ForgeApply
Try it free

ForgeApply · Job listing

AppSec Security Engineer

Aresmgmt

New York, NY | Arlington, US$240k – $270konsite

Tailor your resume for this Aresmgmt job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Aresmgmt's site. Free trial, no card required.

About this role

Over the last 20 years, Ares’ success has been driven by our people and our culture. Today, our team is guided by our core values – Collaborative, Responsible, Entrepreneurial, Self-Aware, Trustworthy – and our purpose to be a catalyst for shared prosperity and a better future. Through our recruitment, career development and employee-focused programming, we are committed to fostering a welcoming and inclusive work environment where high-performance talent of diverse backgrounds, experiences, and perspectives can build careers within this exciting and growing industry.

Job Description Job Family: Cybersecurity Engineering Reports to: Cybersecurity Engineering Manager Direct Reports: None POSITION SUMMARY STATEMENT We are seeking an experienced Application Security Engineer to build, mature, and scale our AppSec program. In this role, you will embed directly with our Product and Engineering teams to secure both our third-party SaaS applications and our home-grown applications. You will serve as a trusted security consultant and a hands-on engineer. You will review complex API designs, threat model new features, and build custom security tooling. You will play a critical role in defining security development standards from scratch and automating security controls directly into our CI/CD pipelines. We’re seeking someone who is excited to bring an automation-first mindset and who knows how to balance developer needs with risk-informed pragmatism. You will bridge security, development and operation cultures by translating between development who want speed, security teams who want safety, and operation teams who want stability. We value diverse backgrounds, perspectives, and experiences, and we are committed to building a team where everyone feels they belong. We especially encourage candidates from underrepresented communities in cybersecurity and technology to apply. Our interview process focuses on problem-solving ability, practical skills, and collaborative mindset. DETAILED RESPONSIBILITIES/DUTIES You will help advance our automation‑first engineering strategy by designing and maintaining the foundational systems that enable secure, reliable, and scalable software delivery across the organization. Engineering and Development • Pipeline Integration: Embed SAST, SCA, DAST, container/IaC scanning, and secret detection tools into pipelines for home-grown apps. • Infrastructure as Code: Develop secure IaC patterns using Terraform, Helm, and Kustomize. • Build Security Tooling: Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default • AI-empowered Review Assistance: Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

Architecture & Design Consultation • Security Design & Threat Modeling: Lead security design and threat modeling sessions based on OWASP Top 10 and Mitre & Attack with Product and Engineering teams during early software design phases • API Security Evaluation: Review API designs and integrations to eliminate authentication anti-patterns, token mismanagement, and injection risks. • Cloud & Container Security: Define and validate security controls for Azure and Kubernetes to mitigate application-layer risks.

Collaboration & Governance • Program Maturation: Define AppSec coverage, tooling, and assessment processes from scratch across our application landscape. Own and evolve our application security program including establishing and maintaining SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

• Stakeholder Management: Partner with engineering  teams and stakeholders to remediate vulnerabilities and drive long-term improvements in secure coding practices • Risk Communication: Translate complex security risks into clear, actionable engineering requirements for development teams

SUPERVISORY RESPONSIBILITIES None  Required Qualifications • Proficient in SAST/SCA/DAST, container/IaC scanners, and secret scanning into pipelines • Hands-on with one or more CI/CD stacks (GitHub Actions, GitLab CI, Azure DevOps, Jenkins) • Proficient in Terraform/IaC, Kubernetes, and cloud provider security (Azure preferred) • Significant hands-on application security experience, , including expert knowledge of established standards (OWASP Top 10, API Security Top 10, OWASP LLM Top 10) and how common vulnerability classes manifest in production systems • Strong Threat modeling and security review experience with Product and Engineering teams • Experience building security tooling or automation (scripts, pipelines, libraries) • Familiarity with Azure and Kubernetes security controls as they relate to application-layer risks • Demonstrated experience reviewing API designs and implementations for auth anti-patterns, token mismanagement, injection risks, and sensitive data exposure • Experience building or maturing an AppSec program where coverage, tooling, or process needed to be defined from scratch • Familiarity with OIDC workload identity, artifact registries, and software supply chain controls • Clear communicator who can translate risk into engineering work

Preferred Qualifications • Built policy gates with OPA/Gatekeeper or Kyverno; authored custom policies.

Education • Bachelor’s degree, relevant technical training, or equivalent hands-on experience. We welcome candidates with nontraditional educational paths. • Azure Security Certification is preferred • Advanced certifications in cloud and AI security are a plus.

LEADERSHIP REQUIREMENTS • Strong sense of ownership, accountability, and attention to detail. • Ability to manage competing priorities and deliver results in a dynamic environment while

Salary insight

The midpoint of this range ($255k) is about 54% above the median disclosed salary for New York roles listed on ForgeApply ($166k across 6,609 jobs).

See full Security Engineer salary data for New York

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Aresmgmt role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in New York · More jobs at Aresmgmt · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)