> Markdown version of [/jobs/ext/2632369-staff-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2632369-staff-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Application Security Engineer - **Company:** Nbcuniversal Media, LLC - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $120,000.0 - $145,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Programming Tools, Github, Issue Tracking Systems, Python (Programming Language), Open Source Technology, Software Tools, Software Engineering, Systems Integration, Software Vulnerability Management, Scripting, Spring Cloud, Software Security, Veracode, Kubernetes, Infrastructure Automation Frameworks, Tools for Reporting, Checkmarx, Devsecops, Static Application Security Testing - **Published:** August 14, 2026 - **Apply:** https://www.jobmonkeyjobs.com/career/27931990/Staff-Application-Security-Engineer-New-York-New-York-1011 ## About the Role * 8+ years of experience in Application Security, Security Engineering, DevSecOps, Software Engineering, or a related technical field. * Deep experience with secure software development, application security, vulnerability management, and software supply chain security. * Hands-on experience building security automations, integrations, APIs, platforms, developer tooling, or similar engineering solutions. * Strong software engineering and scripting skills using Python or similar languages. * Hands-on experience integrating AppSec technologies such as SAST, SCA, secrets detection, container security, CI/CD security, and vulnerability management into developer workflows. * Ability to solve complex, ambiguous technical problems and influence adoption through implementation, documentation, and collaboration. * Familiarity with AI-assisted development, agentic workflows, and related security considerations. Preferred Qualifications * Experience with Snyk, Wiz Code, Github Advanced Security, Checkmarx, Veracode, or similar application security platforms. * Experience building secure developer platforms, internal tools, paved roads, golden paths, or reusable engineering services. * Experience across AppSec and CloudSec domains, including cloud-native architectures, containers, Kubernetes, infrastructure as code, CI/CD security, CSPM, CNAPP, or related technologies. * Experience with software supply chain security, SBOM capabilities, dependency risk workflows, or artifact security processes. * Experience using AI to improve vulnerability management, remediation workflows, security operations, or developer productivity. ## Description This hands-on role within Software Security Services combines deep AppSec expertise, software engineering skills, cross-team thought leadership, and experience building automation, integrations, platforms, and developer-facing security capabilities. The role turns application security strategy into working solutions, including golden paths, remediation automation, secure AI guardrails, and integrated developer workflows. Although primarily focused on Application Security engineering, this role works closely with Cloud Security, Platform Engineering, and Software Engineering teams at NBCUniversal. Key Responsibilities Application Security Engineering * Design, build, and improve application security capabilities that support secure software development across NBCUniversal. * Build reusable security automations, integrations, APIs, workflows, and developer tools that reduce manual effort and improve scalability. * Implement secure-by-default golden paths, paved roads, and engineering patterns that make secure development easier to adopt. * Design and implement scalable security solutions spanning source code, open source dependencies, containers, cloud-native applications, CI/CD pipelines, infrastructure as code, developer platforms, and software supply chains. * Partner with Cloud Security on capabilities spanning application code, containers, CI/CD, infrastructure as code, cloud platforms, and software supply chain workflows. * Improve vulnerability prioritization, triage, remediation, validation, reporting, and speed to remediation. Secure AI and Agentic Workflow Enablement * Build security patterns, guardrails, and reusable implementations that support safe use of AI-assisted development tools and coding assistants. * Build capabilities that secure agentic workflows, AI-enabled developer tooling, and machine-assisted software delivery. * Use automation and AI-enabled techniques to improve vulnerability triage, remediation planning, developer guidance, and workflow efficiency. * Tooling, Automation, and Platform Integration * Build integrations between application security platforms, GitHub, CI/CD systems, developer portals, ticketing systems, reporting platforms, and other engineering tools. * Create telemetry, dashboards, and reporting pipelines for actionable visibility into application risk, coverage, and remediation progress. Technical Leadership and Enablement * Serve as a senior technical expert for application security engineering, secure software development, software supply chain security, and secure AI development. * Partner with architects, platform engineers, cloud security engineers, and development teams to turn security direction into working technical solutions. * Mentor engineers and improve the team's engineering practices, automation skills, and technical depth. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)