Senior Application Security Engineer

City of New YorkNew York City, NY
Onsite

About The Position

The Office of Technology and Innovation (OTI) leverages technology to drive opportunity, improve public safety, and help government run better across New York City. From delivering affordable broadband to protecting against cybersecurity threats and building digital government services, OTI is at the forefront of how the city delivers for New Yorkers in the 21st century. At OTI, we offer great benefits, and the chance to work on projects that have a meaningful impact on millions of people. You'll have the opportunity to work with cutting-edge technology and collaborate with other passionate professionals who share your drive and commitment to making a difference through technology. The Application Security program defines, promotes, assures, and measures the security of business applications and data, empowering city agencies to build and operate secure-by-design software. As a senior technical member of the team, the Senior Application Security Engineer serves as an expert-level specialist and lead resource for the Software Security Assurance Program (SSAP). The selected candidate will be responsible for identifying, validating, and providing definitive remediation guidance for vulnerabilities across the City’s application portfolio. This role focuses on operating and optimizing security scanning platforms, performing deep-dive manual validation, and serving as a key technical resource and mentor to guide other team members performing assessments.

Requirements

  • A baccalaureate degree from an accredited college and four years of satisfactory full-time experience related to projects and policies required by the particular position; or, Education and/or experience which is equivalent to "1" above.

Nice To Haves

  • IT SECURITY SPECIALIST - 95622

Responsibilities

  • Operate, configure, and optimize enterprise-level static, dynamic, and software composition testing platforms (SAST/DAST/SCA);
  • Perform advanced manual testing and exploit reproduction to validate automated findings and uncover complex logic flaws;
  • Partner with development teams across city agencies to translate vulnerability findings into actionable, design-level remediation requirements and coding guidance;
  • Identify recurring vulnerability patterns and systemic security weaknesses to help shape long-term secure coding practices;
  • Serve as the lead technical resource and mentor for internal team members performing scans and learning to execute full security assessments;
  • Generate defensible, high-quality technical reports and executive summaries on application vulnerability statuses.
  • Handle special projects and initiatives as assigned.

Benefits

  • great benefits
  • chance to work on projects that have a meaningful impact on millions of people
  • opportunity to work with cutting-edge technology
  • collaborate with other passionate professionals who share your drive and commitment to making a difference through technology
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service