New York, NYremote

Salary
$220,000–$235,000
Posted
Jul 20, 2026
Location
New York, NY
Last confirmed open
Jul 22, 2026

What this job asks for AI summary

A hands-on application security engineering role at a fintech RIA platform, focused on finding and eliminating vulnerabilities across product codebases and cloud infrastructure rather than compliance or audit work. The core challenge is making AI-assisted development — including by non-technical staff — secure by default: building guardrails, setting code hygiene standards, and operating the AppSec tooling pipeline. Suits an experienced security engineer comfortable reading and remediating code who wants to work closely with engineering teams.

Senior level · 5+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time

Must have (10)
application securitysecrets scanningSCACI/CDGitHubAWS or GCPCloudflareOAuthSSOMFA
Nice to have (6)
Google WorkspaceRipplingSlackLLMsCSPMSIEM

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 190 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 80–280

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
CI/CD45%application security40%MFA40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $143,559 (middle half $110,181–$179,574).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

The role is classified as Information Security Analysts (15-1212) rather than Software Developers (15-1252) because its primary mandate is identifying and eliminating security vulnerabilities, building AppSec tooling pipelines, and hardening configurations — security analysis and engineering work — rather than shipping product features. However, the JD places heavy emphasis on software engineering fundamentals and hands-on code remediation, making 15-1252 a genuine runner-up.

AWS and GCP are listed together in the requirements section as 'AWS and/or GCP', indicating either satisfies the requirement; both are captured as required with each listed as an alternative for the other.

Google Workspace, Rippling, and Slack appear in the responsibilities narrative as examples of SaaS platforms to secure, not as explicit candidate gates — marked preferred accordingly.

SSO and MFA appear in the responsibilities section ('Help establish conditional access and identity-layer controls… SSO, phishing-resistant MFA') rather than the Must Have block; however, they are closely tied to the required 'identity-layer controls' work and are captured as required given the firm language in the responsibilities. This is a borderline call.

LLMs, CSPM, SIEM, Rippling, Slack, and Google Workspace all appear under 'Nice to have' or in narrative context and are marked preferred.

No compensation figures are stated in the posting.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗