Application Security Engineer

City of New York•New York, NY
•$75,000 - $135,000•Onsite

About The Position

The Office of Technology and Innovation (OTI) leverages technology to drive opportunity, improve public safety, and help government run better across New York City. From delivering affordable broadband to protecting against cybersecurity threats and building digital government services, OTI is at the forefront of how the city delivers for New Yorkers in the 21st century. Cyber Command is charged with protecting all City systems against cyber threats, including systems that deliver vital services to New Yorkers. Headed by the Chief Information Security Officer of the City of New York, we provide in-depth support to over 100 agencies and offices to protect, detect, identify, respond to, and recover from cyber threats. The Application Security Engineer will play a core operational role in safeguarding the city's digital infrastructure by identifying, analyzing, and mitigating security risks across software applications. This role will execute key functions of the Software Security Assurance Program (SSAP) and involves using SAST, DAST, and SCA methodologies to uncover vulnerabilities, conduct manual application security reviews, perform threat modeling, and partner directly with agency developers to guide code-level remediation.

Requirements

  • A baccalaureate degree from an accredited college and four years of satisfactory full-time experience related to projects and policies required by the particular position; or, Education and/or experience which is equivalent to "1" above.

Nice To Haves

  • Experience with SAST, DAST, and SCA methodologies
  • Experience with manual application security reviews
  • Experience with threat modeling
  • Experience guiding code-level remediation
  • Experience with CI/CD pipelines (e.g., GitHub Actions, Azure DevOps, GitLab)
  • Experience with DevSecOps practices
  • Experience with web APIs (OAuth, REST)
  • Experience with secure coding guidelines, application security documentation, and training materials

Responsibilities

  • Execute application security assessments within the Software Security Assurance Program (SSAP) to verify that web applications, APIs, and mobile systems meet city security standards prior to deployment.
  • Perform SAST, DAST, and manual security reviews to validate vulnerabilities, eliminate false positives, and prioritize findings based on operational risk.
  • Operate Software Composition Analysis (SCA) tools to monitor, track, and drive remediation of open-source and third-party software component vulnerabilities.
  • Conduct structured threat modeling and logic reviews on assigned applications during the design phase to help identify security flaws before code is written.
  • Serve as a technical point of contact for agency development teams, delivering clear, actionable remediation guidance and secure coding advice.
  • Assist in configuring and integrating automated security scanning tools into agency CI/CD pipelines (e.g., GitHub Actions, Azure DevOps, GitLab) to support DevSecOps practices.
  • Conduct security reviews of third-party vendor solutions and web APIs (OAuth, REST) to verify alignment with city security policies and industry best practices.
  • Contribute to the maintenance of secure coding guidelines, application security documentation, and training materials for agency development staff.

Benefits

  • Great benefits
  • Chance to work on projects that have a meaningful impact on millions of people
  • Opportunity to work with cutting-edge technology
  • Collaborate with other passionate professionals
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service