> Markdown version of [/jobs/ext/1820807-application-security-engineer-ii](https://www.wearedevelopers.com/jobs/ext/1820807-application-security-engineer-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer II - **Company:** The Trade Desk - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $113,500.0 - $208,100.0 - **Contract:** Internship / Graduate position - **Skills:** Java (Programming Language), JavaScript (Programming Language), Adobe InDesign, Artificial Intelligence, Amazon Web Services, User Authentication, Automation of Tests, Microsoft Azure, C Sharp (Programming Language), Software as a Service, Code Review, Cyber Security, Continuous Integration, Data Validation, Cursor (Graphical User Interface Elements), Programming Tools, Distributed Systems, Github, Python (Programming Language), Open Web Application Security, Productivity Software, Software Engineering, Systems Integration, Software Vulnerability Management, Web Applications, Software Organization, GitHub Copilot, Software Security, Git, Kubernetes, Information Technology, Code Testing, Free and Open-Source Software, Build Tools, Codebase, Static Application Security Testing, Golang, Programming Languages, Dynamic Application Security Testing - **Published:** July 31, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87803341/1 ## About the Role * BS degree in Computer Science, Software Engineering, Cybersecurity, or a related technical field, or equivalent practical experience. * 4+ years of professional software development experience, or equivalent experience through internships, open-source contributions, or personal projects. * Experience developing software in one or more modern programming languages such as C#, Java, Python, Go, or JavaScript. * Passionate about writing clean, maintainable, and well-tested code, with an interest in building secure software. * Curious about application security and motivated to grow your expertise in secure software design, common software vulnerabilities, and modern attack techniques. * Familiar with secure software development fundamentals such as authentication, authorization, input validation, cryptography, and common web application vulnerabilities (e.g., OWASP Top 10). * Enjoy building tools, automations, and developer workflows that improve engineering productivity while making secure development the easiest path. * Interested in the future of software engineering, including AI-assisted development, and excited about using automation and developer tooling to improve security outcomes. * Comfortable learning new technologies, reading unfamiliar codebases, and solving complex technical problems. * Experience with modern software development practices, including Git, code reviews, automated testing, and CI/CD pipelines. * Strong analytical, troubleshooting, and communication skills with the ability to collaborate effectively across engineering teams. * Demonstrated curiosity and continuous learning, whether through side projects, open-source contributions, security labs, Capture the Flag (CTF) competitions, or other technical exploration. Nice to have * Exposure to application security tools such as SAST, DAST, Software Composition Analysis (SCA), secrets scanning, or dependency management. * Familiarity with threat modeling, secure design reviews, or vulnerability remediation. * Experience developing or integrating developer tooling, internal platforms, IDE extensions, GitHub Actions, CI/CD automations, or similar engineering productivity tools. * Experience with cloud platforms (AWS, Azure, or GCP), containers, Kubernetes, or infrastructure as code. * Exposure to AI-assisted development tools (such as GitHub Copilot, Cursor, Claude Code, or similar) and an interest in improving how security integrates into AI-enabled engineering workflows. * Experience building AI-powered developer tools, security automations, or evaluating the security of AI-enabled applications is a plus. * Security coursework or certifications (Security+, eJPT, CSSLP Associate, AWS/Azure/GCP certifications, or similar) are a plus. * Experience in ad tech, SaaS, or other large-scale distributed systems is a plus. #LI-TP1 ## Description We are looking for an Application Security Engineer to join our Cybersecurity Department. This role is ideal for a software engineer who enjoys building tools, solving complex technical problems, and wants to grow into a career in application security. You'll work alongside experienced security engineers to help improve the security of our applications, build developer-focused security tooling, and contribute to protecting a platform used daily by many of the world's largest brands. As an Application Security Engineer, you'll partner closely with engineering teams to improve the security of the products they build. You'll investigate vulnerabilities, contribute to security tooling and automation, participate in design and code reviews, and help improve the developer experience through practical, security-focused engineering. As software development continues to evolve with AI-assisted engineering, you'll have the opportunity to help shape the tools, workflows, and practices that enable developers to move quickly without compromising security. We're looking for someone who is curious, collaborative, and enjoys building things. You don't need to be an application security expert on day one; we're looking for a strong engineer with an interest in security and the motivation to learn. If you enjoy understanding how systems work, solving difficult problems, and creating tools that make other engineers more effective, you'll find plenty of opportunities to grow here. We believe security is most successful when it's built in partnership with engineering, and we're looking for someone who shares that mindset What you'll do: * Build tools, automations, and integrations that help engineers develop more secure software with less friction. * Partner with software engineering teams to identify security issues, understand root causes, and implement practical solutions. * Develop and improve integrations with application security tooling, including SAST, DAST, SCA, and CI/CD pipelines. * Investigate security findings from internal testing, automated tooling, and our bug bounty program, validating results and helping engineering teams prioritize and remediate vulnerabilities. * Participate in design reviews and code reviews, learning how to identify security risks early in the software development lifecycle. * Write production-quality code that improves the capabilities and scalability of the Application Security program. * Help evaluate emerging development technologies, including AI-assisted software development, and contribute to secure engineering practices. * Learn from experienced Application Security engineers while growing your expertise in secure software design, application security, and developer enablement. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 119 - ❤️ === ❤️](https://www.wearedevelopers.com/magazine/454-dev-digest-119)