thetradedesk
Application Security Engineer II
At a Glance
- Location
- Bellevue; Ventura
- Experience
- 8+ years
- Posted
- 2026-07-21T18:18:58-04:00
Key Requirements
Required Skills
Certifications
- OSCP
Domain Knowledge
- Automation
- Engineering
- Healthcare
- Insurance
- Medical
- SaaS
Benefits & Perks
ffers a competitive benefits package. Click here to learn more. Note: Intern
Requirements
6-8+ years in application security with a track record of building tooling and automation, not just operating it.
Active software development experience — you write clean, production-ready code in at least one of: C#, Java, Python, Go, or JavaScript.
Hands-on experience with SAST, DAST, SCA, and secrets management tooling, including configuration, tuning, and CI/CD integration (GitHub Actions, GitLab, Jenkins, ArgoCD, or similar).
Experience with vulnerability management workflows: aggregation, triage, risk-based prioritization, and driving remediation at scale.
Working knowledge of Kubernetes and container security (Docker, Helm, Istio) and cloud security fundamentals across at least one major platform (AWS, GCP, or Azure).
Experience in AI/ML security — securing AI pipelines, assessing LLM integrations, understanding GenAI attack surfaces, or building AI-assisted security tooling.
Responsibilities
Extend and own scalable AppSec tooling across four core areas: SAST/DAST pipeline integration, vulnerability management, threat modeling frameworks, and security posture— building on existing foundations and closing meaningful gaps.
Validate findings end-to-end: triage and reproduce scanner output to separate signal from noise, then contextualize risk so engineering teams understand exactly what to fix, why it matters, and what the customer impact would be if exploited.
Review and assess new features, APIs, and architectural changes; conduct security-focused code reviews (C#, Java, JavaScript, or similar) and application-layer penetration tests.
Write production-quality security automation and tooling — this role ships code alongside security guidance.
Assess and help secure AI/ML systems — including inference APIs, LLM integrations, and GenAI attack surfaces such as prompt injection and model exfiltration — and build AI-augmented tooling to scale the team's output.
Drive security culture through direct engineering partnership: advising on secure-by-design patterns early in the development process, raising the security floor across hundreds of engineers, and keeping customer trust at the center of every recommendation.