Clear Street · New York, NY

Salary
$175,000–$210,000from the description
Posted
Jul 22, 2026
Location
New York, NY
Last confirmed open
Jul 23, 2026

What this job asks for AI summary

An application security engineering role focused on embedding security throughout the software development lifecycle. Day-to-day work spans owning CI/CD pipeline security controls (SAST, DAST, SCA, secrets detection), managing vulnerability triage and remediation, enforcing cloud security practices, and building automation tooling. The role suits an experienced practitioner comfortable working across source code, cloud infrastructure, and container environments alongside engineering teams.

Senior level · 7+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time

Must have (9)
CI/CDGitHub Actions, Gitlab Ci or JenkinsAWS, Azure or GCPSASTSemgrep, Snyk, Checkmarx or VeracodeKubernetesPython or Shell ScriptingTerraform or PulumiOPA or Checkov
Nice to have (1)
DAST

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 25 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 10–50

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
Semgrep4%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Python51%CI/CD45%GitHub Actions40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $143,559 (middle half $110,181–$179,574). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (4)

SOC classification is a genuine judgment call: the role is titled 'Application Security Engineer' and is primarily security-analysis work (SAST/DAST/SCA, vulnerability management, threat modeling, cloud security), pointing to 15-1212. However, it also involves substantial software-development activity — building automation and AI-based tools, maintaining pipeline-as-code, and enforcing policy-as-code — which could support 15-1252. 15-1212 was chosen as the primary because security analysis and posture ownership are the stated core mission.

The posting names SAST, DAST, and SCA as distinct capability areas across both the responsibilities and requirements sections. SAST is listed as a required gate (with named tools); DAST and SCA appear in the responsibilities narrative and are captured as preferred since they are not explicitly called out as separate required qualifications.

IaC tools (Terraform, CloudFormation, Pulumi) and policy frameworks (OPA/Rego, Checkov) are listed together under a single required qualification bullet; each is captured individually. OPA is listed with Checkov as alternatives since the JD frames them as a policy-framework category ('or similar' is implied by the grouping).

The role requires 4 days per week in-office and is tagged #LI-Hybrid; remote=false reflects that it is not fully remote. Location is inferred as New York City based on Clear Street's known headquarters; no city is explicitly stated in the posting.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗