Application Security Engineer / Architect (DevSecOps)
Clear Street
- Location
- New York, NY
- Work model
- On-Site
- Level
- Senior
- Salary
- $175k – $210k/yr
- Posted
- 2h ago
Skills
About this role
About Clear Street
Clear Street’s mission is to give every sophisticated investor access to every asset, in every market, through a unified platform built for speed, transparency and scale.
We give our clients the technology, tools, and service once reserved for the largest institutions, rebuilt with modern infrastructure. Our single, cloud-native, end-to-end capital markets platform powers investor growth today and is transforming how they can interact with markets tomorrow.
For more information, visit https://clearstreet.io.
The Team
As an application security engineer in the Security team, you’ll have the opportunity to problem solve, build and influence the security posture of our products and services across the product ecosystem.
In this role specifically, you’ll be responsible for leading application security efforts with our engineers as part of the product development lifecycle at source code and cloud levels within DevSecOps, Vulnerability and other arenas.
Key Responsibilities
● Own security controls within CI/CD pipelines (SAST, DAST, SCA, secrets detection) and maintain pipeline-as-code tooling. ● Work with engineers to identify and remediate vulnerabilities in application source code. ● Manage the vulnerability lifecycle: triage findings from scanners, prioritize by risk, track remediation, and report on trends. ● Lead cloud security efforts, work with engineering teams to enforce cloud security best practices (IAM, network controls, storage security, workload protection). ● Maintain and tune security tooling including SAST/DAST scanners, container security platforms, and dependency analysis tools. ● Build automation and AI based tools to scale Devsecops operations. ● Partner with Infra Engineering teams to define secure infrastructure-as-code (IaC) standards and enforce them via policy-as-code. ● Participate in threat modeling sessions and security design reviews for new features and services. ● Support incident response activities related to application and cloud security events. ● Contribute to security documentation, runbooks, and developer-facing guidance.
Required Qualifications ● 7+ years of experience in a DevSecOps, application security, or cloud security engineering role. ● Hands-on experience with CI/CD platforms (GitHub Actions, GitLab CI, Jenkins, or similar). ● Proficiency with at least one major cloud