Sr Application Security Engineer

The Trade DeskVentura, CA
$113,500 - $208,100Hybrid

About The Position

The Trade Desk is seeking a Senior Application Security Engineer to join their Cybersecurity Department. This role offers a significant opportunity to make an immediate impact by complementing and extending the existing application security capabilities. The engineer will be responsible for tooling, leading threat modeling, and hardening the application security program for a platform used by major brands. This is a dynamic role with meaningful work for someone who is proactive and driven to solve challenges. The ideal candidate possesses deep application security expertise, strong software development instincts, and a bias for action, focusing on building solutions rather than just identifying issues. They should approach security from the perspective of engineers and customers, communicating effectively to enhance their capabilities. Beyond technical skills, the candidate should be curious, take ownership, communicate clearly, and collaborate effectively with engineers, viewing security as a team sport.

Requirements

  • BS degree or equivalent years of experience in related field
  • 6-8+ years in application security with a track record of building tooling and automation, not just operating it.
  • Active software development experience — you write clean, production-ready code in at least one of: C#, Java, Python, Go, or JavaScript. Candidates who currently or recently ship code are meaningfully better positioned for this role.
  • Hands-on experience with SAST, DAST, SCA, and secrets management tooling, including configuration, tuning, and CI/CD integration (GitHub Actions, GitLab, Jenkins, ArgoCD, or similar).
  • Practical threat modeling experience (STRIDE, PASTA, or equivalent) — producing engineering-useful outputs, not just risk documentation.
  • Experience with vulnerability management workflows: aggregation, triage, risk-based prioritization, and driving remediation at scale.
  • Working knowledge of Kubernetes and container security (Docker, Helm, Istio) and cloud security fundamentals across at least one major platform (AWS, GCP, or Azure).
  • Experience in AI/ML security — securing AI pipelines, assessing LLM integrations, understanding GenAI attack surfaces, or building AI-assisted security tooling. This is a meaningful differentiator.
  • Strong written and verbal communication skills — able to translate technical risk into terms that resonate with engineering teams, product leadership, and the broader customer-first mindset that drives decisions at The Trade Desk.

Nice To Haves

  • Certifications such as OSWE, GWAPT, CSSLP, OSCP, or cloud security certifications (AWS, GCP, or Azure) are a plus.
  • Experience in ad tech, large-scale SaaS, or other high-throughput consumer or enterprise platforms is a plus.

Responsibilities

  • Extend and own scalable AppSec tooling across four core areas: SAST/DAST pipeline integration, vulnerability management, threat modeling frameworks, and security posture— building on existing foundations and closing meaningful gaps.
  • Validate findings end-to-end: triage and reproduce scanner output to separate signal from noise, then contextualize risk so engineering teams understand exactly what to fix, why it matters, and what the customer impact would be if exploited.
  • Review and assess new features, APIs, and architectural changes; conduct security-focused code reviews (C#, Java, JavaScript, or similar) and application-layer penetration tests.
  • Write production-quality security automation and tooling — this role ships code alongside security guidance.
  • Assess and help secure AI/ML systems — including inference APIs, LLM integrations, and GenAI attack surfaces such as prompt injection and model exfiltration — and build AI-augmented tooling to scale the team's output.
  • Drive security culture through direct engineering partnership: advising on secure-by-design patterns early in the development process, raising the security floor across hundreds of engineers, and keeping customer trust at the center of every recommendation.
  • Participate in and drive security governance-first frameworks to include developing and publishing standards, guidelines, procedures, secure baselines, and policies.

Benefits

  • Comprehensive healthcare (medical, dental, and vision) with premiums paid in full for employees and dependents
  • Retirement benefits such as a 401k plan and company match
  • Short and long-term disability coverage
  • Basic life insurance
  • Well-being benefits
  • Reimbursement for certain tuition expenses
  • Parental leave
  • Sick time of 1 hour per 30 hours worked
  • Vacation time for full-time employees up to 120 hours thru the first year and 160 hours thereafter
  • Around 13 paid holidays per year
  • Employees can also purchase The Trade Desk stock at a discount through The Trade Desk’s Employee Stock Purchase Plan.
  • Stock-based compensation grants
  • Variable compensation-based incentives and commissions
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service