Application Security Engineer / Architect (DevSecOps)
Clear Street · New York, NY
$175,000–$210,000from the description
Jul 22, 2026
New York, NY
Jul 23, 2026
What this job asks for AI summary
An application security engineering role focused on embedding security throughout the software development lifecycle. Day-to-day work spans owning CI/CD pipeline security controls (SAST, DAST, SCA, secrets detection), managing vulnerability triage and remediation, enforcing cloud security practices, and building automation tooling. The role suits an experienced practitioner comfortable working across source code, cloud infrastructure, and container environments alongside engineering teams.
Senior level · 7+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 25 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 10–50
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $143,559 (middle half $110,181–$179,574). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (4)
SOC classification is a genuine judgment call: the role is titled 'Application Security Engineer' and is primarily security-analysis work (SAST/DAST/SCA, vulnerability management, threat modeling, cloud security), pointing to 15-1212. However, it also involves substantial software-development activity — building automation and AI-based tools, maintaining pipeline-as-code, and enforcing policy-as-code — which could support 15-1252. 15-1212 was chosen as the primary because security analysis and posture ownership are the stated core mission.
The posting names SAST, DAST, and SCA as distinct capability areas across both the responsibilities and requirements sections. SAST is listed as a required gate (with named tools); DAST and SCA appear in the responsibilities narrative and are captured as preferred since they are not explicitly called out as separate required qualifications.
IaC tools (Terraform, CloudFormation, Pulumi) and policy frameworks (OPA/Rego, Checkov) are listed together under a single required qualification bullet; each is captured individually. OPA is listed with Checkov as alternatives since the JD frames them as a policy-framework category ('or similar' is implied by the grouping).
The role requires 4 days per week in-office and is tagged #LI-Hybrid; remote=false reflects that it is not fully remote. Location is inferred as New York City based on Clear Street's known headquarters; no city is explicitly stated in the posting.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.