Application Security Engineer II
The Trade Desk is a global technology company and the world’s leading independent platform for digital advertising, with nearly 4,000 employees across more than 30 offices. Our technology helps advertisers reach the right audiences across the open internet — from streaming TV and podcasts to mobile apps, news, and more.
Advertising powers the content people love. By making it more transparent, effective, and responsible, we help support trusted journalism, quality entertainment, and creators worldwide. The world’s brands and agencies rely on us to reach their customers and grow their businesses responsibly.
The scale of our platform brings unique technical challenges — from processing massive datasets in real time to building systems that operate reliably on a global scale. When you work here, your impact is worldwide. We welcome diverse perspectives, encourage curiosity, and build teams that learn from one another. If you’re driven to solve meaningful challenges, we’d love to meet you.
What we do:
We are looking for an Application Security Engineer to join our Cybersecurity Department. This role is ideal for a software engineer who enjoys building tools, solving complex technical problems, and wants to grow into a career in application security. You'll work alongside experienced security engineers to help improve the security of our applications, build developer-focused security tooling, and contribute to protecting a platform used daily by many of the world's largest brands.
As an Application Security Engineer, you'll partner closely with engineering teams to improve the security of the products they build. You'll investigate vulnerabilities, contribute to security tooling and automation, participate in design and code reviews, and help improve the developer experience through practical, security-focused engineering. As software development continues to evolve with AI-assisted engineering, you'll have the opportunity to help shape the tools, workflows, and practices that enable developers to move quickly without compromising security.
We're looking for someone who is curious, collaborative, and enjoys building things. You don't need to be an application security expert on day one; we're looking for a strong engineer with an interest in security and the motivation to learn. If you enjoy understanding how systems work, solving difficult problems, and creating tools that make other engineers more effective, you'll find plenty of opportunities to grow here. We believe security is most successful when it's built in partnership with engineering, and we're looking for someone who shares that mindset
What you'll do:
- Build tools, automations, and integrations that help engineers develop more secure software with less friction.
- Partner with software engineering teams to identify security issues, understand root causes, and implement practical solutions.
- Develop and improve integrations with application security tooling, including SAST, DAST, SCA, and CI/CD pipelines.
- Investigate security findings from internal testing, automated tooling, and our bug bounty program, validating results and helping engineering teams prioritize and remediate vulnerabilities.
- Participate in design reviews and code reviews, learning how to identify security risks early in the software development lifecycle.
- Write production-quality code that improves the capabilities and scalability of the Application Security program.
- Help evaluate emerging development technologies, including AI-assisted software development, and contribute to secure engineering practices.
- Learn from experienced Application Security engineers while growing your expertise in secure software design, application security, and developer enablement.
Who you are:
- BS degree in Computer Science, Software Engineering, Cybersecurity, or a related technical field, or equivalent practical experience.
- 4+ years of professional software development experience, or equivalent experience through internships, open-source contributions, or personal projects.
- Experience developing software in one or more modern programming languages such as C#, Java, Python, Go, or JavaScript.
- Passionate about writing clean, maintainable, and well-tested code, with an interest in building secure software.
- Curious about application security and motivated to grow your expertise in secure software design, common software vulnerabilities, and modern attack techniques.
- Familiar with secure software development fundamentals such as authentication, authorization, input validation, cryptography, and common web application vulnerabilities (e.g., OWASP Top 10).
- Enjoy building tools, automations, and developer workflows that improve engineering productivity while making secure development the easiest path.
- Interested in the future of software engineering, including AI-assisted development, and excited about using automation and developer tooling to improve security outcomes.
- Comfortable learning new technologies, reading unfamiliar codebases, and solving complex technical problems.
- Experience with modern software development practices, including Git, code reviews, automated testing, and CI/CD pipelines.
- Strong analytical, troubleshooting, and communication skills with the ability to collaborate effectively across engineering teams.
- Demonstrated curiosity and continuous learning, whether through side projects, open-source contributions, security labs, Capture the Flag (CTF) competitions, or other technical exploration.
Nice to have
- Exposure to application security tools such as SAST, DAST, Software Composition Analysis (SCA), secrets scanning, or dependency management.
- Familiarity with threat modeling, secure design reviews, or vulnerability remediation.
- Experience developing or integrating developer tooling, internal platforms, IDE extensions, GitHub Actions, CI/CD automations, or similar engineering productivity tools.
- Experience with cloud platforms (AWS, Azure, or GCP), containers, Kubernetes, or infrastructure as code.
- Exposure to AI-assisted development tools (such as GitHub Copilot, Cursor, Claude Code, or similar) and an interest in improving how security integrates into AI-enabled engineering workflows.
- Experience building AI-powered developer tools, security automations, or evaluating the security of AI-enabled applications is a plus.
- Security coursework or certifications (Security+, eJPT, CSSLP Associate, AWS/Azure/GCP certifications, or similar) are a plus.
- Experience in ad tech, SaaS, or other large-scale distributed systems is a plus. #LI-TP1
The Trade Desk does not accept unsolicited resumes from search firm recruiters. Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired; such resumes will be deemed the sole property of The Trade Desk. The Trade Desk is an equal opportunity employer. All aspects of employment will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.
[LA JOBS ONLY]The Trade Desk will consider qualified applicants with criminal histories for employment in a manner consistent with the requirements of the Los Angeles Fair Chance Initiative for Hiring, Ordinance No. 184652.
[SF JOBS ONLY]Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
In accordance with various US state laws, the range provided is the Trade Desk's reasonable estimate of the base compensation for this role. The actual amount may differ based on non-discriminatory factors such as experience, knowledge, skills, and location. All employees may be eligible to become The Trade Desk shareholders through eligibility for stock-based compensation grants, which are awarded to employees based on company and individual performance. The Trade Desk also offers other compensation depending on the role such as variable compensation-based incentives and commissions. Plus, expected benefits for this role include comprehensive healthcare (medical, dental, and vision) with premiums paid in full for employees and dependents, retirement benefits such as a 401k plan and company match, short and long-term disability coverage, basic life insurance, well-being benefits, reimbursement for certain tuition expenses, parental leave, sick time of 1 hour per 30 hours worked, vacation time for full-time employees up to 120 hours thru the first year and 160 hours thereafter, and around 13 paid holidays per year. Employees can also purchase The Trade Desk stock at a discount through The Trade Desk’s Employee Stock Purchase Plan.
The Trade Desk also offers a competitive benefits package. Click here to learn more.
Note: Interns are not eligible for variable incentive awards such as stock-based compensation, retirement plan, vacation, tuition reimbursement or parental leave
At the Trade Desk, Base Salary is one part of our competitive total compensation and benefits package and is determined using a salary range. The base salary range for this role is $103,200—$189,200 USDAs an Equal Opportunity Employer, The Trade Desk is committed to creating an inclusive hiring experience where everyone has the opportunity to thrive.
Please reach out to us at accommodations@thetradedesk.com to request an accommodation or discuss any accessibility needs you may require to access our Company Website or navigate any part of the hiring process.
When you contact us, please include your preferred contact details and specify the nature of your accommodation request or questions. Any information you share will be handled confidentially and will not impact our hiring decisions.