Clear Street
Posted 3w ago

Application Security Engineer / Architect (DevSecOps)

Clear Street
New York City, New York, United States
$175k-$210k/yrHybridFull Time
Responsibilities
  • maintaining pipelines
  • remediating vulnerabilities
  • leading cloudsecurity
Requirements
  • 7+ years in DevSecOps/application or cloud security
  • Hands-on CI/CD and cloud experience
  • SAST/DAST/SCA tool use
  • Container/Kubernetes security
  • Scripting and IaC familiarity
  • Strong communication
Technical tools mentioned
GitHub ActionsGitLab CIJenkinsAWSAzureGCPSemgrepSnykCheckmarxVeracodeKubernetesPythonBashTerraformCloudFormationPulumiOPA/RegoCheckovOWASP Top 10CWE

Job description

About Clear Street:

Clear Street’s mission is to give every sophisticated investor access to every asset, in every market, through a unified platform built for speed, transparency and scale.

We give our clients the technology, tools, and service once reserved for the largest institutions, rebuilt with modern infrastructure. Our single, cloud-native, end-to-end capital markets platform powers investor growth today and is transforming how they can interact with markets tomorrow.

For more information, visit https://clearstreet.io.

The Team:

As an application security engineer in the Security team, you’ll have the opportunity to problem solve, build and influence the security posture of our products and services across the product ecosystem. 

In this role specifically, you’ll be responsible for leading application security efforts with our engineers as part of the product development lifecycle at source code and cloud levels within DevSecOps, Vulnerability and other arenas. 

Key Responsibilities:

●     Own security controls within CI/CD pipelines (SAST, DAST, SCA, secrets detection) and maintain pipeline-as-code tooling.
●     Work with engineers to identify and remediate vulnerabilities in application source code.
●     Manage the vulnerability lifecycle: triage findings from scanners, prioritize by risk, track remediation, and report on trends.
●     Lead cloud security efforts, work with engineering teams to enforce cloud security best practices (IAM, network controls, storage security, workload protection).
●     Maintain and tune security tooling including SAST/DAST scanners, container security platforms, and dependency analysis tools.
●     Build automation and AI based tools to scale Devsecops operations.
●     Partner with Infra Engineering teams to define secure infrastructure-as-code (IaC) standards and enforce them via policy-as-code.
●     Participate in threat modeling sessions and security design reviews for new features and services.
●     Support incident response activities related to application and cloud security events.
●     Contribute to security documentation, runbooks, and developer-facing guidance.

Required Qualifications
●     7+ years of experience in a DevSecOps, application security, or cloud security engineering role.
●     Hands-on experience with CI/CD platforms (GitHub Actions, GitLab CI, Jenkins, or similar).
●     Proficiency with at least one major cloud provider (AWS, Azure, or GCP) and its native security services.
●     Experience with SAST/SCA tools (e.g., Semgrep, Snyk, Checkmarx, Veracode) and interpreting findings.
●     Working knowledge of container and Kubernetes security (image scanning, RBAC, network policies, admission control).
●     Scripting skills in Python, Bash, or similar for automation and tooling.
●     Familiarity with IaC tools (Terraform, CloudFormation, Pulumi) and policy frameworks (OPA/Rego, Checkov).
●     Understanding of OWASP Top 10, CWE, and common vulnerability classes.
●     Strong communication skills — able to explain security risk clearly to non-security audiences.

Your impact won't be measured by the number of servers you manage—it will be measured by how much faster and happier our engineers become.

The Base Salary Range is $175,000 - $210,000. These ranges are representative of the starting base salaries for this role at Clear Street. Which range a candidate fits into and where a candidate falls in the range will be based on job related factors such as relevant experience, skills, and location. These ranges represent Base Salary only, which is just one element of Clear Street's total compensation. The ranges stated do not include other factors of total compensation such as bonuses or equity.

At Clear Street, we offer competitive compensation packages, company equity, 401k matching, gender neutral parental leave, and full medical, dental and vision insurance. Our belief has always been that we are better as a business when we are all together in person. We are requiring employees to be in the office 4 days per week. In-office benefits include lunch stipends, fully stocked kitchens, happy hours, a great location, and amazing views.

Our top priority is our people. We’re continuously investing in a culture that promotes collaboration. We help each other through challenges and celebrate each other's successes. We believe that modern workplaces succeed by virtue of having high-performance workforces that are diverse — in ideas, in cultures, and in experiences. We put in the effort to make such a workplace a daily reality and are proud to be an equal opportunity employer.

#LI-Hybrid

About Clear Street

Cloud-native capital markets platform for institutional trading and clearing.

Year founded
2018
Employees
789
Organization type
Private
Latest investment
Raised $135.40M Series C (2026) — led by Baillie Gifford, SBI Holdings
Headquarters
US

Similar jobs

Application Security Engineer roles near New York City, New York
1d
Save
Mark Applied
Hide
Staff/Lead Application Security Engineer
San Francisco or New York or Toronto
OnsiteFull Time
SnailWorks
SnailWorks: SnailWorks provides mail tracking and delivery intelligence software for marketers.
Expert web/API security, identity and access design, applied cryptography, cloud and container security; production coding experience and a record of driving security work across engineering organizations.
AI, SAST, DAST, SCA, CI/CD, RBAC, ABAC
2d
Save
Mark Applied
Hide
Confluent - Staff Security Engineer
Poughkeepsie or Lowell or Rochester or Tucson or Research Triangle Park or Armonk or Boston or Bellevue or Atlanta or San Jose or Dallas or Austin or San Francisco or Seattle
$161k-$299k/yr RemoteFull Time
IBM
IBMNew York Stock Exchange: IBM: Global technology providing enterprise software, cloud, and consulting.
10+ YOERequires a bachelor's degree and 10+ years of application security experience, with expertise in secure architecture, cloud-native platforms, security automation, CI/CD, and Go, Python, or Java.
Go, Python, Java, CI/CD, AI, LLMs
6d
Save
Mark Applied
Hide
Staff Application Security Engineer
New York City, New York, United States
$120k-$145k/yr RemoteFull Time
NBCUniversal
NBCUniversalNASDAQ: CMCSA: Produces and distributes entertainment content and theme park experiences.
8+ YOE8+ years in application security, security engineering, DevSecOps, or software engineering; secure development, vulnerability management, automation, APIs, integrations, and Python required.
Python, GitHub, Snyk, Wiz Code, GitHub Advanced Security, Checkmarx, Veracode, Kubernetes, CI/CD, SAST, SCA, CSPM, CNAPP, SBOM
1w
Save
Mark Applied
Hide
Senior Application Security Engineer
Toronto or London or New York City or Pune
OnsiteFull Time
TripleLift
TripleLift: Programmatic advertising platform for high-quality digital ad experiences.
5+ YOERequires 5+ years in application security or security engineering, secure coding, SAST/DAST/SCA, CI/CD security, penetration testing, threat modeling, AWS security, and cybersecurity frameworks.
GitHub Advanced Security, SAST, DAST, SCA, CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode, CI/CD, Python, Java, TypeScript, Go, NIST CSF, PCI, SOC2, HITRUST, ISO 27001/2, AWS, IAM, VPC, KMS, GuardDuty, CloudTrail, Claude
1w
Save
Mark Applied
Hide
Staff Application Security Engineer – Threat Research
New York City, New York, United States
$107k-$284k/yr HybridFull Time
CVS Health
CVS HealthNYSE: CVS: Provides retail pharmacy, health insurance, and pharmacy benefit management services.
7+ YOERequires 7+ years in application or information security, 5+ years programming, 3+ years cloud and container security, infrastructure or security as code, assessments, vulnerability analysis, and threat modeling.
Java, Python, JavaScript, C#, C/C++, PowerShell, Shell, AWS, Microsoft Azure, Google Cloud Platform, Docker, Kubernetes, Snowflake, Web Application Firewall, API
1w
Save
Mark Applied
Hide
Sr. Application Security Engineer
Fort Mill or Charlotte or New York City or San Diego or Austin or Tempe
$101k-$168k/yr HybridFull Time
LPL Financial
LPL FinancialNASDAQ: LPLA: Provides wealth management and brokerage services to financial advisors.
5+ YOERequires 5+ years of application security experience, manual API and web testing, vulnerability analysis, security libraries, scanning tools, risk evaluation, secure SDLC, DevSecOps, and CI/CD expertise.
Synopsys, BlackDuck, J-Frog, PrismaCloud, Burpsuite, Postman, C#, Java, HTML, CSS, JS, React, Angular, REST, DevSecOps, CI/CD
1w
Save
Mark Applied
Hide
Sr. Application Security Engineer
Fort Mill or Charlotte or New York City or San Diego or Austin or Tempe
$101k-$168k/yr HybridFull Time
LPL Financial
LPL FinancialNASDAQ: LPLA: Provides independent financial advisory and wealth management services.
5+ YOERequires 5+ years of application security experience, manual API and web testing, vulnerability analysis, security libraries, scanning tools, risk evaluation, secure SDLC, DevSecOps, and strong communication skills.
Synopsys, Black Duck, JFrog, Prisma Cloud, Burp Suite, Postman, C#, Java, HTML, CSS, JavaScript, React, Angular, REST, CI/CD, OWASP Top 10, IAST
2w
Save
Mark Applied
Hide
Senior / Staff Application Security Engineer
Boston or New York City or Los Angeles or San Francisco
$230k-$330k/yr OnsiteFull Time
Suno
Suno: AI platform for creating full songs from text prompts.
6+ YOE6+ years in security engineering with hands-on application security, secure SDLC tooling, AWS experience, ability to write production code and threat-model AI/LLM surfaces.
AWS, SAST, DAST