NYC Parks Arsenal West Logo

NYC Parks Arsenal West

Senior Application Security Engineer

Posted 11 Days Ago
Be an Early Applicant
In-Office
New York, NY
75K-135K Annually
Senior level
In-Office
New York, NY
75K-135K Annually
Senior level
Lead application security assessments across New York City agencies by operating SAST, DAST, and SCA platforms, validating vulnerabilities through manual testing and exploit reproduction, providing remediation and secure coding guidance, identifying systemic weaknesses, mentoring assessment staff, and producing technical and executive security reports.
The summary above was generated by AI
Job Description

The Office of Technology and Innovation (OTI) leverages technology to drive opportunity, improve public safety, and help government run better across New York City. From delivering affordable broadband to protecting against cybersecurity threats and building digital government services, OTI is at the forefront of how the city delivers for New Yorkers in the 21st century. Follow us on social media @NYCOfficeofTech, and visit www.nyc.gov/oti to learn more.
At OTI, we offer great benefits, and the chance to work on projects that have a meaningful impact on millions of people. You'll have the opportunity to work with cutting-edge technology and collaborate with other passionate professionals who share your drive and commitment to making a difference through technology.
Job Description
The Application Security program defines, promotes, assures, and measures the security of business applications and data, empowering city agencies to build and operate secure-by-design software.
As a senior technical member of the team, the Senior Application Security Engineer serves as an expert-level specialist and lead resource for the Software Security Assurance Program (SSAP). The selected candidate will be responsible for identifying, validating, and providing definitive remediation guidance for vulnerabilities across the City’s application portfolio. This role focuses on operating and optimizing security scanning platforms, performing deep-dive manual validation, and serving as a key technical resource and mentor to guide other team members performing assessments.
Responsibilities will include:
- Operate, configure, and optimize enterprise-level static, dynamic, and software composition testing platforms (SAST/DAST/SCA);
- Perform advanced manual testing and exploit reproduction to validate automated findings and uncover complex logic flaws;
- Partner with development teams across city agencies to translate vulnerability findings into actionable, design-level remediation requirements and coding guidance;
- Identify recurring vulnerability patterns and systemic security weaknesses to help shape long-term secure coding practices;
- Serve as the lead technical resource and mentor for internal team members performing scans and learning to execute full security assessments;
- Generate defensible, high-quality technical reports and executive summaries on application vulnerability statuses.
- Handle special projects and initiatives as assigned.
HOURS/SHIFT
Day - Due to the necessary technical duties of this position in a 24/7 operation, candidate may be required to work various shifts such as weekends and/or nights/evenings.
WORK LOCATION
Brooklyn, NY
TO APPLY
* Interested applicants with other civil service titles who meet the preferred requirements should also submit a resume for consideration
Please go to www.cityjobs/jobs/search and search for Job ID #791073
SUBMISSION OF A RESUME IS NOT A GUARANTEE THAT YOU WILL RECEIVE AN INTERVIEW
APPOINTMENTS ARE SUBJECT TO OVERSIGHT APPROVAL
OTI participates in E-Verify
IT SECURITY SPECIALIST - 95622

Qualifications

A baccalaureate degree from an accredited college and four years of satisfactory full-time experience related to projects and policies required by the particular position; or,
Education and/or experience which is equivalent to "1" above.

Additional Information

The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.

Similar Jobs

17 Days Ago
Remote or Hybrid
182K-288K Annually
Senior level
182K-288K Annually
Senior level
Healthtech • Social Impact • Software
Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development.
Top Skills: Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling
One Month Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
140K-165K Annually
Senior level
140K-165K Annually
Senior level
Fintech • Financial Services
Own and evolve the application security program: embed secure SDLC practices, partner with engineering on design and code reviews, manage AppSec tooling (SAST/DAST/ASM/WAF/mobile), harden AWS deployments, integrate security into CI/CD, and lead vulnerability investigation and remediation efforts.
Top Skills: AppdomeAsmAWSCi/Cd PipelinesCloudflare WafCryptographic Key ManagementDastEcsGithub Advanced SecurityGoHadrianIamInvictiMobile Application Security ToolsPythonReact NativeRuby On RailsSastScaSecret ScanningSsl Certificates
25 Days Ago
Remote or Hybrid
USA
160K-250K Annually
Senior level
160K-250K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead application security for products by performing threat modeling, manual secure code reviews, and penetration testing. Collaborate with engineers to remediate defects, build AppSec automation and tooling, secure cloud/containerized applications, and drive bug-bounty responses to harden platform security.
Top Skills: Ai TechnologiesApi SecurityAppsec ToolsAspmAWSAzureBug BountyChromeCspmDastDockerDspmElectronFirefoxGCPGo (Golang)JavaScriptKotlinKubernetesNode.jsPythonReactSastScalaStrideTypescriptWebassembly (Wasm)

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account