TripleLift Logo

TripleLift

Senior Application Security Engineer

Posted Yesterday
Be an Early Applicant
Pune, Maharashtra
Senior level
Pune, Maharashtra
Senior level
The Senior Application Security Engineer will enhance security operations, develop security testing tools, manage vulnerabilities, and educate on secure coding practices.
The summary above was generated by AI

About TripleLift

We're TripleLift, an advertising platform on a mission to elevate digital advertising through beautiful creative, quality publishers, actionable data and smart targeting. Through over 1 trillion monthly ad transactions, we help publishers and platforms monetize their businesses. Our technology is where the world's leading brands find audiences across online video, connected television, display and native ads. Brand and enterprise customers choose us because of our innovative solutions, premium formats, and supportive experts dedicated to maximizing their performance.

As part of the Vista Equity Partners portfolio, we are NMSDC certified, qualify for diverse spending goals and are committed to economic inclusion. Find out how TripleLift raises up the programmatic ecosystem at triplelift.com.

The Role

TripleLift is seeking a Senior Application Security Engineer to join our team full-time. We are an established company in the advertising technology sector, trying to tackle some of the most challenging problems facing the industry. You will be joining a rapidly growing and complex environment and will work as part of a small team that will be responsible for developing, evangelizing, and executing our security roadmap. You’ll help drive improvements in our security operations capability and support critical projects, enhancing our detect-and-respond capabilities.


Responsibilities

  • Play a critical role in building and maintaining a global security compliance program based on NIST CSF.
  • Scale application security by developing automated security testing utilizing enterprise SAST, DAST, and code-review tools
  • Champion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities.
  • Automate security testing in CI/CD pipelines to detect vulnerabilities early.
  • Coordinate with stakeholders to develop and implement a vulnerability management program and to perform threat-hunting activities.
  • Monitor and respond to application-layer security threats like API abuses, business logic flaws, and common web vulnerabilities.
  • Collaborate with product and engineering teams to ensure security is a key consideration in software design and architecture.
  • Enhance application security posture by working with cross-function teams to implement proper authentication, authorization, and data protection mechanisms.
  • Enhance and facilitate security incident handling activities
  • Evangelize security best practices and provide education and awareness to company employees. Develop and implement secure coding guidelines and conduct secure development training for engineers.
  • Evaluate and continuously improve the maturity of the security program through the deployment and management of various security tools and processes.

Desired Skills and Attributes

  • 5+ years of experience in application security, secure software development, security engineering, or a similar role
  • Strong understanding of secure coding practices and ability to guide developers on remediation strategies.
  • Experience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review.
  • Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode).
  • Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning.
  • Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security).
  • Ability to perform threat modeling and assess security risks in applications and services.
  • Experience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go).
  • Understanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similar
  • Understanding to securely manage cloud-native environments and the ability to deploy tools in these environments.
  • Takes ownership of projects, works independently with minimal oversight, and delivers results in a fast-paced environment while balancing multiple priorities.
  • Continuously learns, adapts, and values correctness, efficiency, and constructive feedback.
  • Holds a Cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc.


#LI-CS1

Life at TripleLift

At TripleLift, we’re a team of great people who like who they work with and want to make everyone around them better. This means being positive, collaborative, and compassionate. We hustle harder than the competition and are continuously innovating.

Learn more about TripleLift and our culture by visiting our LinkedIn Life page.

Diversity, Equity, Inclusion and Accessibility at TripleLift 

At TripleLift, we believe in the power of diversity, equity, inclusion and accessibility. Our culture enables individuals to share their uniqueness and contribute as part of a team. With our DE&I initiatives, TripleLift is a place that works for you, and where you can feel a sense of belonging and support. At TripleLift, we will consider and champion all qualified applicants for employment without regard to race, creed, color, religion, national origin, sex, age, disability, sexual orientation, gender identity, gender expression, genetic predisposition, veteran, marital, or any other status protected by law. TripleLift is proud to be an equal opportunity employer.

Learn more about our DEI efforts at https://triplelift.com/diversity-equity-and-inclusion/

Privacy Policy

Please see our Privacy Policies on our TripleLift and 1plusX websites.

TripleLift does not accept unsolicited resumes from any type of recruitment search firm. Any resume submitted in the absence of a signed agreement will become the property of TripleLift and no fee shall be due.

Top Skills

Burp Suite
Checkmarx
Codeql
Github Advanced Security
Go
Java
Owasp Zap
Python
Snyk
Typescript
Veracode

Similar Jobs

Yesterday
Hybrid
Pune, Maharashtra, IND
Mid level
Mid level
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
As a Senior Platform Support Engineer, you'll assist clients with SaaS applications, troubleshoot software issues, and develop documentation. You'll work closely with development and operations teams while also managing end-user support issues.
Top Skills: IisJSONMicrosoft .NetMicrosoft Sql ServerOraclePostgresPowershellPythonWeb ApplicationsWeblogicWindows ServerXML
Yesterday
Remote
Hybrid
Pune, Maharashtra, IND
Senior level
Senior level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
The Global IT Help Desk Manager leads the establishment of a new help desk team, ensuring quality support, optimizing processes, and managing performance across time zones.
Top Skills: CpqDuoExperience CloudFreshserviceGoogle SuiteO365OktaSales CloudService CloudServicenowZoom
Yesterday
Hybrid
Pune, Maharashtra, IND
Mid level
Mid level
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
The Senior Enterprise Systems Administrator will manage the O365 ecosystem, develop solutions using Power Platform, administer Exchange servers, and provide hybrid O365 administration.
Top Skills: AzureadExchange OnlineMicrosoft GraphMs TeamsO365Power AppsPower AutomatePower BIPower PlatformPowershellSharepoint Online

What you need to know about the Pune Tech Scene

Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account