Job Closed
This listing is no longer active.
We deliver better experiences for consumers and better results for your brand.
Staff Application Security Engineer
Location
United States
Posted
69 days ago
Salary
$160K - $200K / year
Seniority
Lead
Job Description
Staff Application Security Engineer
Zeta Global
WHO WE ARE Zeta Global (NYSE: ZETA) is the AI-Powered Marketing Cloud that leverages advanced artificial intelligence (AI) and trillions of consumer signals to make it easier for marketers to acquire, grow, and retain customers more efficiently. Through the Zeta Marketing Platform (ZMP), our vision is to make sophisticated marketing simple by unifying identity, intelligence, and omnichannel activation into a single platform – powered by one of the industry’s largest proprietary databases and AI. Our enterprise customers across multiple verticals are empowered to personalize experiences with consumers at an individual level across every channel, delivering better results for marketing programs. Zeta was founded in 2007 by David A. Steinberg and John Sculley and is headquartered in New York City with offices around the world. To learn more, go to www.zetaglobal.com. About the Role We’re looking for a highly skilled Staff Application Security Engineer to lead our application and platform security initiatives. You’ll be responsible for embedding security into every stage of the development lifecycle, from threat modeling through deployment, ensuring secure-by-design practices are consistently applied. Zeta operates at significant scale, supporting billions of consumer profiles and petabytes of data across real-time, AI-powered marketing platforms. In this role, you'll help safeguard our high-performance systems by driving best practices, evaluating emerging threats, and enabling cross-functional teams to build secure, reliable applications. This is a high-impact position with visibility across engineering, product, and executive leadership. Key Responsibilities Threat Modeling & Security Validation • Lead threat modeling and security architecture reviews for distributed, event- driven systems. • Integrate security code reviews, SAST/DAST, Software Composition Analysis (SCA), and container scanning into CI/CD and AI/ML pipelines. • Coordinate and lead incident simulations specific to AI systems; oversee red/blue team exercises to validate defensive posture. • Conduct security reviews of third-party vendors and tools to ensure alignment with enterprise security standards. Embedding Security into the SDLC • Collaborate with engineers and product teams to build secure features without impeding innovation. • Establish and lead security checkpoints across the software development lifecycle. • Review system designs, architecture, and data flow diagrams to identify and mitigate risks early. • Collaborate with key stakeholders to drive informed Go/No-Go security decisions for all major production deployments. Emerging Threat Monitoring & Proactive Defense • Stay on the forefront of security innovations, including OWASP, cloud-native, and API security practices. • Monitor modern threat vectors like LLM jailbreaks, prompt injection, and data poisoning. • Recommend and implement forward-looking controls to safeguard AI models and data platforms.Security Awareness & Policy Implementation • Evangelize secure coding and AI security through training, brown bag sessions, and workshops. • Develop and roll out internal security policies, standards, and best practices. • Raise awareness of security threats through documentation and hands-on engagement. • Foster a security-first culture across engineering, product, and data teams. What You Need to Succeed • Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent experience. • 5+ years of experience in Application Security, DevSecOps, or secure software development. • In-depth understanding of OWASP Top 10, SANS CWE Top 25, MITRE ATT&CK for ML, and adversarial threat modeling. • Experience securing modern frameworks and architectures (e.g., React, Node.js, Django, FastAPI). • Familiarity with AI/ML attack vectors including model inversion, adversarial examples, and training pipeline integrity. • Strong foundation in OAuth2, OpenID Connect, JWT, and securing APIs and microservices. • Experience with cloud-native security (e.g., AWS, GCP, Azure) and container technologies (e.g., Docker, Kubernetes). • Strong communication and stakeholder management skills. Nice to Have • Hands-on with tools like Semgrep, Veracode, Checkmarx, SonarQube, Burp Suite, Zap, Trivy, Brakeman, or LangSec. • Certifications such as OSCP, CSSLP, GWAPT, or ML-specific certs (e.g., MITRE ATT&CK Defender for ML). BENEFITS & PERKS - Unlimited PTO - Excellent medical, dental, and vision coverage - Employee Equity - Employee Discounts, Virtual Wellness Classes, and Pet Insurance And more!! SALARY RANGE The salary range for this role is $160,000 - $200,000, depending on location and experience. PEOPLE & CULTURE AT ZETA Zeta considers applicants for employment without regard to, and does not discriminate on the basis of an individual’s sex, race, color, religion, age, disability, status as a veteran, or national or ethnic origin; nor does Zeta discriminate on the basis of sexual orientation, gender identity or expression. We’re committed to building a workplace culture of trust and belonging, so everyone feels invited to bring their whole selves to work. We provide a forum for employees to celebrate, support and advocate for one another. Learn more about our commitment to diversity, equity and inclusion here: https://zetaglobal.com/blog/a-look-into-zetas-ergs/ ZETA IN THE NEWS! https://zetaglobal.com/press/?cat=press-releases #LI-DD1 #LI-Remote
Job Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent experience.
- 5+ years of experience in Application Security, DevSecOps, or secure software development.
- In-depth understanding of OWASP Top 10, SANS CWE Top 25, MITRE ATT&CK for ML, and adversarial threat modeling.
- Experience securing modern frameworks and architectures (e.g., React, Node.js, Django, FastAPI).
- Familiarity with AI/ML attack vectors including model inversion, adversarial examples, and training pipeline integrity.
- Strong foundation in OAuth2, OpenID Connect, JWT, and securing APIs and microservices.
- Experience with cloud-native security (e.g., AWS, GCP, Azure) and container technologies (e.g., Docker, Kubernetes).
- Strong communication and stakeholder management skills.
- Nice to Have
- Hands-on with tools like Semgrep, Veracode, Checkmarx, SonarQube, Burp Suite, Zap, Trivy, Brakeman, or LangSec.
- Certifications such as OSCP, CSSLP, GWAPT, or ML-specific certs (e.g., MITRE ATT&CK Defender for ML).
Benefits
- Unlimited PTO
- Excellent medical, dental, and vision coverage
- Employee Equity
- Employee Discounts, Virtual Wellness Classes, and Pet Insurance
- And more!!
- Salary Range
- The salary range for this role is $160,000 - $200,000, depending on location and experience.
- People & Culture at Zeta
- Zeta considers applicants for employment without regard to, and does not discriminate on the basis of an individual’s sex, race, color, religion, age, disability, status as a veteran, or national or ethnic origin; nor does Zeta discriminate on the basis of sexual orientation, gender identity or expression. We’re committed to building a workplace culture of trust and belonging, so everyone feels invited to bring their whole selves to work. We provide a forum for employees to celebrate, support and advocate for one another.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Information Technology Specialist 4 Information Security
State of New YorkThe State of New York, established in 1778, is a longstanding public service entity for the residents of New York. Its workplace culture emphasizes dedication t
Title: Information Technology Specialist 4 Information Security - 10928 Location: Latham NY United States Salary RangeFrom $96336 to $121413 Annually Employment Type Full-Time Appointment Type Contingent Permanent Jurisdictional Class Non-competitive Class Travel Percentage 0% Workweek Mon-Fri Hours Per Week 37.5 Workday From 8 AM To 5 PM Telecommuting allowed? Yes County Albany Street Address 31 British American Blvd. City Latham StateNY Zip Code12110 Duties Description Under the direction of senior staff within the Chief Information Security Office (CISO), the incumbent will provide services for the administration of Active Directory Services (AD) within the Chief Information Security Office, Cyber Defense and Response Bureau. The incumbent will be expected to participate in technical work to improve systems architecture and infrastructure and implement new solutions. The ideal candidate will possess a solid understanding of information technology systems administration and technical support. The position requires availability during off-shift hours to ensure appropriate response to security incidents or other critical activities that may impact sensitive information, critical systems, NYS agencies, or ITS. Duties include, but are not limited to, the following: - Build, maintain, and support AD authentication and authorization applications such as Active Directory Federation Services. - Build, maintain, and support AD management and automation applications such as OneIdentity Active Roles Server. - Build, maintain, and support AD synchronization applications such as Microsoft Identity Manager, Azure AD Connect, and OneIdentity QuickConnect. - Collaborate with other teams to integrate applications with NYS AD using common protocols such as SAML, OIDC, and LDAP. - Collaborate with CISO and compliance teams to ensure systems meet security and compliance standards. - Assign, approve, and track changes to supported environments. - Ensure staff are following the proper change control procedures for all work performed. - Perform daily monitoring of all supported services. - Respond to requests and incidents in accordance with pre-defined SLAs. - Collaborate with other teams on incidents, projects and threat responses. - Troubleshoot issues on supported systems as necessary. - Update and maintain system documentation. - Provide after-hours support as needed. - Perform the full range of supervisory responsibilities. Minimum Qualifications Information Technology Specialist 4 (Information Security) Non-competitive: six years of information technology, cybersecurity, or information assurance experience, including one year at the supervisory level. Substitutions: A bachelor's or higher-level degree in any field including or supplemented by 15 semester credit hours in computer science or related field substitutes for three years of required experience; any bachelor's substitutes for two years of required experience. An associate degree with 15 semester credit hours in computer science or related field may substitute for one year of required experience. Candidates in a bachelor's degree program with at least 15 semester credit hours in computer science or related field may substitute such credits for one year of required experience. A master's degree or higher in computer science or related field substitutes for one year of required experience. Preferred Qualifications: - Demonstrated experience managing enterprise identity services with a strong focus on Microsoft Entra ID (Azure AD) and Active Directory Federation Services (ADFS) in a production environment. - Hands-on operational experience supporting hybrid identity environments, including synchronization and federation between on-premises Active Directory and Entra ID. - Working knowledge of Entra ID security features, such as Conditional Access policies, identity protection concepts, authentication methods, and access governance controls. - Experience overseeing ADFS operations, including monitoring federation health, managing relying party trusts, certificates, and authentication flows. - Prior experience within information security, IAM, or CISO-aligned organization, supporting secure identity operations. - Strong understanding of identity-related incident response, including troubleshooting authentication failures, federation outages, and access-related security events. Benefits of Working for NYS Generous benefits package, worth 65% of salary, including: Holiday & Paid Time Off - Thirteen (13) paid holidays annually - Up to Thirteen (13) days of paid vacation leave annually - Up to Five (5) days of paid personal leave annually - Up to Thirteen (13) days of paid sick leave annually for PEF. - Up to three (3) days of professional leave annually to participate in professional development Health Care Benefits - Eligible employees and dependents can pick from a variety of affordable health insurance programs - Family dental and vision benefits at no additional cost Additional Benefits - New York State Employees' Retirement System (ERS) Membership - NYS Deferred Compensation - Access to NY 529 and NY ABLE College Savings Programs, as well as U.S. Savings Bonds - Public Service Loan Forgiveness (PSLF)
Security Architect- Remote or Hybrid in MN or DC
OptumOptum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.
Requisition Number: 2348014 Optum Tech is a global leader in health care innovation. Our teams develop cutting-edge solutions that help people live healthier lives and help make the health system work better for everyone. From advanced data analytics and AI to cybersecurity, we use innovative approaches to solve some of health care's most complex challenges. Your contributions here have the potential to change lives. Ready to build the next breakthrough? Join us to start Caring. Connecting. Growing together. The Security Architect serves as a technical security authority supporting mergers and acquisitions (M&A) security implementation programs. This role is responsible for defining, influencing, and implementing security architectures and controls that are being developed to be included within Optum's current security portfolio, while ensuring integrations are executed securely, efficiently, and in alignment with enterprise risk tolerance. This role operates at the intersection of integration delivery, security architecture, and product/platform evolution. The Principal Security Architect partners closely with M&A targets, Enterprise Security, Infrastructure, Cloud, Application, and Product teams to translate integration-driven security needs into actionable architectures, capability gaps, roadmap recommendations, and ready to implement accordingly both individually and by others within the organization. Success in this role requires the ability to lead through influence without authority, operate effectively amid ambiguity, and balance identified risks with long-term platform and product strategy. You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week. Key Accountabilities: - Serve as an architect for M&A integration initiatives, accountable for the overall security architecture, risk posture, and strategic alignment of acquired entities - Lead security discovery and architecture assessments of acquisition targets to identify gaps between current UHG capabilities and required future-state security outcomes - Define and recommend security solutions and architectural patterns where capabilities do not yet exist, including interim, compensating, and long-term solutions - Partner with downstream internal teams (Enterprise Security, Infrastructure, Cloud, IAM, Application Security, Product, and Engineering) to: - Understand existing technical offerings and constraints - Translate integration-driven security requirements into capability enhancements or net-new solutions - Influence and shape security product and platform roadmaps to close identified gaps - Act as a trusted advisor to business and technology leaders, clearly articulating security risk, trade-offs, and architectural options - Lead the development of future-state security architectures, reference designs, and integration patterns applicable across multiple acquisitions - Provide architectural oversight through early implementation phases to ensure security intent is preserved and delivered - Drive alignment across multiple stakeholders with competing priorities, using influence rather than authority - Mentor and provide architectural guidance to other security and integration architects across the organization - Represent security architecture in executive-level discussions related to M&A strategy, integration planning, and risk decisions Primary Responsibilities: - Own and evolve security architecture standards and patterns for M&A, including: - Identity and Access Management (IAM) - Network and perimeter security - Cloud and hybrid security - Data protection and privacy controls - Evaluate and document security risks, assumptions, dependencies, and constraints associated with protecting acquired environments - Produce high-quality internal artifacts including: - Security architecture diagrams and reference architectures - Gap analyses and capability assessments - Roadmap input and security design recommendations - Provide guidance on secure adoption of Optum platforms while recognizing when non-standard or emerging solutions are required - Develop automation where applicable that enables security deployments to be faster, more programmatic, and reduce human intervention You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Required Qualifications: - Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent experience - 8+ years of experience in security architecture, enterprise security, or platform security roles, with demonstrated impact at an enterprise level - Proven experience supporting M&A integrations, complex enterprise transformations, or large-scale platform initiatives - Solid breadth across IT and security domains, including: - Cloud (public, private, hybrid) security architectures - IAM, zero trust, and secure access models - Network, endpoint, and infrastructure security - Security orchestration & automated response - Demonstrated ability to operate in high ambiguity environments where requirements, solutions, or products are not yet fully defined - Experience influencing product, platform, or service roadmaps based on architectural and security needs - Exceptional ability to communicate complex security concepts to technical and non-technical audiences - Proven track record of leading through influence across organizational boundaries Preferred Qualifications: - Healthcare or other highly regulated industry experience - Expert level experience with the following tools: - Zscaler - Palo Alto - Microsoft Entra - Splunk - Tanium - Experience designing or influencing enterprise security platforms or shared services - Familiarity with regulatory and compliance frameworks (e.g., HIPAA, NIST, ISO, SOC) - Experience working with executive stakeholders during acquisition due diligence and integration planning - Mentorship or thought leadership experience within architecture or security communities that can effectively span down towards younger engineers *All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy. Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $112,700 to $193,200 annually based on full-time employment. We comply with all minimum wage laws as applicable. Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants. At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission. UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.
• Drive continuous improvement within SNOC security operations by identifying opportunities to enhance monitoring, response workflows, automation, and operational efficiency • Serve as the primary escalation point for complex security incidents, providing advanced technical analysis and resolution support to the SNOC engineering team. • Support the development and maintenance of operational documentation including security runbooks, incident response procedures, investigation guides, and knowledge base articles. • Identify and analyze potential security risks, vulnerabilities, and suspicious activity across network, system, endpoint, identity, and cloud environments, recommending remediation actions. • Assist in strengthening security monitoring capabilities by improving detection logic, tuning alerts, and contributing to SIEM analytics rules and automation workflows. • Provide mentorship and technical guidance to junior SNOC engineers during investigations, troubleshooting, and incident response activities. • Support security compliance initiatives by ensuring operational activities, incident investigations, and response actions are properly documented to support audits and reporting. • Participate in validation and testing of incident response procedures, disaster recovery plans, and operational readiness exercises.
Staff Security Engineer
AssuredAssured is a claims automation insurtech backed by leading Silicon Valley investors.
• Lead security architecture and design reviews across applications, infrastructure, and integrations to ensure secure patterns are embedded early in the development lifecycle. • Conduct and coordinate penetration testing, threat modeling, and security reviews for critical services, new features, and third-party integrations. • Design and implement security automation within CI/CD pipelines to ensure secure coding practices and infrastructure policies are enforced at scale. • Partner with infrastructure and DevOps teams to secure cloud platforms (AWS) and improve identity, network, and workload security. • Build security observability and detection capabilities, including security data pipelines, SIEM integrations, and threat intelligence signals. • Think like an attacker—identify systemic weaknesses and design controls that protect against entire classes of attacks, not just individual vulnerabilities. • Work closely with developers to improve security practices through secure architecture guidance, code review support, and developer enablement. • Lead incident response investigations and help build processes for identifying, analyzing, and mitigating security incidents. • Own and evolve the bug bounty program, including triage, response processes, and improvements to vulnerability management workflows. • Develop security standards, playbooks, and training programs that make security practices easier for engineering teams to adopt. • Help define the security roadmap, identifying initiatives that improve both risk posture and operational efficiency.



