Jobs Companies The Trade Desk Sr Application Security Engineer

Sobre esta vaga de Sr Application Security Engineer na The Trade Desk

The Trade Desk · Presencial · Bellevue; Ventura

The Trade Desk is a global technology company and the world’s leading independent platform for digital advertising, with nearly 4,000 employees across more than 30 offices. Our technology helps advertisers reach the right audiences across the open internet — from streaming TV and podcasts to mobile apps, news, and more. 

Advertising powers the content people love. By making it more transparent, effective, and responsible, we help support trusted journalism, quality entertainment, and creators worldwide. The world’s brands and agencies rely on us to reach their customers and grow their businesses responsibly.

The scale of our platform brings unique technical challenges — from processing massive datasets in real time to building systems that operate reliably on a global scale. When you work here, your impact is worldwide. We welcome diverse perspectives, encourage curiosity, and build teams that learn from one another. If you’re driven to solve meaningful challenges, we’d love to meet you.

What we do:

We are looking for a Senior Application Security Engineer to join our Cybersecurity Department. This person will complement and extend the application security capabilities we have built — with significant opportunity to make an immediate, sizable impact. You will own tooling, lead threat modeling, and harden the application security program across a platform used daily by the world's largest brands. This is not a steady-state role: there is meaningful work to do, and the right person will see it and run toward it.

The right candidate brings deep application security expertise, strong software development instincts, and a genuine bias to action. You are someone who builds things — not just findings documents. You think about security from the perspective of the engineers you partner with and the customers whose trust is at stake, and you communicate in ways that make both groups more effective.

Beyond the technical experience, we are looking for someone with the qualities that make a security engineer effective in a collaborative, fast-moving engineering culture. You are curious about how systems work and how they break. You pair that curiosity with ownership and follow-through. You communicate clearly, give and receive feedback well, and approach the engineers you work with as partners — not gatekeepers. Security is a team sport, and you bring that mindset every day.

What you'll do:

  • Extend and own scalable AppSec tooling across four core areas: SAST/DAST pipeline integration, vulnerability management, threat modeling frameworks, and security posture— building on existing foundations and closing meaningful gaps.
  • Validate findings end-to-end: triage and reproduce scanner output to separate signal from noise, then contextualize risk so engineering teams understand exactly what to fix, why it matters, and what the customer impact would be if exploited.
  • Review and assess new features, APIs, and architectural changes; conduct security-focused code reviews (C#, Java, JavaScript, or similar) and application-layer penetration tests.
  • Write production-quality security automation and tooling — this role ships code alongside security guidance.
  • Assess and help secure AI/ML systems — including inference APIs, LLM integrations, and GenAI attack surfaces such as prompt injection and model exfiltration — and build AI-augmented tooling to scale the team's output.
  • Drive security culture through direct engineering partnership: advising on secure-by-design patterns early in the development process, raising the security floor across hundreds of engineers, and keeping customer trust at the center of every recommendation.
  • Participate in and drive security governance-first frameworks to include developing and publishing standards, guidelines, procedures, secure baselines, and policies.

Who you are: 

  • BS degree or equivalent years of experience in related field
  • 6-8+ years in application security with a track record of building tooling and automation, not just operating it.
  • Active software development experience — you write clean, production-ready code in at least one of: C#, Java, Python, Go, or JavaScript. Candidates who currently or recently ship code are meaningfully better positioned for this role.
  • Hands-on experience with SAST, DAST, SCA, and secrets management tooling, including configuration, tuning, and CI/CD integration (GitHub Actions, GitLab, Jenkins, ArgoCD, or similar).
  • Practical threat modeling experience (STRIDE, PASTA, or equivalent) — producing engineering-useful outputs, not just risk documentation.
  • Experience with vulnerability management workflows: aggregation, triage, risk-based prioritization, and driving remediation at scale.
  • Working knowledge of Kubernetes and container security (Docker, Helm, Istio) and cloud security fundamentals across at least one major platform (AWS, GCP, or Azure).
  • Experience in AI/ML security — securing AI pipelines, assessing LLM integrations, understanding GenAI attack surfaces, or building AI-assisted security tooling. This is a meaningful differentiator.
  • Strong written and verbal communication skills — able to translate technical risk into terms that resonate with engineering teams, product leadership, and the broader customer-first mindset that drives decisions at The Trade Desk.
  • Certifications such as OSWE, GWAPT, CSSLP, OSCP, or cloud security certifications (AWS, GCP, or Azure) are a plus.
  • Experience in ad tech, large-scale SaaS, or other high-throughput consumer or enterprise platforms is a plus.   #LI-TP1

The Trade Desk does not accept unsolicited resumes from search firm recruiters. Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired; such resumes will be deemed the sole property of The Trade Desk. The Trade Desk is an equal opportunity employer. All aspects of employment will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.

[LA JOBS ONLY] The Trade Desk will consider qualified applicants with criminal histories for employment in a manner consistent with the requirements of the Los Angeles Fair Chance Initiative for Hiring, Ordinance No. 184652.

[SF JOBS ONLY] Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

In accordance with various US state laws, the range provided is the Trade Desk's reasonable estimate of the base compensation for this role. The actual amount may differ based on non-discriminatory factors such as experience, knowledge, skills, and location.  All employees may be eligible to become The Trade Desk shareholders through eligibility for stock-based compensation grants, which are awarded to employees based on company and individual performance. The Trade Desk also offers other compensation depending on the role such as variable compensation-based incentives and commissions. Plus, expected benefits for this role include comprehensive healthcare (medical, dental, and vision) with premiums paid in full for employees and dependents, retirement benefits such as a 401k plan and company match, short and long-term disability coverage, basic life insurance, well-being benefits, reimbursement for certain tuition expenses, parental leave, sick time of 1 hour per 30 hours worked, vacation time for full-time employees up to 120 hours thru the first year and 160 hours thereafter, and around 13 paid holidays per year.  Employees can also purchase The Trade Desk stock at a discount through The Trade Desk’s Employee Stock Purchase Plan. 

The Trade Desk also offers a competitive benefits package. Click here to learn more.

Note: Interns are not eligible for variable incentive awards such as stock-based compensation, retirement plan, vacation, tuition reimbursement or parental leave

At the Trade Desk, Base Salary is one part of our competitive total compensation and benefits package and is determined using a salary range. The base salary range for this role is
$113,500$208,100 USD

As an Equal Opportunity Employer, The Trade Desk is committed to creating an inclusive hiring experience where everyone has the opportunity to thrive.

Please reach out to us at accommodations@​thetradedesk.​com to request an accommodation or discuss any accessibility needs you may require to access our Company Website or navigate any part of the hiring process. 

When you contact us, please include your preferred contact details and specify the nature of your accommodation request or questions. Any information you share will be handled confidentially and will not impact our hiring decisions.

Pronto para se candidatar à The Trade Desk?
Candidatar-se à The Trade Desk

Como este salário de Application Security se compara

Esta vaga paga $160,800/yrem linha com da faixa típica para vagas de Application Security.

$111,188 a mediana $190,000 $274,500

Faixa típica $160,000–$235,000/yr, com base em 174 vagas de Application Security comparáveis na JobsRadar (pagamento anualizado em USD). Ver insights salariais de Application Security →

Vagas semelhantes

Shopback
Product Security Engineer
Shopback
⚡ Candidate-se cedo Bangalore, India Remoto $11,440–$11,440
● Nova 👁 Vista ✓ Candidatada há 5h
Prolific
Senior Application Security Engineer
Prolific
⚡ Candidate-se cedo Remote, UK · local restrito
● Nova 👁 Vista ✓ Candidatada há 9h
Roblox
Principal Security Software Engineer, Application Security
Roblox
⚡ Candidate-se cedo San Mateo, CA, United States Presencial $326,060–$385,050
● Nova 👁 Vista ✓ Candidatada há 11h
Roblox
Senior Security Software Engineer, Application Security
Roblox
⚡ Candidate-se cedo San Mateo, CA, United States Presencial $269,170–$326,060
● Nova 👁 Vista ✓ Candidatada há 11h
OneTrust
Senior Product Security Engineer
OneTrust
⚡ Candidate-se cedo Madrid, Spain Presencial
● Nova 👁 Vista ✓ Candidatada há 12h
United Talent Agency
Senior Product Security Engineer
United Talent Agency
⚡ Candidate-se cedo Foothill Office Presencial $160,000–$200,000
● Nova 👁 Vista ✓ Candidatada há 12h
Asana
Application Security Engineer
Asana
⚡ Candidate-se cedo Warsaw Híbrido
● Nova 👁 Vista ✓ Candidatada há 15h
Temporal Technologies
Senior Application Security Engineer
Temporal Technologies
⚡ Candidate-se cedo United States or Canada - Remo... · local restrito $180,000–$225,000
● Nova 👁 Vista ✓ Candidatada há 16h
Oscar Health
Senior Product Security Engineer I
Oscar Health
⚡ Candidate-se cedo New York, New York, United Sta... Presencial $215,176–$215,176
● Nova 👁 Vista ✓ Candidatada há 18h

Cadastre-se para receber sugestões sob medida com base nas vagas que você abre e nas buscas que você salva.

Mais vagas na The Trade Desk

Ver todas as vagas na The Trade Desk →

Candidatar-se agora
🤖

Opa — calma aí

A JobsRadar foi feita para pessoas de verdade passando por um momento difícil na busca por emprego — não para requisições automatizadas. Você está clicando rápido demais e agora está temporariamente bloqueado.

Volte mais tarde. Se você está mesmo procurando emprego, estamos com você — apenas aja como um ser humano.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Ganhe vantagem na sua busca por emprego.

Entre no nosso canal do Telegram para o que ajuda você a conseguir a vaga — referências salariais, o pulso semanal do mercado e avisos de novos recursos. Sem spam, só sinal.

Entre no canal — é grátis