123 application security engineer jobs at 83 companies in New York
🚀PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yrOn-SiteFull Time
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
Tatari: A platform for buying and measuring TV advertising campaigns.
Production Python experience, significant hands-on application security experience, threat modeling, building security tooling/automation, familiarity with AWS and Kubernetes, and SAST/DAST/SCA/CI-CD integration.
Python, Java, Rust, AWS, Kubernetes, OWASP Top 10, API Security Top 10, ASVS, SPVS, AISVS, SAST, DAST, SCA, CI/CD
Chicago or California or Colorado or Florida or Georgia or Illinois or Indiana or Minnesota or Missouri or Montana or New Jersey or New York or North Carolina or Ohio or Oregon or Pennsylvania or South Carolina or Texas or Utah or Vermont or Virginia or Washington or Washington or Wisconsin
$210k-$260k/yrHybridFull Time
NinjaTrader: Provides futures brokerage services and a trading software platform.
7+ YOE7+ years in application/product/security engineering; hands-on threat modeling, vulnerability management, secure design, CI/CD integration, automation using Python/Go; experience with cloud-native AWS/GCP environments.
United States or Canada or San Francisco or New York City or Seattle
$190k-$273k/yrRemoteFull Time
Apollo.io: AI-powered platform for B2B sales intelligence and outreach automation.
5+ YOE5+ years software engineering or application security experience; strong coding skills (Ruby, Python), Linux and GCP familiarity, deep AppSec/vulnerability management, pen-testing and SAST experience, AI security, and strong communication.
GeminiNasdaq: GEMI: Regulated platform for trading and storing digital assets.
7+ YOEExpertise in threat modeling, secure design/code review, penetration testing, application security controls, familiarity with regulated environments, strong communication, and experience building AI security tooling.
Apollo Global ManagementNYSE: APO: Global alternative asset manager providing investment and retirement solutions.
10+ YOE10+ years in application security; strong software development background; experience with SCA/SAST/DAST, secure SDLC; familiarity with cloud, leading security standards; CISSP/CSSLP etc preferred.
Anthropic: Developing safe and reliable artificial intelligence systems.
Hands-on application and infrastructure security experience, production-quality coding in Python/Go/Rust/TypeScript, threat-modeling, vulnerability ID, clear communication, and ability to assess unfamiliar codebases under time pressure.
Seattle or Los Angeles or San Francisco or California or Colorado or Connecticut or Delaware or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or Nevada or New Jersey or New York or Rhode Island or Virginia or Washington or Washington DC or United States
$141k-$259k/yrOnsiteFull Time
Nordstrom: Operates luxury department stores and off-price retail outlets.
4+ YOE4+ years in application security or related field; experience shipping security tooling and automation; expert threat modeling, security design review, and manual code review; fluent reading/writing code in Java, Kotlin, C#, or Python; cloud-native and LLM/AI security knowledge.
Mercor: Connecting expert human intelligence with frontier AI model development.
5+ YOEFive+ years of professional experience in application security or security engineering; strong web security knowledge; proficient in at least one of Python, TypeScript, or Go; experience with SAST/DAST tooling and vulnerability management.
Research Triangle Park or San Jose or New York City or New York or Washington or Canada
$167k-$211k/yrHybridFull Time
CiscoNASDAQ: CSCO: Develops and sells networking hardware and cybersecurity software.
1+ YOEAdvanced AI research experience applied to networking/security or related computer science areas; ability to design and run experiments, build and evaluate models, and communicate research to cross-functional teams.
Writer: Platform for building and deploying enterprise generative AI agents.
4+ YOE4+ years in application security; strong coding in Python/Java/Go/JavaScript/TypeScript; SAST/DAST in CI/CD; threat modeling; secure SDLC; security reviews; automation.
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
2+ YOE2+ years IT security experience or bachelor's in computer science; knowledge of system vulnerabilities, penetration testing, web protocols, secure coding, identity management, and strong communication and troubleshooting skills.
Clear Street: Cloud-native capital markets platform for institutional trading and clearing.
7+ YOE7+ years in DevSecOps/application or cloud security, hands-on CI/CD and cloud experience, SAST/DAST/SCA tool use, container/Kubernetes security, scripting and IaC familiarity, strong communication.
DatadogNASDAQ: DDOG: Observability and security platform for cloud applications and infrastructure.
Software engineering background with hands-on code review; knowledge of OWASP Top 10, SAST/DAST, API security; able to mentor engineers and define secure-by-default solutions.
Go, Python, Rust, OWASP, SAST, DAST, API security, APM, CI/CD
RobinhoodNASDAQ: HOOD: Provides a commission-free platform for investing and financial services.
5+ YOE5+ years in application security or related field; experience with secure SDLC and threat modeling; production-grade Python/Go experience; collaboration with engineers; reliability and incident response focus.
Boston or Carmel or Chicago or Lambertville or New York City or San Francisco or United States
$60k-$80k/yrHybridFull Time
Real Chemistry: Provides marketing and communication services for healthcare companies.
5+ YOE5+ years cloud security experience (3+ in high-growth acceptable), including 2 years focused on application security; hands-on with AWS IAM, SAML/OIDC, GitHub security tooling, threat modeling, penetration testing, and familiarity with SOC 2/GDPR/HIPAA-adjacent controls.