The Trade Desk

Sr Application Security Engineer

The Trade Desk$113K — $208K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • BS degree or equivalent experience in related field
  • 6-8+ years in application security with a focus on building tooling and automation
  • Active software development experience in languages such as C#, Java, Python, Go, or JavaScript
  • Hands-on experience with SAST, DAST, SCA, and secrets management tooling
  • Practical threat modeling experience producing engineering-useful outputs
  • Experience with vulnerability management workflows at scale
  • Working knowledge of Kubernetes, container security, and cloud security fundamentals
  • Experience in AI/ML security is a significant differentiator.

Responsibilities

  • Extend and own scalable AppSec tooling across multiple core areas
  • Validate findings end-to-end, contextualizing risks for engineering teams
  • Review and assess new features and conduct security-focused code reviews
  • Write production-quality security automation and tooling, shipping code alongside guidance
  • Assess security in AI/ML systems and build AI-augmented tooling
  • Drive security culture through direct partnerships with engineering teams
  • Participate in developing security governance frameworks and standards.

Benefits

  • Comprehensive healthcare coverage for employees and dependents
  • 401k plan with company matching
  • Short and long-term disability coverage
  • Reimbursement for certain tuition expenses
  • Parental leave and sick time
  • Generous vacation policy up to 160 hours
  • 13 paid holidays per year
  • Employee Stock Purchase Plan with stock at a discount.
Full Job Description
What we do:

We are looking for a Senior Application Security Engineer to join our Cybersecurity Department. This person will complement and extend the application security capabilities we have built - with significant opportunity to make an immediate, sizable impact. You will own tooling, lead threat modeling, and harden the application security program across a platform used daily by the world's largest brands. This is not a steady-state role: there is meaningful work to do, and the right person will see it and run toward it.

The right candidate brings deep application security expertise, strong software development instincts, and a genuine bias to action. You are someone who builds things - not just findings documents. You think about security from the perspective of the engineers you partner with and the customers whose trust is at stake, and you communicate in ways that make both groups more effective.

Beyond the technical experience, we are looking for someone with the qualities that make a security engineer effective in a collaborative, fast-moving engineering culture. You are curious about how systems work and how they break. You pair that curiosity with ownership and follow-through. You communicate clearly, give and receive feedback well, and approach the engineers you work with as partners - not gatekeepers. Security is a team sport, and you bring that mindset every day.

What you'll do:
  • Extend and own scalable AppSec tooling across four core areas: SAST/DAST pipeline integration, vulnerability management, threat modeling frameworks, and security posture- building on existing foundations and closing meaningful gaps.
  • Validate findings end-to-end: triage and reproduce scanner output to separate signal from noise, then contextualize risk so engineering teams understand exactly what to fix, why it matters, and what the customer impact would be if exploited.
  • Review and assess new features, APIs, and architectural changes; conduct security-focused code reviews (C#, Java, JavaScript, or similar) and application-layer penetration tests.
  • Write production-quality security automation and tooling - this role ships code alongside security guidance.
  • Assess and help secure AI/ML systems - including inference APIs, LLM integrations, and GenAI attack surfaces such as prompt injection and model exfiltration - and build AI-augmented tooling to scale the team's output.
  • Drive security culture through direct engineering partnership: advising on secure-by-design patterns early in the development process, raising the security floor across hundreds of engineers, and keeping customer trust at the center of every recommendation.
  • Participate in and drive security governance-first frameworks to include developing and publishing standards, guidelines, procedures, secure baselines, and policies.

Who you are:
  • BS degree or equivalent years of experience in related field
  • 6-8+ years in application security with a track record of building tooling and automation, not just operating it.
  • Active software development experience - you write clean, production-ready code in at least one of: C#, Java, Python, Go, or JavaScript. Candidates who currently or recently ship code are meaningfully better positioned for this role.
  • Hands-on experience with SAST, DAST, SCA, and secrets management tooling, including configuration, tuning, and CI/CD integration (GitHub Actions, GitLab, Jenkins, ArgoCD, or similar).
  • Practical threat modeling experience (STRIDE, PASTA, or equivalent) - producing engineering-useful outputs, not just risk documentation.
  • Experience with vulnerability management workflows: aggregation, triage, risk-based prioritization, and driving remediation at scale.
  • Working knowledge of Kubernetes and container security (Docker, Helm, Istio) and cloud security fundamentals across at least one major platform (AWS, GCP, or Azure).
  • Experience in AI/ML security - securing AI pipelines, assessing LLM integrations, understanding GenAI attack surfaces, or building AI-assisted security tooling. This is a meaningful differentiator.
  • Strong written and verbal communication skills - able to translate technical risk into terms that resonate with engineering teams, product leadership, and the broader customer-first mindset that drives decisions at The Trade Desk.
  • Certifications such as OSWE, GWAPT, CSSLP, OSCP, or cloud security certifications (AWS, GCP, or Azure) are a plus.
  • Experience in ad tech, large-scale SaaS, or other high-throughput consumer or enterprise platforms is a plus. #LI-TP1

In accordance with various US state laws, the range provided is the Trade Desk's reasonable estimate of the base compensation for this role. The actual amount may differ based on non-discriminatory factors such as experience, knowledge, skills, and location. All employees may be eligible to become The Trade Desk shareholders through eligibility for stock-based compensation grants, which are awarded to employees based on company and individual performance. The Trade Desk also offers other compensation depending on the role such as variable compensation-based incentives and commissions. Plus, expected benefits for this role include comprehensive healthcare (medical, dental, and vision) with premiums paid in full for employees and dependents, retirement benefits such as a 401k plan and company match, short and long-term disability coverage, basic life insurance, well-being benefits, reimbursement for certain tuition expenses, parental leave, sick time of 1 hour per 30 hours worked, vacation time for full-time employees up to 120 hours thru the first year and 160 hours thereafter, and around 13 paid holidays per year. Employees can also purchase The Trade Desk stock at a discount through The Trade Desk's Employee Stock Purchase Plan.

The Trade Desk also offers a competitive benefits package. Click here to learn more.

Note: Interns are not eligible for variable incentive awards such as stock-based compensation, retirement plan, vacation, tuition reimbursement or parental leave

At the Trade Desk, Base Salary is one part of our competitive total compensation and benefits package and is determined using a salary range. The base salary range for this role is

$113,500-$208,100 USD

About The Trade Desk

The Trade Desk is a global advertising technology company that provides a self-service platform for buyers of digital advertising. The company was founded in 2009 and is headquartered in Ventura, California. The Trade Desk's mission is to empower buyers of advertising with the tools they need to reach their target audiences in a more efficient and effective way. The company's platform allows buyers to manage their advertising campaigns across multiple channels, including display, video, mobile, and social. The Trade Desk's technology uses advanced algorithms and machine learning to optimize ad campaigns in real-time, ensuring that buyers get the best possible return on their investment.
Learn more about The Trade Desk
Size
1,967 employees
Market Cap
$21.4 billion
Industry
Net Income
$242.3 million
Founded
2009
5 Year Trend
+42.6%
Revenue
$836 million
NASDAQ

Similar Jobs

More Jobs at The Trade Desk

More Information Technology Jobs

Find similar Sr Application Security Engineer jobs: