Sr Application Security Engineer

The Trade Desk The Trade Desk · Media · Bellevue, WA · Information Security

Senior Application Security Engineer to join Cybersecurity Department, focusing on extending and owning scalable AppSec tooling, leading threat modeling, and hardening the application security program. The role involves validating findings, reviewing features/APIs, conducting code reviews and penetration tests, writing security automation, securing AI/ML systems, and driving security culture through engineering partnerships. Requires active software development experience and hands-on experience with security tools and cloud environments. Experience in AI/ML security is a significant differentiator.

What you'd actually do

  1. Extend and own scalable AppSec tooling across four core areas: SAST/DAST pipeline integration, vulnerability management, threat modeling frameworks, and security posture— building on existing foundations and closing meaningful gaps.
  2. Validate findings end-to-end: triage and reproduce scanner output to separate signal from noise, then contextualize risk so engineering teams understand exactly what to fix, why it matters, and what the customer impact would be if exploited.
  3. Review and assess new features, APIs, and architectural changes; conduct security-focused code reviews (C#, Java, JavaScript, or similar) and application-layer penetration tests.
  4. Write production-quality security automation and tooling — this role ships code alongside security guidance.
  5. Assess and help secure AI/ML systems — including inference APIs, LLM integrations, and GenAI attack surfaces such as prompt injection and model exfiltration — and build AI-augmented tooling to scale the team's output.

Skills

Required

  • BS degree or equivalent years of experience in related field
  • 6-8+ years in application security
  • Active software development experience
  • Hands-on experience with SAST, DAST, SCA, and secrets management tooling
  • Practical threat modeling experience
  • Experience with vulnerability management workflows
  • Working knowledge of Kubernetes and container security
  • cloud security fundamentals across at least one major platform (AWS, GCP, or Azure)
  • Strong written and verbal communication skills

Nice to have

  • OSWE, GWAPT, CSSLP, OSCP, or cloud security certifications
  • Experience in ad tech, large-scale SaaS, or other high-throughput consumer or enterprise platforms

What the JD emphasized

  • track record of building tooling and automation, not just operating it
  • Candidates who currently or recently ship code are meaningfully better positioned for this role
  • Experience in AI/ML security — securing AI pipelines, assessing LLM integrations, understanding GenAI attack surfaces, or building AI-assisted security tooling. This is a meaningful differentiator.

Other signals

  • AI/ML systems security
  • LLM integrations
  • GenAI attack surfaces
  • AI-augmented tooling