
Staff Application Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in New York.
• Design, develop, and enhance application security capabilities that support secure software development at NBCUniversal.
• Create reusable security automations, integrations, APIs, workflows, and developer tools.
• Establish secure-by-default golden paths, paved roads, and engineering patterns.
• Architect and implement scalable security solutions across source code, open source dependencies, containers, cloud-native applications, CI/CD pipelines, infrastructure as code, developer platforms, and software supply chains.
• Collaborate with Cloud Security on application and cloud security capabilities.
• Enhance vulnerability prioritization, triage, remediation, validation, reporting, and speed of remediation.
• Develop security patterns and guardrails for AI-assisted development tools, coding assistants, and agentic workflows.
• Employ automation and AI-driven techniques to enhance vulnerability triage, remediation planning, developer guidance, and workflow efficiency.
• Create integrations between application security platforms, GitHub, CI/CD systems, developer portals, ticketing systems, reporting platforms, and other engineering tools.
• Generate telemetry, dashboards, and reporting pipelines for application risk, coverage, and remediation progress.
• Act as a senior technical authority in application security engineering, secure software development, software supply chain security, and secure AI development.
• Collaborate with architects, platform engineers, cloud security engineers, and development teams to execute technical solutions.
• Mentor engineers to enhance engineering practices, automation skills, and technical expertise.
• Over 8 years of experience in Application Security, Security Engineering, DevSecOps, Software Engineering, or a related technical discipline.
• Extensive experience in secure software development, application security, vulnerability management, and software supply chain security.
• Practical experience in building security automations, integrations, APIs, platforms, developer tooling, or similar engineering solutions.
• Strong software engineering and scripting abilities, particularly in Python or comparable languages.
• Direct experience integrating SAST, SCA, secrets detection, container security, CI/CD security, and vulnerability management into developer workflows.
• Capability to address complex, ambiguous technical challenges and drive adoption through implementation, documentation, and collaboration.
• Knowledge of AI-assisted development, agentic workflows, and associated security considerations.
• Familiarity with application security platforms such as Snyk, Wiz Code, GitHub Advanced Security, Checkmarx, Veracode, or similar tools.
• Experience in creating secure developer platforms, internal tools, paved roads, golden paths, or reusable engineering services.
• Proficiency across AppSec and CloudSec domains, including cloud-native architectures, containers, Kubernetes, infrastructure as code, CI/CD security, CSPM, CNAPP, or related technologies.
• Background in software supply chain security, SBOM capabilities, dependency risk workflows, or artifact security processes.
• Experience leveraging AI to enhance vulnerability management, remediation workflows, security operations, or developer productivity.
• Company-sponsored medical insurance.
• Dental insurance.
• Vision insurance.
• 401(k) plan.
• Paid leave.
• Tuition reimbursement.
• A variety of other discounts and perks.
• Eligibility for bonuses.
Moniepoint Inc. (Formerly TeamApt Inc.)
Angst+Pfister Sensors and Power AG
GE Vernova
GE Vernova
Get handpicked remote jobs straight to your inbox weekly.