--- title: 'Senior Application Security Engineer at TripleLift' canonical: 'https://feeny.ai/job/senior-application-security-engineer-triplelift-london-england-3nrv1nesgrxt' type: 'job' last_seen: '2026-09-07' --- # Senior Application Security Engineer at TripleLift - **Company:** TripleLift - **Location:** London England, United Kingdom - **Posted:** 2026-08-12 - **Last confirmed live:** 2026-09-07 - **Apply:** https://triplelift.com/careers-posts/?gh_jid=8126001 ## Job description ## About TripleLift We're TripleLift, an advertising platform on a mission to elevate digital advertising through beautiful creative, quality publishers, actionable data and smart targeting. Through over 1 trillion monthly ad transactions, we help publishers and platforms monetize their businesses. Our technology is where the world's leading brands find audiences across online video, connected television, display and native ads. Brand and enterprise customers choose us because of our innovative solutions, premium formats, and supportive experts dedicated to maximizing their performance. As part of the Vista Equity Partners portfolio, we are NMSDC certified, qualify for diverse spending goals and are committed to economic inclusion. Find out how TripleLift raises up the programmatic ecosystem at[triplelift.com](https://c212.net/c/link/?t=0&l=en&o=3665616-1&h=429054733&u=http%3A%2F%2Ftriplelift.com%2F&a=%C2%A0triplelift.com). ## Overview The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift's Engineering and Security organization, directly influencing how we protect our advertising platforms and the trust our publishers and advertisers place in us. In this position, you will partner closely with Engineering, Platform, Cloud Infrastructure, and Security teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security, ensuring security is embedded into how we design, build, deploy, and operate our products.This is an exciting opportunity for someone who wants to build and scale an application security program at a company operating at the center of a rapidly evolving, high-stakes ad-tech landscape, while contributing meaningfully to the long-term security posture and resilience of the organization. ## Responsibilities - Play a critical role in building and maintaining a global security compliance program based on NIST CSF. - Scale application security by developing automated security testing utilizing enterprise SAST, DAST, and code-review tools. - Champion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities. - Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations themselves. - Administer and drive adoption of GitHub Advanced Security (GHAS) : code scanning, secret scanning, and dependency review across engineering repositories. - Participate in threat modeling and design/architecture spec reviews to identify and mitigate security risks early in the SDLC. - Coordinate with stakeholders to develop and implement a vulnerability management program and to perform threat-hunting activities. - Own and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate findings from third-party pentest engagements. - Monitor and respond to application-layer security threats like API abuses, business logic flaws, and common web vulnerabilities. - Collaborate with product and engineering teams to ensure security is a key consideration in software design and architecture. - Enhance application security posture by working with cross-functional teams to implement proper authentication, authorization, and data protection mechanisms. - Enhance and facilitate security incident handling activities. - Evangelize security best practices and provide education and awareness to company employees. Develop and implement secure coding guidelines and conduct secure development training for engineers. - Evaluate and continuously improve the maturity of the security program through the deployment and management of various security tools and processes. Education & Requirements - 5 years minimum of experience in application security, secure software development, security engineering, or a similar role. - Strong understanding of secure coding practices and ability to guide developers on remediation strategies. - Experience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review. - Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode). - Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows. - Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure. - Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security). - Ability to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and services. - Experience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go). - Understanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similar. - Strong understanding of AWS security services and controls (IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, with the ability to deploy security tools within them. - Takes ownership of projects, works independently with minimal oversight, and delivers results in a fast-paced environment while balancing multiple priorities. - Continuously learns, adapts, and values correctness, efficiency, and constructive feedback. Preferred: - Experience in the ad-tech / programmatic advertising industry, or another high-scale, real-time environment. - Preferred: Familiarity with using AI/LLM-based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automation. - Holds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc. Life at TripleLift At TripleLift, we’re a team of great people who like who they work with and want to make everyone around them better. This means being positive, collaborative, and compassionate. We hustle harder than the competition and are continuously innovating. Learn more about TripleLift and our culture by visiting our [LinkedIn Life page.](https://www.linkedin.com/company/triplelift/life/tripleliftdei/?viewAsMember=true) Establishing People, Culture and Community Initiatives At TripleLift, we are committed to building a culture where people feel connected, supported, and empowered to do their best work. We invest in our people and foster a workplace that encourages curiosity, celebrates shared values, and promotes meaningful connections across teams and communities. We want to ensure the best talent of every background, viewpoint, and experience has an opportunity to be hired, belong, and develop at TripleLift. Through our People, Culture, and Community initiatives, we aim to create an environment where everyone can thrive and feel a true sense of belonging. Privacy Policy Please see our Privacy Policies on our [TripleLift](https://triplelift.com/privacy/) and [1plusX](https://www.1plusx.com/privacy-policy/) websites. TripleLift does not accept unsolicited resumes from any type of recruitment search firm. Any resume submitted in the absence of a signed agreement will become the property of TripleLift and no fee shall be due. ## About TripleLift ## Company Overview - **One-liner**: TripleLift is a creative supply-side platform (SSP) that orchestrates data, creative, and supply to help brands move from buying impressions to engineering measurable advertising impact. - **Entity Type**: Private (funding stage not publicly disclosed) - **Headquarters**: New York, NY, USA - **Founded**: 2012 - **Founders**: Not publicly available (founder names are not listed on the company’s official site or in the provided sources) ## Core Business - **Primary industry**: Advertising Technology (AdTech) - **Target customers**: B2B – publishers (supply side) and brands/advertisers (demand side) - **Mission or purpose statement**: “Impact by Design” – every impression has the potential to deliver impact when creative, data, supply, and measurement are designed intentionally to work together from the start. ## Products & Services - **Creative SSP**: The core platform that connects data, creative, and supply into one coordinated system for omnichannel advertising. - **TL Spark**: An intelligence layer that connects every signal across campaigns and continuously improves advertising performance. - **Supply & Curation**: Tools for publishers to unlock the full impact of their inventory while elevating the user experience. - **Measurement**: Solutions that track attention, perception, and outcomes – including brand lift in CTV, purchase intent in retail media, and ad recall benchmarks. - **Optimization**: Features that reduce waste (50%+ reduction claimed) and improve conversion rates. ## Market Standing - **Valuation/Market Cap**: Not disclosed - **Key Metric**: Annual revenue not publicly available; total funding not disclosed - **Notable Investors/Partners**: Not listed in provided sources - **Growth Signals**: - 350+ employees (335 according to Built In) - 6 global offices across 4 continents - Reported performance metrics: 3.6x ROI (Forrester TEI study), 272% increase in purchase intent for retail media, 7.9x brand lift in CTV, 50%+ waste reduction - Strong presence in native advertising, now evolved to full omnichannel coverage ## Competitive Advantages - **Creative-first approach**: Built on innovative ad formats starting with native, now spanning all channels. - **Orchestration layer**: TL Spark coordinates creative, curation, audience, and measurement as one system rather than siloed point solutions. - **First-party publisher data focus**: Future-forward data strategy built around publisher first-party data, making it privacy-compliant and scalable. - **Proven results**: Case studies and third-party studies (Forrester) show significant lifts in attention, brand perception, and conversion. ## Strategic Focus - **Orchestration era**: Moving beyond simple impression delivery to engineering impact through coordinated systems. - **Retail media & CTV**: Key growth areas where TripleLift claims strong performance (purchase intent, brand lift). - **Continuous innovation**: Emphasis on learning and adapting to a dynamic ecosystem, with a founder’s mentality across the organization. ## Why Work Here - **Culture & Values**: Core values include “Win as a Team,” “Learn & Grow,” “Embrace & Drive Change,” “Operate with a Founder’s Mentality,” and “Own Your Piece, Know the Puzzle.” - **Learning & Development**: Annual learning stipend, coaching/mentoring opportunities, internal rotation programs. - **Work-Life Balance**: Paid time off, leave options, and a 5-year sabbatical (1 month). - **Wellness**: Headspace subscription, mental wellbeing support, physical care, financial advice, paid parental leave. - **Health Benefits**: Competitive medical, dental, vision; company-paid short-term and long-term disability. - **Work Environment**: Hybrid workspace (combination of remote and on-site), with in-office locations in New York and other global offices. - **Community**: Employee Resource Groups (ERGs), monthly Lift Lab sessions, events, and company-wide Pulse meetings to stay connected. - **Tenure Celebrations**: 5-year anniversary includes a 1-month sabbatical. ## Sources 1. [triplelift.com](https://triplelift.com/) 2. [triplelift.com/careers/](https://triplelift.com/careers/) 3. [triplelift.com/about/](https://triplelift.com/about/) 4. [triplelift.com/careers-posts/](https://triplelift.com/careers-posts/) 5. [builtin.com/company/triplelift](https://builtin.com/company/triplelift) ## Other roles at TripleLift - [Team Lead, Employee Experience](https://feeny.ai/job/team-lead-employee-experience-triplelift-new-york-new-york-spg3qstctjkh) — New York New York, United States - [Senior Software Engineer](https://feeny.ai/job/senior-software-engineer-triplelift-zurich-njhtyzx9nc5j) — Zurich, Switzerland - [Cloud Engineer](https://feeny.ai/job/cloud-engineer-triplelift-new-york-new-york-z5m870hrrm5h) — New York New York, United States - [Product Marketing Director](https://feeny.ai/job/product-marketing-director-triplelift-new-york-new-york-xvhh796jqatv) — New York New York, United States - [Senior Staff Engineer](https://feeny.ai/job/senior-staff-engineer-triplelift-new-york-new-york-z98y7hpwtpw2) — New York New York, United States - [VP, DSP Partnerships](https://feeny.ai/job/vp-dsp-partnerships-triplelift-new-york-new-york-5mrgvqp2g36a) — New York New York, United States - [Senior Application Security Engineer](https://feeny.ai/job/senior-application-security-engineer-triplelift-toronto-ck4naddetmnq) — Toronto, Canada - [Trading Specialist](https://feeny.ai/job/trading-specialist-triplelift-chicago-il-evxe7m9qwn54) — Chicago IL, United States - [Trading Specialist](https://feeny.ai/job/trading-specialist-triplelift-toronto-5j2m1ctbf4ps) — Toronto, Canada - [Partnerships & Alliances Director](https://feeny.ai/job/partnerships-alliances-director-triplelift-chicago-il-8nhnypnpv7r7) — Chicago IL, United States