{"schemaVersion":"jobsearcher.job.v1","id":"698b4f3cb2d8fe9714ae4780","url":"https://jobsearcher.com/jobs/698b4f3cb2d8fe9714ae4780","canonicalUrl":"https://jobsearcher.com/jobs/698b4f3cb2d8fe9714ae4780","title":"Lead Application Security Engineer","description":"WHO WE ARE\nZeta Global (NYSE: ZETA) is the AI-Powered Marketing Cloud that leverages advanced artificial intelligence (AI) and trillions of consumer signals to make it easier for marketers to acquire, grow, and retain customers more efficiently. Through the Zeta Marketing Platform (ZMP), our vision is to make sophisticated marketing simple by unifying identity, intelligence, and omnichannel activation into a single platform – powered by one of the industry's largest proprietary databases and AI. Our enterprise customers across multiple verticals are empowered to personalize experiences with consumers at an individual level across every channel, delivering better results for marketing programs. Zeta was founded in 2007 by David A. Steinberg and John Sculley and is headquartered in New York City with offices around the world. To learn more, go to www.zetaglobal.com.\nAbout the Role\nWe're seeking a Lead Application Security Engineer to help advance Zeta Global's application and platform security posture through AI-native security practices, intelligent automation, and scalable security engineering. You'll play a critical role in embedding security throughout the software development lifecycle by using AI-driven tools, automated controls, and data-informed risk prioritization to ensure our systems, applications, and AI-powered platforms are built securely from the ground up.\nZeta operates at massive scale, powering billions of consumer profiles and petabytes of data across real-time, AI-powered marketing platforms. In this role, you'll collaborate with Engineering, Product, QA, DevOps, and AI platform teams to identify risks, design secure-by-default patterns, and build automated security capabilities that enable secure innovation at speed.\nThis position offers significant technical scope, cross-functional visibility, and the opportunity to directly influence the company's security maturity through AI-enabled threat modeling, automated validation, intelligent vulnerability management, and proactive defense.\nKey Responsibilities\nAI-Driven Threat Modeling & Security Validation\nUse AI-assisted threat modeling capabilities to identify application, platform, API, cloud, data, and AI/ML security risks early in the design and development process.\nLeverage automated security review tools to evaluate architecture, design documents, code changes, APIs, and data flows for security gaps and control weaknesses.\nDrive AI-assisted code security reviews using SAST, DAST, SCA, secrets detection, IaC scanning, container scanning, and contextual risk analysis.\nUse automation and intelligent correlation to assess third-party libraries, APIs, vendor integrations, and open-source dependencies for security, compliance, and supply-chain risk.\nSupport AI-enabled red team, blue team, and incident response simulations to validate detection, prevention, and response capabilities.\nEmbedding AI-Native Security into the SDLC\nPartner with developers and QA engineers to embed AI-driven security testing and automated risk detection into CI/CD pipelines.\nBuild and improve security automation that provides real-time feedback to developers during design, coding, testing, release, and deployment.\nUse AI-assisted analysis to review architecture and design artifacts, identify risks earlier, and recommend secure implementation patterns.\nContribute to intelligent security checkpoints that reduce manual review effort while improving consistency, traceability, and developer velocity.\nHelp design scalable guardrails, reusable security controls, and policy-as-code capabilities across application and platform teams.\nEmerging Threat Monitoring & Proactive Defense\nMonitor evolving application, cloud, API, AI/ML, and data security risks using AI-assisted threat intelligence, vulnerability intelligence, and attack-pattern analysis.\nIdentify and evaluate AI-specific threats such as prompt injection, data poisoning, model abuse, model leakage, insecure tool use, and sensitive data exposure.\nAssist in designing and deploying proactive defense mechanisms across applications, APIs, data platforms, and AI-powered systems.\nUse automated signals, telemetry, and risk scoring to support investigations, post-incident analysis, and continuous improvement of prevention and detection capabilities.\nTranslate recurring vulnerabilities and incidents into feedback loops that improve threat models, secure design patterns, and SDLC controls.\nSecurity Awareness, Standards & Scalable Enablement\nPromote secure coding and secure design practices through AI-assisted guidance, reusable playbooks, automated recommendations, and developer-friendly documentation.\nContribute to internal security standards, secure engineering patterns, and AI-native security playbooks.\nHelp teams adopt security self-service capabilities that reduce dependency on manual AppSec review.\nCollaborate closely with Engineering, DevOps, QA, Product, and AI platform teams to foster a security-first and automation-first culture.\nUse metrics and insights to measure control effectiveness, remediation trends, developer adoption, and overall security maturity.\nWhat You Need to Succeed\nBachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience.\n5+ years of experience in Application Security, DevSecOps, Secure Software Development, or Security Engineering.\nStrong understanding of OWASP Top 10, SANS CWE Top 25, secure design principles, and application threat modeling.\nFamiliarity with AI/ML security concepts such as prompt injection, data poisoning, adversarial testing, model integrity, model abuse, and AI supply-chain risks.\nExperience building or integrating AI-assisted security workflows, security bots, automated triage systems, or risk scoring models.\nExperience using AI-assisted or automation-driven approaches to improve security testing, vulnerability analysis, code review, or risk prioritization.\nExperience with modern application frameworks and architectures such as React, Node.js, Django, FastAPI, or similar technologies.\nKnowledge of securing APIs, microservices, authentication, and authorization mechanisms such as OAuth2, OIDC, JWT, and service-to-service authentication.\nExperience with cloud platforms such as AWS, GCP, or Azure, and containerized environments such as Docker and Kubernetes.\nWorking knowledge of security testing and automation tools such as Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security, or similar tools.\nAbility to analyze security findings, correlate risk context, and drive practical remediation guidance for engineering teams.\nStrong collaboration and communication skills with the ability to work across Engineering, Product, QA, DevOps, and Security teams.\nNice to Have\nExperience with policy-as-code, infrastructure-as-code security, CI/CD security controls, and automated governance.\nExperience with automation frameworks and scripting for security testing, vulnerability validation, and remediation workflows.\nRelevant certifications such as OSCP, GWAPT, CSSLP, cloud security certifications, or AI/ML-specific security certifications.\nBENEFITS & PERKS\nUnlimited PTO\nExcellent medical, dental, and vision coverage\nEmployee Equity\nEmployee Discounts, Virtual Wellness Classes, and Pet Insurance And more!!\nSALARY RANGE\nThe salary range for this role is $140,000 - $180,000, depending on location and experience.\nPEOPLE & CULTURE AT ZETA\nZeta considers applicants for employment without regard to, and does not discriminate on the basis of an individual's sex, race, color, religion, age, disability, status as a veteran, or national or ethnic origin; nor does Zeta discriminate on the basis of sexual orientation, gender identity or expression.\nWe're committed to building a workplace culture of trust and belonging, so everyone feels invited to bring their whole selves to work. We provide a forum for employees to celebrate, support and advocate for one another. Learn more about our commitment to diversity, equity and inclusion here: https://zetaglobal.com/blog/a-look-into-zetas-ergs/\nZETA IN THE NEWS!\nhttps://zetaglobal.com/press/?cat=press-releases\n\n#LI-TS1","company":"Zetaglobal","rawCompany":"zetaglobal","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-08-03T18:57:45.474Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Lead Application Security Engineer","description":"WHO WE ARE\nZeta Global (NYSE: ZETA) is the AI-Powered Marketing Cloud that leverages advanced artificial intelligence (AI) and trillions of consumer signals to make it easier for marketers to acquire, grow, and retain customers more efficiently. Through the Zeta Marketing Platform (ZMP), our vision is to make sophisticated marketing simple by unifying identity, intelligence, and omnichannel activation into a single platform – powered by one of the industry's largest proprietary databases and AI. Our enterprise customers across multiple verticals are empowered to personalize experiences with consumers at an individual level across every channel, delivering better results for marketing programs. Zeta was founded in 2007 by David A. Steinberg and John Sculley and is headquartered in New York City with offices around the world. To learn more, go to www.zetaglobal.com.\nAbout the Role\nWe're seeking a Lead Application Security Engineer to help advance Zeta Global's application and platform security posture through AI-native security practices, intelligent automation, and scalable security engineering. You'll play a critical role in embedding security throughout the software development lifecycle by using AI-driven tools, automated controls, and data-informed risk prioritization to ensure our systems, applications, and AI-powered platforms are built securely from the ground up.\nZeta operates at massive scale, powering billions of consumer profiles and petabytes of data across real-time, AI-powered marketing platforms. In this role, you'll collaborate with Engineering, Product, QA, DevOps, and AI platform teams to identify risks, design secure-by-default patterns, and build automated security capabilities that enable secure innovation at speed.\nThis position offers significant technical scope, cross-functional visibility, and the opportunity to directly influence the company's security maturity through AI-enabled threat modeling, automated validation, intelligent vulnerability management, and proactive defense.\nKey Responsibilities\nAI-Driven Threat Modeling & Security Validation\nUse AI-assisted threat modeling capabilities to identify application, platform, API, cloud, data, and AI/ML security risks early in the design and development process.\nLeverage automated security review tools to evaluate architecture, design documents, code changes, APIs, and data flows for security gaps and control weaknesses.\nDrive AI-assisted code security reviews using SAST, DAST, SCA, secrets detection, IaC scanning, container scanning, and contextual risk analysis.\nUse automation and intelligent correlation to assess third-party libraries, APIs, vendor integrations, and open-source dependencies for security, compliance, and supply-chain risk.\nSupport AI-enabled red team, blue team, and incident response simulations to validate detection, prevention, and response capabilities.\nEmbedding AI-Native Security into the SDLC\nPartner with developers and QA engineers to embed AI-driven security testing and automated risk detection into CI/CD pipelines.\nBuild and improve security automation that provides real-time feedback to developers during design, coding, testing, release, and deployment.\nUse AI-assisted analysis to review architecture and design artifacts, identify risks earlier, and recommend secure implementation patterns.\nContribute to intelligent security checkpoints that reduce manual review effort while improving consistency, traceability, and developer velocity.\nHelp design scalable guardrails, reusable security controls, and policy-as-code capabilities across application and platform teams.\nEmerging Threat Monitoring & Proactive Defense\nMonitor evolving application, cloud, API, AI/ML, and data security risks using AI-assisted threat intelligence, vulnerability intelligence, and attack-pattern analysis.\nIdentify and evaluate AI-specific threats such as prompt injection, data poisoning, model abuse, model leakage, insecure tool use, and sensitive data exposure.\nAssist in designing and deploying proactive defense mechanisms across applications, APIs, data platforms, and AI-powered systems.\nUse automated signals, telemetry, and risk scoring to support investigations, post-incident analysis, and continuous improvement of prevention and detection capabilities.\nTranslate recurring vulnerabilities and incidents into feedback loops that improve threat models, secure design patterns, and SDLC controls.\nSecurity Awareness, Standards & Scalable Enablement\nPromote secure coding and secure design practices through AI-assisted guidance, reusable playbooks, automated recommendations, and developer-friendly documentation.\nContribute to internal security standards, secure engineering patterns, and AI-native security playbooks.\nHelp teams adopt security self-service capabilities that reduce dependency on manual AppSec review.\nCollaborate closely with Engineering, DevOps, QA, Product, and AI platform teams to foster a security-first and automation-first culture.\nUse metrics and insights to measure control effectiveness, remediation trends, developer adoption, and overall security maturity.\nWhat You Need to Succeed\nBachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience.\n5+ years of experience in Application Security, DevSecOps, Secure Software Development, or Security Engineering.\nStrong understanding of OWASP Top 10, SANS CWE Top 25, secure design principles, and application threat modeling.\nFamiliarity with AI/ML security concepts such as prompt injection, data poisoning, adversarial testing, model integrity, model abuse, and AI supply-chain risks.\nExperience building or integrating AI-assisted security workflows, security bots, automated triage systems, or risk scoring models.\nExperience using AI-assisted or automation-driven approaches to improve security testing, vulnerability analysis, code review, or risk prioritization.\nExperience with modern application frameworks and architectures such as React, Node.js, Django, FastAPI, or similar technologies.\nKnowledge of securing APIs, microservices, authentication, and authorization mechanisms such as OAuth2, OIDC, JWT, and service-to-service authentication.\nExperience with cloud platforms such as AWS, GCP, or Azure, and containerized environments such as Docker and Kubernetes.\nWorking knowledge of security testing and automation tools such as Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security, or similar tools.\nAbility to analyze security findings, correlate risk context, and drive practical remediation guidance for engineering teams.\nStrong collaboration and communication skills with the ability to work across Engineering, Product, QA, DevOps, and Security teams.\nNice to Have\nExperience with policy-as-code, infrastructure-as-code security, CI/CD security controls, and automated governance.\nExperience with automation frameworks and scripting for security testing, vulnerability validation, and remediation workflows.\nRelevant certifications such as OSCP, GWAPT, CSSLP, cloud security certifications, or AI/ML-specific security certifications.\nBENEFITS & PERKS\nUnlimited PTO\nExcellent medical, dental, and vision coverage\nEmployee Equity\nEmployee Discounts, Virtual Wellness Classes, and Pet Insurance And more!!\nSALARY RANGE\nThe salary range for this role is $140,000 - $180,000, depending on location and experience.\nPEOPLE & CULTURE AT ZETA\nZeta considers applicants for employment without regard to, and does not discriminate on the basis of an individual's sex, race, color, religion, age, disability, status as a veteran, or national or ethnic origin; nor does Zeta discriminate on the basis of sexual orientation, gender identity or expression.\nWe're committed to building a workplace culture of trust and belonging, so everyone feels invited to bring their whole selves to work. We provide a forum for employees to celebrate, support and advocate for one another. Learn more about our commitment to diversity, equity and inclusion here: https://zetaglobal.com/blog/a-look-into-zetas-ergs/\nZETA IN THE NEWS!\nhttps://zetaglobal.com/press/?cat=press-releases\n\n#LI-TS1","datePosted":"2026-08-03T18:57:45.474Z","dateModified":"2026-08-03T18:57:45.474Z","hiringOrganization":{"@type":"Organization","name":"Zetaglobal","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"698b4f3cb2d8fe9714ae4780"},"url":"https://jobsearcher.com/jobs/698b4f3cb2d8fe9714ae4780"}}