NBCUniversal Media, LLC

Staff Application Security Engineer

NBCUniversal Media, LLC$120K — $145K *
US-AnywhereRemote in New York, NY
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in Application Security, Security Engineering, DevSecOps, or related field.
  • Extensive experience in secure software development and vulnerability management.
  • Hands-on expertise in building security automations and developer tools.
  • Proficient in scripting languages like Python for software engineering tasks.
  • Experience integrating AppSec technologies into developer workflows.
  • Strong problem-solving skills in complex technical environments.
  • Familiarity with AI-assisted development and its security implications.

Responsibilities

  • Design and enhance application security capabilities to support secure software development.
  • Build automations and integrations to improve scalability and reduce manual efforts.
  • Implement secure development practices through golden paths and design patterns.
  • Create scalable security solutions for various software environments and pipelines.
  • Collaborate with Cloud Security on comprehensive security across platforms.
  • Enhance processes for vulnerability management and reporting.
  • Serve as a technical expert in application security and mentor engineering teams.

Benefits

  • Fully remote working opportunity.
  • Medical, dental, and vision insurance.
  • 401(k) retirement plan.
  • Paid leave for work-life balance.
  • Tuition reimbursement for education advancement.
  • Access to various discounts and perks.
Full Job Description
Job Description

Role Overview

NBCUniversal is seeking a Staff Cyber Systems Engineer to build and scale modern application security capabilities across the enterprise.

This hands-on role within Software Security Services combines deep AppSec expertise, software engineering skills, cross-team thought leadership, and experience building automation, integrations, platforms, and developer-facing security capabilities.

The role turns application security strategy into working solutions, including golden paths, remediation automation, secure AI guardrails, and integrated developer workflows.

Although primarily focused on Application Security engineering, this role works closely with Cloud Security, Platform Engineering, and Software Engineering teams at NBCUniversal.

Key Responsibilities

Application Security Engineering
  • Design, build, and improve application security capabilities that support secure software development across NBCUniversal.
  • Build reusable security automations, integrations, APIs, workflows, and developer tools that reduce manual effort and improve scalability.
  • Implement secure-by-default golden paths, paved roads, and engineering patterns that make secure development easier to adopt.
  • Design and implement scalable security solutions spanning source code, open source dependencies, containers, cloud-native applications, CI/CD pipelines, infrastructure as code, developer platforms, and software supply chains.
  • Partner with Cloud Security on capabilities spanning application code, containers, CI/CD, infrastructure as code, cloud platforms, and software supply chain workflows.
  • Improve vulnerability prioritization, triage, remediation, validation, reporting, and speed to remediation.

Secure AI and Agentic Workflow Enablement
  • Build security patterns, guardrails, and reusable implementations that support safe use of AI-assisted development tools and coding assistants.
  • Build capabilities that secure agentic workflows, AI-enabled developer tooling, and machine-assisted software delivery.
  • Use automation and AI-enabled techniques to improve vulnerability triage, remediation planning, developer guidance, and workflow efficiency.
  • Tooling, Automation, and Platform Integration
  • Build integrations between application security platforms, GitHub, CI/CD systems, developer portals, ticketing systems, reporting platforms, and other engineering tools.
  • Create telemetry, dashboards, and reporting pipelines for actionable visibility into application risk, coverage, and remediation progress.

Technical Leadership and Enablement
  • Serve as a senior technical expert for application security engineering, secure software development, software supply chain security, and secure AI development.
  • Partner with architects, platform engineers, cloud security engineers, and development teams to turn security direction into working technical solutions.
  • Mentor engineers and improve the team's engineering practices, automation skills, and technical depth.


Qualifications

Required Qualifications
  • 8+ years of experience in Application Security, Security Engineering, DevSecOps, Software Engineering, or a related technical field.
  • Deep experience with secure software development, application security, vulnerability management, and software supply chain security.
  • Hands-on experience building security automations, integrations, APIs, platforms, developer tooling, or similar engineering solutions.
  • Strong software engineering and scripting skills using Python or similar languages.
  • Hands-on experience integrating AppSec technologies such as SAST, SCA, secrets detection, container security, CI/CD security, and vulnerability management into developer workflows.
  • Ability to solve complex, ambiguous technical problems and influence adoption through implementation, documentation, and collaboration.
  • Familiarity with AI-assisted development, agentic workflows, and related security considerations.

Preferred Qualifications
  • Experience with Snyk, Wiz Code, Github Advanced Security, Checkmarx, Veracode, or similar application security platforms.
  • Experience building secure developer platforms, internal tools, paved roads, golden paths, or reusable engineering services.
  • Experience across AppSec and CloudSec domains, including cloud-native architectures, containers, Kubernetes, infrastructure as code, CI/CD security, CSPM, CNAPP, or related technologies.
  • Experience with software supply chain security, SBOM capabilities, dependency risk workflows, or artifact security processes.
  • Experience using AI to improve vulnerability management, remediation workflows, security operations, or developer productivity.

Additional Requirements:
  • Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee's residence.

This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website. Salary range: $120,000 - $145,000 (bonus eligible)
We are accepting applications for this position on an ongoing basis.

About NBCUniversal Media, LLC

NBCUniversal Media, LLC is a media and entertainment company that operates a variety of businesses, including television networks, film studios, and theme parks. The company was founded in 2004 and is headquartered in New York, New York. NBCUniversal's television networks include NBC, Telemundo, and USA Network, among others. The company's film studios produce and distribute movies under the Universal Pictures brand. NBCUniversal also operates theme parks in the United States and Japan. The company is committed to producing high-quality content and delivering it to audiences around the world.
Learn more about NBCUniversal Media, LLC
Size
35,000 employees
Industry
Founded
1994

Similar Jobs

More Jobs at NBCUniversal Media, LLC

More Information Technology Jobs

Find similar Staff Application Security Engineer jobs: