Application Security Engineer Jobs in New York
Application Security Engineer jobs in New York are among the most active in the country, concentrated in financial services, technology, media, and healthcare sectors with demand at every level from entry-level analyst to senior architect. Most hiring is in New York City, with secondary clusters in Albany and Buffalo, where employers like JPMorgan Chase, Citigroup, and IBM have deep, lasting engineering footprints. The most sought-after specializations include secure software development lifecycle practices, cloud-native security architecture, and penetration testing for regulated industries. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 13+ Application Security Engineer jobs











INTRODUCTION
Tatari is on a mission to revolutionize TV advertising. Founded in 2016 to help transform the antiquated world of TV advertising through the intelligent application of AI and machine learning, Tatari helps some of the world’s fastest growing brands including Chime, Calm, Tecovas, Manscaped, Saatva, and Liquid I.V, reach their customers using linear and streaming TV ads. Our platform combines sophisticated media buying with proprietary analytics to turn TV advertising into an automated, digital-like experience, enabling businesses of any size to advertise on TV. That approach has earned Tatari broad industry recognition, including being named Best CTV AdTech Platform in the 8th annual MarTech Breakthrough Awards, as well as honors from Digiday (Best Connected TV Platform), AdExchanger (Most Innovative TV Advertising Technology), and Business Insider (Hottest AdTech Companies). Tatari has also been recognized as the Best Place to Work by Inc. Magazine. Backed by an executive team of former founders and senior leaders from companies including Shazam, TrueCar, AdapTV, LiveRail, Amazon, Google, Meta, Microsoft, and Yahoo, Tatari continues to scale rapidly as TV advertising enters its next major era. We're a late-stage AdTech company with a recently attained SOC2 Type II attestation, and a clear mandate to mature our security and privacy posture. We're looking for the right engineer to make it happen.
THE ROLE
As our first dedicated Application Security Engineer, you will define the security architecture for everything we ship. You will work directly with our Engineering teams to identify vulnerabilities, design mitigations, and build the tooling and automation that makes secure development the path of least resistance. You will report to the Head of Security as a key technical contributor to Tatari's Security program. You write production-quality code. You think like an attacker. And you know how to bring engineers along with you.
Responsibilities:
- Design and execute greenfield AppSec initiatives across Tatari's SaaS platform from threat modeling to remediation
- Build and maintain security automation integrated into CI/CD pipelines and manage software supply chain risk
- Own container security across build and runtime
- Develop internal tooling and libraries that make secure coding easier for application engineers
- Own SAST/DAST/SCA tooling: selection, tuning, CI/CD integration, and triage
- Conduct application security reviews and threat models for new features and architectural changes
- Identify and remediate vulnerabilities across APIs, services, and data pipelines
- Partner with Engineering teams to establish secure coding standards and provide hands-on guidance
- Assess and mitigate LLM-introduced risks in product features
- Integrate agentic tooling into AppSec workflows to reduce toil
- Contribute to security incident response when application-layer issues are involved
QUALIFICATIONS
- Production Python experience with the engineering depth to review code meaningfully and build security tooling; Java or Rust is a bonus
- Significant hands-on application security experience, ideally at a SaaS company, including working knowledge of established standards (OWASP Top 10, API Security Top 10, ASVS, SPVS, AISVS) and how common vulnerability classes manifest in production systems
- Threat modeling experience with Product and Engineering teams
- Experience building security tooling or automation (scripts, pipelines, libraries)
- Familiarity with AWS and Kubernetes security controls as they relate to application-layer risks
- Working knowledge of how LLMs introduce new attack surfaces and how to mitigate them, with practical experience using AI tools in security or engineering workflows
- Demonstrated experience reviewing API designs and implementations for auth anti-patterns, token mismanagement, injection risks, and sensitive data exposure
- Track record embedding with Engineering teams: code review, design consultation, and standards definition
- Experience building or maturing an AppSec program where coverage, tooling, or process needed to be defined from scratch
BENEFITS
- Total compensation ($165,000-$190,000)
- Equity compensation
- Health insurance coverage for you and your dependents
- 401K, FSA, and commuter benefits
- $150 monthly spending account
- $1,000 annual continued education benefit
- $500 Newbie Productivity Perk
- Unlimited PTO and sick days
- Monthly Company Wellness Day Off
- Snacks, drinks, and catered lunches at the office
- Team building events
- Hybrid RTO of 2 days per week in office. do not use this for office manager openings
At Tatari, we believe in the importance of cultivating teams with diverse backgrounds and offering equal opportunities to all. We strive to create a welcoming, inclusive environment where every team member feels valued and diversity is celebrated.
See All 13 Application Security Engineer Jobs in New York
Find roles in New York that match your experience and apply in just a few clicks.
Find JobsApplication Security Engineer Jobs by City in New York
Where New York roles are concentrated, by current openings.
Application Security Engineer Job Market in New York
A snapshot from current New York openings, updated as new roles post.
Who's Hiring
- Palantir Technologies3

- Anthropic1

- Apollo1

- CVS Health1

- Datadog1

Top Industries Hiring
- Technology & Software5
- Artificial Intelligence2
- Government & Public Sector2
- Investment & Asset Management2
- Science & Research2
What New York Employers Look For
The qualifications that appear most often in application security engineer jobs across New York.
- Bachelor's degree in computer science, information security, or a closely related field
- Hands-on experience with SAST, DAST, and software composition analysis tools
- Proficiency in at least one programming language such as Java, Python, or Go
- Industry certification such as CISSP, CEH, or GWEB recognized by New York employers
- Working knowledge of OWASP Top 10 and secure coding standards for web and API applications
- Experience with cloud security controls across AWS, Azure, or GCP environments
Application Security Engineer Jobs in New York: Frequently Asked Questions
How do you become a application security engineer in New York?
There is no state-issued license required to work as an application security engineer in New York, so the path focuses on education and credentials recognized by employers. Most roles require a bachelor's degree in computer science, cybersecurity, or software engineering. Earning certifications such as CISSP, CEH, or GWEB strengthens your profile significantly for the financial services and technology sectors that dominate New York hiring. Building a portfolio demonstrating code review, threat modeling, and penetration testing experience is equally important for competitive positions.
How much do application security engineers make in New York?
Application security engineers in New York earn a median of about $166,180 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $97,430 for the lowest 10% to over $224,590 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire application security engineers in New York?
Employers hiring application security engineers in New York right now include Palantir Technologies, Anthropic, and Apollo, based on current listings on Migrate Mate as of June 2026. New York's concentration of global financial institutions and large technology firms means demand for application security engineers is consistently high and spread across a diverse range of regulated industries.
Which New York cities have the most application security engineer jobs?
New York and Buffalo have the most application security engineer openings in New York. New York City accounts for the largest share by far due to its density of major banks, fintech companies, media organizations, and healthcare systems, while Albany's government and state agency presence and Buffalo's growing technology and insurance sector drive openings outside the metro.
Are there remote application security engineer jobs in New York?
Yes, and more than most technical fields. About 62% of application security engineer openings tied to New York are remote or hybrid as of June 2026, reflecting that code review, threat modeling, and security tooling work is largely desk-based. Roles that involve on-site penetration testing, regulated financial system access, or government contract work are more likely to require in-person presence.
How can I get hired as a application security engineer in New York with little or no experience?
The most realistic entry path is moving into application security from a software development or IT role, since New York's large financial and technology employers frequently hire developers with a demonstrated interest in security. Large institutions like Citigroup, JPMorgan Chase, and major healthcare systems run rotational technology analyst programs and early-career cybersecurity tracks for new graduates. Earning an entry-level credential such as CompTIA Security+ and building a portfolio with a bug bounty participation or a capstone secure coding project gives candidates a concrete edge in New York interviews.
Where can I find and apply to application security engineer jobs in New York?
You can find and apply to application security engineer jobs in New York on Migrate Mate, which lists current openings from New York employers across finance, technology, healthcare, and government contracting. Find the roles that fit your experience and apply directly to each one.
See All 13 Application Security Engineer Jobs in New York
Find roles in New York that match your experience and apply in just a few clicks.
Find Jobs