Jobs › Companies › Arrowstreet Capital › Senior Application Security Engineer

Über diese Senior Application Security Engineer Stelle bei Arrowstreet Capital

Arrowstreet Capital · Vor Ort · Boston

Job Overview


Join our Cyber Security team as an experienced Application Security Engineer, where you’ll play a key role in driving and advancing application security in close alignment with our vulnerability management initiatives. In this senior technical position, you’ll collaborate with development, DevOps, cloud, infrastructure, and product teams to embed security controls throughout the software development lifecycle and CI/CD pipelines.

Your responsibilities will include developing and refining secure development standards, strengthening pipeline security, automating vulnerability discovery and testing, and building scalable processes for effective risk remediation. You’ll help guide vulnerability management priorities, deliver meaningful reporting and measurement of security risks, and provide actionable guidance and training to engineering teams, all with a focus on continuous improvement of our overall security posture.


Responsibilities


  • Manage and enhance pipeline security posture by building a modern DevSecOps ecosystem that leverages innovative workflows and vulnerability management to drive effective, scalable security throughout the development lifecycle.
  • Modernize vulnerability management by integrating AI-driven analysis that correlates technical risks with business impact, enabling more informed prioritization and remediation.
  • Explore and implement the responsible use of AI to improve vulnerability discovery, code review, threat modeling, risk prioritization, security monitoring, and remediation recommendations.
  • Lead threat modeling and security reviews for AI-enabled systems, including risks such as prompt injection, insecure model output handling, sensitive data disclosure, model abuse, excessive agency, and data or model poisoning.
  • Define metrics and reporting that communicate the security posture and risk exposure of AI-enabled applications to technical teams and senior leadership.
  • Define and maintain secure SDLC policies, procedures, and workflows—and translate these into actionable technical requirements.
  • Drive security controls in CI/CD pipelines (SAST, DAST, SCA, secret detection, container scanning, API testing, etc.).
  • Work directly with development teams to explain findings, risks, and remediation steps, guiding vulnerability remediation based on an internal risk matrix of attack vectors and business objectives.
  • Advance software supply chain security, including dependency governance, artifact integrity, SBOM adoption, and third-party risk management.
  • Enhance software development pipelines with automated vulnerability and risk measurement, implementing promotion guardrails that balance effective risk management with delivery speed.
  • Support incident response for application and pipeline security events.

Qualifications


  • Ability to leverage frontier AI models to enhance secure code scanning, vulnerability discovery, and application penetration testing.
  • Experience in application security, DevSecOps, secure SDLC, vulnerability management, or security engineering.
  • Experience building advanced dashboards that highlight key risk indicators, trends, and actionable insights for technical and business stakeholders.
  • Hands-on experience collaborating with developers to remediate vulnerabilities.
  • Proficiency with CI/CD platforms and source control tools (GitHub, GitLab, Azure DevOps, Jenkins, etc.).
  • Use of application security testing tools (SAST, DAST, SCA, container scanning, API testing, etc.).
  • Experience conducting security reviews of application architectures and APIs to identify design weaknesses, vulnerabilities, and potential attack paths.
  • Familiarity with modern architectures (microservices, containers, APIs, cloud-native apps).
  • Programming/scripting experience (Python, PowerShell, Bash, C#, Java, JS/TS, Ruby, etc.).
  • Working knowledge of AWS/Azure cloud security concepts.
  • Experience developing technical documentation and secure coding guides.
  • Effective communication of technical security concepts.
  • Strong collaboration and relationship-building skills.
  • Ability to influence secure development practices and drive adoption.
  • Demonstrated adaptability and the ability to pivot strategy or priorities when faced with significant technical challenges or evolving project scopes.
  • Risk-based mindset with attention to business and delivery needs.
  • Initiative and independent leadership with strong project management.
  • Analytical and detail-oriented; excellent problem solving.
  • Thrives in fast-paced, multi-team environments.
  • Metrics-driven approach to program effectiveness.
  • Clear written and verbal communication of vulnerabilities and remediation.
  • Passion for enabling secure development through automation, training, and scalable processes.
  • Familiarity with frameworks/standards (NIST, CIS, ISO 27001, SOC 2, PCI DSS).
  • Some knowledge of application security risks and frameworks (OWASP Top 10, CWE/SANS 25, secure coding, threat modeling).
  • Experience leading or maturing application security/DevSecOps programs is a plus.
  • Developer-first tools and integration (pull requests, issue tracking, IDEs) is preferred.
  • Software supply chain security (SBOM, dependency governance, artifact signing) is a plus.
  • Threat modeling methodologies (STRIDE, attack trees, agile models).
  • Experience with containers and cloud-native platforms (Docker, Kubernetes, ECS/EKS/AKS/OpenShift) desired.
  • Experience providing application security and secure coding training is an added value.
  • Relevant certifications (CSSLP, CISSP, GWAPT, GWEB, OSWE, AWS/Azure Security) are an asset.

 

The base salary range for this position is $110,000 - $315,000 per year.

Arrowstreet Capital operates a robust talent acquisition program, and we also seek to compensate and reward our employees competitively within our industry and in line with our merit-based culture. Our approach to total compensation includes base salaries and annual discretionary bonuses, as well as a robust benefits package. The determination of a successful candidate’s base salary placement within the listed range will vary based on the candidate’s relevant experience and qualifications (which may also include relevant certifications, credentials and other education), the job responsibilities and scope, the commensurate resulting level of the position and other relevant factors. The listed range is also an estimate, and additional information regarding base salary and other elements of total compensation offered by Arrowstreet Capital to successful applicants will be communicated during the recruitment process.  

Arrowstreet Capital is a Boston-based systematic investment firm that manages global equity portfolios for institutional investors around the world. 

All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, ancestry, genetic information, age, pregnancy, medical condition, disability, veteran or military status, marital status or any other characteristic protected by federal, state, or local law.

Arrowstreet Capital is committed to working with and providing reasonable accommodations for qualified individuals with disabilities and disabled veterans. If you need a reasonable accommodation for any part of the employment process due to a disability, contact us to discuss the nature of your request and contact information.

Bereit, sich bei Arrowstreet Capital zu bewerben?
Bei Arrowstreet Capital bewerben

Wie sich dieses Gehalt für Application Security vergleicht

Diese Stelle zahlt $212,500/yr — im Einklang mit der üblichen Spanne für Application Security Stellen.

$139,680 dem Median $195,000 $265,600

Übliche Spanne $161,250–$222,050/yr, aus 13 vergleichbaren Application Security Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Application Security ansehen →

Über Arrowstreet Capital

Arrowstreet Capital is a Boston-based systematic investment firm that manages global equity portfolios for institutional investors around the world. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, ancestry, genetic information, age, pregnancy, medical condition, disability, veteran or military status, marital status or any other characteristic protected by federal, state, or local law. Arrowstreet is an equal opportunity employer. Please click here for more information. Arrowstreet Capital is committed to working with and providing reasonable accommodations for qualified individuals with disabilities and disabl

Alle Jobs bei Arrowstreet Capital ansehen →

Ähnliche Jobs

DigitalOcean
Staff Product Security Engineer, Secure Design (Kernel and Virtualization)
DigitalOcean
⚡ Früh bewerben Boston Vor Ort $180,000–$215,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
DigitalOcean
Senior Product Security Engineer
DigitalOcean
⚡ Früh bewerben Boston Vor Ort $140,800–$176,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Datadog
Staff Application Security Engineer
Datadog
⚡ Früh bewerben Boston, Massachusetts, USA; Co... · standortgebunden $244,000–$305,000
● Neu 👁 Gesehen ✓ Beworben vor 4 Tg.
Starburst
Senior Application Security Engineer
Starburst
⚡ Früh bewerben Boston, MA Vor Ort $175,000–$215,000
● Neu 👁 Gesehen ✓ Beworben vor 5 Tg.
Compass
Staff Security Engineer, Product Security And Architecture
Compass
⚡ Früh bewerben Boston Vor Ort $210,000–$234,100
● Neu 👁 Gesehen ✓ Beworben vor 5 Tg.
Shift Technology
Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada
Shift Technology
⚡ Früh bewerben US - Boston Vor Ort $120,000–$150,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
VE
Senior Product Security Engineer
Verily
⚡ Früh bewerben Boston - 100 Causeway Vor Ort $165,500–$185,500
● Neu 👁 Gesehen ✓ Beworben vor 2 Wo.
DataRobot
Staff Product Security Engineer
DataRobot
⚡ Früh bewerben Boston, Massachusetts, US Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 3 Wo.
athenahealth
Lead Application Security Engineer- DevSecOps
athenahealth
⚡ Früh bewerben Boston MA Vor Ort $143,000–$243,000
● Neu 👁 Gesehen ✓ Beworben vor 3 Wo.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Arrowstreet Capital

Alle Jobs bei Arrowstreet Capital ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos