ForgeApply · Job listing
Sr Application Security Engineer
Thetradedesk
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
The Trade Desk is a global technology company and the world’s leading independent platform for digital advertising, with nearly 4,000 employees across more than 30 offices. Our technology helps advertisers reach the right audiences across the open internet — from streaming TV and podcasts to mobile apps, news, and more.
Advertising powers the content people love. By making it more transparent, effective, and responsible, we help support trusted journalism, quality entertainment, and creators worldwide. The world’s brands and agencies rely on us to reach their customers and grow their businesses responsibly.
The scale of our platform brings unique technical challenges — from processing massive datasets in real time to building systems that operate reliably on a global scale. When you work here, your impact is worldwide. We welcome diverse perspectives, encourage curiosity, and build teams that learn from one another. If you’re driven to solve meaningful challenges, we’d love to meet you.
What we do:
We are looking for a Senior Application Security Engineer to join our Cybersecurity Department. This person will complement and extend the application security capabilities we have built — with significant opportunity to make an immediate, sizable impact. You will own tooling, lead threat modeling, and harden the application security program across a platform used daily by the world's largest brands. This is not a steady-state role: there is meaningful work to do, and the right person will see it and run toward it.
The right candidate brings deep application security expertise, strong software development instincts, and a genuine bias to action. You are someone who builds things — not just findings documents. You think about security from the perspective of the engineers you partner with and the customers whose trust is at stake, and you communicate in ways that make both groups more effective.
Beyond the technical experience, we are looking for someone with the qualities that make a security engineer effective in a collaborative, fast-moving engineering culture. You are curious about how systems work and how they break. You pair that curiosity with ownership and follow-through. You communicate clearly, give and receive feedback well, and approach the engineers you work with as partners — not gatekeepers. Security is a team sport, and you bring that mindset every day.
What you'll do:
• Extend and own scalable AppSec tooling across four core areas: SAST/DAST pipeline integration, vulnerability management, threat modeling frameworks, and security posture— building on existing foundations and closing meaningful gaps.
• Validate findings end-to-end: triage and reproduce scanner output to separate signal from noise, then contextualize risk so engineering teams understand exactly what to fix, why it matters, and what the customer impact would be if exploited.
• Review and assess new features, APIs, and architectural changes; conduct security-focused code reviews (C#, Java, JavaScript, or similar) and application-layer penetration tests.
• Write production-quality security automation and tooling — this role ships code alongside security guidance.
• Assess and help secure AI/ML systems — including inference APIs, LLM integrations, and GenAI attack surfaces such as prompt injection and model exfiltration — and build AI-augmented tooling to scale the team's output.
• Drive security culture through direct engineering partnership: advising on secure-by-design patterns early in the development process, raising the security floor across hundreds of engineers, and keeping customer trust at the center of every recommendation.
• Participate in and drive security governance-first frameworks to include developing and publishing standards, guidelines, procedures, secure baselines, and policies.
Who you are:
• BS degree or equivalent years of experience in related field
• 6-8+ years in application security with a track record of building tooling and automation, not just operating it.
• Active software development experience — you write clean, production-ready code in at least one of: C#, Java, Python, Go, or JavaScript. Candidates who currently or recently ship code are meaningfully better positioned for this role.
• Hands-on experience with SAST, DAST, SCA, and secrets management tooling, including configuration, tuning, and CI/CD integration (GitHub Actions, GitLab, Jenkins, ArgoCD, or similar).
• Practical threat modeling experience (STRIDE, PASTA, or equivalent) — producing engineering-useful outputs, not just risk documentation.
• Experience with vulnerability management workflows: aggregation, triage, risk-based prioritization, and driving remediation at scale.
• Working knowledge of Kubernetes and container security (Docker, Helm, Istio) and cloud security fundamentals across at least one major platform (AWS, GCP, or Azure).
• Experience in AI/ML security — securing AI pipelines, assessing LLM integrations, understanding GenAI attack surfaces, or building AI-assisted security tooling. This is a meaningful differentiator.
• Strong written and verbal communication skills — able to translate technical risk into terms that resonate with engineering teams, product leadership, and the broader customer-first mindset that drives decisions at The Trade Desk.
• Certifications such as OSWE, GWAPT, CSSLP, OSCP, or cloud security certifications (AWS, GCP, or Azure) are a plus.
• Experience in ad tech, large-scale SaaS, or other high-throughput consumer or enterprise platforms is a plus. #LI-TP1
The Trade Desk does not accept unsolicited resumes from search firm recruiters. Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired; such resumes will be deemed the sole property of The Trade Desk. The Trade Desk is an equal opportunity employer. All aspects of employment will be based on merit, competence, performance, and business needs. We do
Salary insight
This posting doesn't disclose pay. Across 688 Seattle jobs with disclosed salaries on ForgeApply, the median is $170k.
See full Security Engineer salary data for Seattle →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Ready to apply to Thetradedesk?
Apply in about a minuteSimilar jobs
- Senior Application Security Engineer — Tatari · New York, New York, United States
- Senior Application Security Engineer — Monarchmoney · Remote
- Senior Application Security Engineer — Gemini · New York, New York; Miami, Florida; Remote (USA)
- Senior Application Security Engineer — Consensys · Remote
- Senior Application Security Engineer — Apolloio · Remote
- Senior Application Security Engineer — Trueanomalyinc · Denver, CO or Long Beach, CA or SF Bay Area, CA
- Senior Application Security Engineer — Temporaltechnologies · Remote
- Senior Application Security Engineer — Tatari · San Francisco, California, United States
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Seattle · More jobs at Thetradedesk · Browse all jobs