> Markdown version of [/jobs/ext/1400577-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1400577-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** Savvy Wealth - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $220,000.0 - $235,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Software as a Service, Cloud Computing, Cloud Computing Security, Code Review, Continuous Integration, Github, Intrusion Detection and Prevention, OAuth, Phishing, Red Team (Cyber Security), Security Information and Event Management, Software Vulnerability Management, Data Processing, Google Cloud, Large Language Models, Software Security, Git, AI Platforms, Information Technology, Cloudflare, Integration Frameworks, Codebase, Gsuite, Static Application Security Testing - **Published:** July 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9f4893ae9004bbdc ## About the Role * 5+ years of hands-on security engineering experience, with significant time in application security or product security * Strong software engineering fundamentals; comfortable reading, writing, and remediating code, not just filing findings * Deep experience with the modern AppSec toolchain: secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration (GitHub-centric) * Practical experience securing SaaS environments: OAuth and third-party app review, configuration hardening, and least-privilege access design * Working knowledge of cloud security across AWS and/or GCP, and edge/CDN security (Cloudflare) * A pragmatic, risk-based mindset: you prioritize by what actually gets exploited, ship iteratively, and avoid drowning teams in noise * Strong perspective on AI-assisted development security: you understand how AI coding tools change the shape of AppSec risk (hallucinated dependencies, leaked secrets, insecure patterns at scale) and how to build guardrails without killing velocity * Track record of partnering with engineering teams as an enabler, embedding security into existing workflows rather than bolting it on * Excellent communication skills and ability to work independently in a fast-paced environment * Strong writing skills; Savvy is a written culture Nice to have: * Experience building security programs at an early-to-mid stage company, taking a function from reactive to systematic * Experience with SaaS security posture management, CSPM, or identity threat detection * Familiarity with securing LLM-based tooling, agentic workflows, or internal AI platforms * Detection engineering experience (SIEM/MDR, high-signal alerting) * Fintech or financial services environment experience * Offensive security background (pentesting, bug bounty, red team) that informs how you defend ## Description We are seeking a Senior Application Security Engineer to join Savvy Wealth at our NYC headquarters. This is a hands-on, in-the-weeds engineering role. You will execute the security strategy set by our Director of IT & Information Security and our CTO, with day-to-day work centered on identifying vulnerabilities, remediating them, and closing the longer-term gaps that make us exposed, both in our product and in the SaaS tools our teams use every day. Savvy is an AI-forward company. Most of our engineering is AI-assisted, and we enable people across the business, including non-technical roles, to build with AI coding tools. That enablement is a core part of how we work, and we intend to keep it. Your job is to make it safe: setting security hygiene standards in our codebases, building guardrails around AI-assisted development, and partnering closely with our internal AI team so that speed and security move together. You will make the secure path the easy path. This role is deliberately not a compliance or GRC position. There are no audits to run, no certifications to chase, and no questionnaires to fill out. This is purely technical security work: finding and eliminating the vectors that make us vulnerable. Responsibilities: * Own vulnerability management end to end: identify, triage, prioritize by real-world risk, and drive remediation to closure across our product, codebases, and cloud infrastructure (AWS, GCP, Cloudflare) * Build and operate our AppSec tooling pipeline: secrets scanning in CI and at the git layer, SCA/dependency scanning with triage SLAs, and SAST rollout on our most sensitive repos, tuned for signal over noise * Set and enforce security hygiene standards within our codebases, including code review standards that explicitly account for AI-generated code (authorship transparency, mandatory human review on security-sensitive paths) * Partner with our internal AI team to design guardrails that keep AI-assisted development, including vibe coding by non-technical builders, safe by default: sanctioned tooling, data handling boundaries, dependency vetting, and secure defaults for AI-built integrations * Secure the SaaS stack: harden configurations, review OAuth grants and third-party integrations, reduce misconfiguration risk across platforms like Google Workspace, GitHub, Rippling, and Slack * Help establish conditional access and identity-layer controls in partnership with IT (SSO, phishing-resistant MFA, managed-device posture) * Define cloud and SaaS configuration baselines for the infrastructure footprint we operate * Contribute to detection and response readiness: high-signal detections (new OAuth grants, mass code-host downloads, credential anomalies) and participate in incident response when needed * Work cross-functionally with Engineering, IT, and the internal AI team; clearly articulate risk, remediation paths, and tradeoffs to both technical and non-technical stakeholders ## Related Videos - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)