xelys jobs xelys jobs

Lead Application Security Engineer

Zeta Global

Full remote Today via WTTJ

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

About the role

Join Zeta Global as a Lead Application Security Engineer, where you'll play a critical role in advancing the company's application and platform security posture. You'll collaborate with various teams to identify risks, design secure patterns, and build automated security capabilities. This position offers significant technical scope, cross-functional visibility, and the opportunity to directly influence the company's security maturity. Key missions: Lead the advancement of Zeta Global's application and platform security posture through AI-native security practices, intelligent automation, and scalable security engineering.. Collaborate with cross-functional teams to identify risks, design secure-by-default patterns, and build automated security capabilities that enable secure innovation at speed.. Drive AI-assisted code security reviews, leverage automated security review tools, and support AI-enabled red team, blue team, and incident response simulations to validate detection, prevention, and response capabilities. Profile: - Experience with cloud platforms such as AWS, GCP, or Azure, and containerized environments such as Docker and Kubernetes - 5+ years of experience in Application Security, DevSecOps, Secure Software Development, or Security Engineering - Experience with modern application frameworks and architectures such as React, Node.js, Django, FastAPI, or similar technologies - Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience - Knowledge of securing APIs, microservices, authentication, and authorization mechanisms such as OAuth2, OIDC, JWT, and service-to-service authentication - Working knowledge of security testing and automation tools such as Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security, or similar tools - Strong understanding of OWASP Top 10, SANS CWE Top 25, secure design principles, and application threat modeling - Familiarity with AI/ML security concepts such as prompt injection, data poisoning, adversarial testing, model integrity, model abuse, and AI supply-chain risks - Experience using AI-assisted or automation-driven approaches to improve security testing, vulnerability analysis, code review, or risk prioritization - Ability to analyze security findings, correlate risk context, and drive practical remediation guidance for engineering teams - Strong collaboration and communication skills with the ability to work across Engineering, Product, QA, DevOps, and Security teams - Experience building or integrating AI-assisted security workflows, security bots, automated triage systems, or risk scoring models - Relevant certifications such as OSCP, GWAPT, CSSLP, cloud security certifications, or AI/ML-specific security certifications - Experience with automation frameworks and scripting for security testing, vulnerability validation, and remediation workflows - Experience with policy-as-code, infrastructure-as-code security, CI/CD security controls, and automated governance

Scraped 7/30/2026