Security Engineer, Application Security

GameChangerNew York, NY
$120,000 - $140,000Hybrid

About The Position

We’re looking for a Security Engineer to join our InfoSec team and become the primary security partner for our software engineering organization. Reporting to the Security Engineering Manager, you’ll operate application security across the SDLC, champion secure design and development practices, and bring DevSecOps discipline to how we build and ship software. This is a high-impact, highly collaborative role. You’ll work closely with platform and product engineers to make security a part of how we build and deliver. You will also be a member of our weekly on-call rotation.

Requirements

  • 3+ years in application security engineering
  • Proven experience building and operating internal security developer platforms or tooling that reduces developer friction
  • Demonstrated ability to use AI/ML-driven tools to enhance security effectiveness and scalability
  • Hands-on experience leading threat modeling engagements and designing paved roads
  • Proven track record integrating security tooling into CI/CD pipelines
  • Working knowledge of OWASP Top 10s (web, mobile, API, LLM)
  • Hands-on experience securing deployments in AWS with container and Kubernetes security, IaC scanning, and policy-as-code approaches
  • Demonstrated expertise in security-by-design in TypeScript, Swift, and/or Kotlin
  • Track record of implementing secure primitives in mobile ecosystems (iOS/Android)

Nice To Haves

  • Beneficial certifications: AWS Certified Security Specialty, CKS, GWEB, GMOB, or equivalent.

Responsibilities

  • Application security
  • Embed security into every phase of the SDLC
  • Champion security requirements for the responsible and secure integration of Gen AI and agentic AI tools within our product stack
  • Conduct security-by-design engagements for new features, APIs, platform initiatives, and infrastructure changes
  • Perform secure code reviews providing engineers with clear, actionable findings and remediation guidance
  • Partner with architecture and platform teams to establish secure API patterns (REST and GraphQL)
  • Contribute to and maintain secure coding guidelines, API security standards, and security architectural patterns that serve as the “paved roads” for all engineering teams
  • Give useful code review feedback, write documentation that outlasts the ticket, and run the occasional workshop or lunch-and-learn for engineers
  • DevSecOps
  • Integrate and maintain security tooling across CI/CD pipelines
  • Enforce security quality gates in delivery pipelines
  • Harden the CI/CD platform components, including configuration and hardening of GitHub Actions and runner environments
  • Identify opportunities to leverage AI for increasing engineering productivity and agentic security workflows
  • Work alongside DevOps engineers to ensure cloud infrastructure is defined and deployed securely via IaC (terraform, k8s)
  • Implement and validate security controls for containerized workloads
  • Support the implementation of application-layer network security controls, such as Web Application Firewalls (WAFs) and CDN security, to protect application endpoints
  • Vulnerability & Risk Management
  • Operate the application vulnerability management lifecycle
  • Triage and prioritize findings from our sources (including; GHAS, NowSecure, Wiz, BugCrowd, penetration tests) by business impact and exploitability
  • Proactively identify systemic risks and facilitate cross-functional initiatives to address root causes
  • Track security-specific KPIs (e.g., MTTR, vulnerability density, and security coverage of CI/CD pipelines) and translate them into actionable insights for engineering and business leadership
  • Effectively communicate security risk clearly to both engineering and business leaders

Benefits

  • Work remotely throughout the US or from our well-furnished, modern office in Manhattan, NY.
  • Unlimited vacation policy.
  • Paid volunteer opportunities.
  • Technology stipend - $4,000 every 2 years after your start to make sure you have the latest and greatest technology.
  • WFH stipend - $500 annually to make your WFH situation comfortable.
  • Monthly physical, mental, wellness & learning stipend offered through Holisticly.
  • Monthly lifestyle stipend offered through Fringe.
  • Full health benefits - medical, dental, vision, prescription, FSA, HRA, HSA, and coverage for family/dependents.
  • Retirement savings - Traditional and Roth 401K plans are offered through Vanguard, with an immediate company match.
  • Life insurance - basic life, supplemental life, and dependent life.
  • Disability leave - short-term disability and long-term disability.
  • Company paid parental leave - up to 20 weeks for birthing parents and up to 12 weeks for non-birthing parents.
  • Family building benefits offered through Progyny.
  • DICK'S Sporting Goods and their family of brands teammate discount.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service