Senior Application Security Engineer

Savvy
New York
Workplace: HybridFull timeUSD 220,000 - 235,000 annuallyFunction: CybersecurityExperience: 5+ yearsSkills: ["Risk-based prioritization","Communication","Independent work","Writing skills"]

Own end-to-end application security at an AI-forward wealth-tech company: identify and remediate real-world vulnerabilities across product, codebases, and cloud/SaaS infrastructure. Build and run an AppSec pipeline (secrets scanning, dependency/SCA scanning, and SAST) and set security hygiene standards that account for AI-assisted development. Partner with IT and internal AI teams to secure OAuth and third-party integrations and improve detection/response readiness.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Savvy
Savvy
1 month ago

Senior Application Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 19 hours agoStatus: Live

Job Summary

Own end-to-end application security at an AI-forward wealth-tech company: identify and remediate real-world vulnerabilities across product, codebases, and cloud/SaaS infrastructure. Build and run an AppSec pipeline (secrets scanning, dependency/SCA scanning, and SAST) and set security hygiene standards that account for AI-assisted development. Partner with IT and internal AI teams to secure OAuth and third-party integrations and improve detection/response readiness.
Location: New York
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own vulnerability management end to end by triaging and driving remediation to closure across product, codebases, and cloud infrastructure.
  • •Build and operate an AppSec tooling pipeline including secrets scanning, dependency/SCA scanning with SLAs, and SAST rollout on sensitive repositories.
  • •Set and enforce security hygiene standards in codebases, including review practices for AI-generated code and mandatory human review on security-sensitive paths.
  • •Partner with the internal AI team to design AI development guardrails (secure defaults, tooling/data boundaries, dependency vetting).
  • •Secure the SaaS stack by hardening configurations, reviewing OAuth grants and third-party integrations, and improving detection/response readiness.

Pay and Benefits

Salary: USD 220,000 - 235,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceDentalVision401kPaid LeaveCommuter BenefitsHsa/fsa

Key Requirements

  • •5+ years of hands-on security engineering experience focused on application or product security.
  • •Strong software engineering fundamentals, comfortable reading, writing, and remediating code.
  • •Deep AppSec toolchain experience: secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration.
  • •Experience securing SaaS environments, including OAuth/third-party app reviews, configuration hardening, and least-privilege access.
  • •Working knowledge of cloud security across AWS and/or GCP, plus edge/CDN security (Cloudflare).
Experience:5+ years
Skills:Risk-based prioritizationCommunicationIndependent workWriting skills
Tech Stack:AWSGCPCloudflareGitHubCI/CDSecrets scanningSCADependency scanningSASTOAuthGoogle WorkspaceRipplingSlackSSOMFAClaudeAI-assisted developmentAppSecOAuth grants

Company Brief

Savvy
Provides wealth management and financial planning services focused on helping individuals and families grow, preserve, and manage their wealth through personalized investment strategies and advisory support.
Industry: Wealth Management
Website