or Azure, as well as container technologies like Docker and Kubernetes.
- Knowledge of security testing tools, including Semgrep, SonarQube, and OWASP ZAP.
- Strong analytical abilities to interpret security findings and offer actionable recommendations.
- Exceptional communication and collaboration skills across various teams and departments.
Nice to have
- Experience with policy-as-code and automation in infrastructure security.
- Familiarity with scripting languages for security testing and vulnerability management.
- Relevant industry certifications such as OSCP, GWAPT, or cloud security credentials.
Practical notes
The salary for this role ranges from $140,000 to $180,000, contingent on experience and geographical location. We provide unlimited paid time off, comprehensive health benefits, employee equity options, and a variety of wellness initiatives. Zeta Global is dedicated to creating a diverse and inclusive work environment and encourages candidates from all backgrounds to apply.
About the company
 Zeta Global (NYSE: ZETA) is the AI-Powered Marketing Cloud that leverages advanced artificial intelligence (AI) and trillions of consumer signals to make it easier for marketers to acquire, grow, and retain customers more efficiently. Through the Zeta Marketing Platform (ZMP), our vision is to make sophisticated marketing simple by unifying identity, intelligence, and omnichannel activation into a single platform â powered by one of the industryâs largest proprietary databases and AI.