Savvy Insurance Services, Inc. logo

Senior Application Security Engineer

Job Overview

Location

NYC Office

Job Type

Full-time

Category

DevOps & SysAdmin

Date Posted

August 8, 2026

Full Job Description

đź“‹ Description

  • • We are seeking a Senior Application Security Engineer to join Savvy Wealth at our NYC headquarters.
  • • This is a hands-on, in-the-weeds engineering role.
  • • You will execute the security strategy set by our Director of IT & Information Security and our CTO, with day-to-day work centered on identifying vulnerabilities, remediating them, and closing the longer-term gaps that make us exposed, both in our product and in the SaaS tools our teams use every day.
  • • Savvy is an AI-forward company, and most of our engineering is AI-assisted.
  • • Your job is to make it safe: setting security hygiene standards in our codebases, building guardrails around AI-assisted development, and partnering closely with our internal AI team so that speed and security move together.
  • • You will make the secure path the easy path.
  • • Responsibilities:
  • • Own vulnerability management end to end: identify, triage, prioritize by real-world risk, and drive remediation to closure across our product, codebases, and cloud infrastructure (AWS, GCP, Cloudflare)
  • • Build and operate our AppSec tooling pipeline: secrets scanning in CI and at the git layer, SCA/dependency scanning with triage SLAs, and SAST rollout on our most sensitive repos, tuned for signal over noise
  • • Set and enforce security hygiene standards within our codebases, including code review standards that explicitly account for AI-generated code (authorship transparency, mandatory human review on security-sensitive paths)
  • • Partner with our internal AI team to design guardrails that keep AI-assisted development, including vibe coding by non-technical builders, safe by default: sanctioned tooling, data handling boundaries, dependency vetting, and secure defaults for AI-built integrations
  • • Secure the SaaS stack: harden configurations, review OAuth grants and third-party integrations, reduce misconfiguration risk across platforms like Google Workspace, GitHub, Rippling, and Slack
  • • Help establish conditional access and identity-layer controls in partnership with IT (SSO, phishing-resistant MFA, managed-device posture)
  • • Define cloud and SaaS configuration baselines for the infrastructure footprint we operate
  • • Contribute to detection and response readiness: high-signal detections (new OAuth grants, mass code-host downloads, credential anomalies) and participate in incident response when needed
  • • Work cross-functionally with Engineering, IT, and the internal AI team; clearly articulate risk, remediation paths, and tradeoffs to both technical and non-technical stakeholders
  • • Must have:
  • • 5+ years of hands-on security engineering experience, with significant time in application security or product security
  • • Strong software engineering fundamentals; comfortable reading, writing, and remediating code, not just filing findings
  • • Deep experience with the modern AppSec toolchain: secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration (GitHub-centric)
  • • Practical experience securing SaaS environments: OAuth and third-party app review, configuration hardening, and least-privilege access design
  • • Working knowledge of cloud security across AWS and/or GCP, and edge/CDN security (Cloudflare)
  • • A pragmatic, risk-based mindset: you prioritize by what actually gets exploited, ship iteratively, and avoid drowning teams in noise
  • • Strong perspective on AI-assisted development security: you understand how AI coding tools change the shape of AppSec risk (hallucinated dependencies, leaked secrets, insecure patterns at scale) and how to build guardrails without killing velocity
  • • Track record of partnering with engineering teams as an enabler, embedding security into existing workflows rather than bolting it on
  • • Excellent communication skills and ability to work independently in a fast-paced environment
  • • Strong writing skills; Savvy is a written culture
  • • Nice to have:
  • • Experience building security programs at an early-to-mid stage company, taking a function from reactive to systematic
  • • Experience with SaaS security posture management, CSPM, or identity threat detection
  • • Familiarity with securing LLM-based tooling, agentic workflows, or internal AI platforms
  • • Detection engineering experience (SIEM/MDR, high-signal alerting)
  • • Fintech or financial services environment experience
  • • Offensive security background (pentesting, bug bounty, red team) that informs how you defend

🏖️ Benefits

  • • Competitive salary and equity package
  • • Unlimited PTO + paid company holidays
  • • Access to holistic medical, dental, and vision plans
  • • Company 401(k), Commuter, and HSA/FSA plans
  • • NYC office in the heart of Manhattan
  • • Lunch and snacks provided in the office
  • • Access to virtual mental health care (Spring Health) and health concierge (Rightway) to help you find the right care
  • • Access to counseling for stress management, dependent care, nutrition, fitness, legal, and financial issues (Guardian WorkLifeMatters EAP)

🎯 Requirements

  • • 5+ years of hands-on security engineering experience, with significant time in application security or product security
  • • Strong software engineering fundamentals; comfortable reading, writing, and remediating code, not just filing findings
  • • Deep experience with the modern AppSec toolchain: secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration (GitHub-centric)
  • • Practical experience securing SaaS environments: OAuth and third-party app review, configuration hardening, and least-privilege access design
  • • Working knowledge of cloud security across AWS and/or GCP, and edge/CDN security (Cloudflare)

🏖️ Benefits

  • • Competitive salary and equity package
  • • Unlimited PTO + paid company holidays
  • • Access to holistic medical, dental, and vision plans
  • • Company 401(k), Commuter, and HSA/FSA plans
  • • NYC office in the heart of Manhattan
  • • Lunch and snacks provided in the office
  • • Access to virtual mental health care (Spring Health) and health concierge (Rightway) to help you find the right care
  • • Access to counseling for stress management, dependent care, nutrition, fitness, legal, and financial issues (Guardian WorkLifeMatters EAP)

Skills & Technologies

Spring
AWS
GCP
GitHub
Git
Senior
Onsite

Ready to Apply?

You will be redirected to an external site to apply.

AI Job Fit Analysis
Pro

See exactly how your profile matches this role — strengths, skill gaps, and what to do about them.

Savvy Insurance Services, Inc. logo
Savvy Insurance Services, Inc.
Visit Website

About Savvy Insurance Services, Inc.

Savvy combines technology and human financial advisors to provide wealth management services. The firm delivers personalized financial plans and investment strategies tailored to individual client goals. Savvy's advisors are located across the U.S. and can be found through their online search tool, with a focus area for each advisor. The company offers a dashboard for clients to track investments and progress towards financial goals. Savvy targets a wide range of clients, offering specialized services, such as P&G employee benefits and small business tax planning. Savvy has over $3 billion in assets under management.

Get more remote jobs like this

Subscribe to the weekly newsletter for similar remote roles and curated hiring updates.

Newsletter

Weekly remote jobs and featured talent.

No spam. Only curated remote roles and product updates. You can unsubscribe anytime.

Similar Opportunities

Expired
Pragmatike Soluciones TecnolĂłgicas S.L. logo

Pragmatike Soluciones TecnolĂłgicas S.L.

Albania
Full-time
Expired Aug 29, 2026
Python
Node.js
Kubernetes
+4 more

2 months ago

Expired
Remote
Contract
Expired Aug 23, 2026
Rust
AWS
Azure
+4 more

3 months ago

Expired
Colombia
Full-time
Expired Aug 23, 2026
Python
AWS
GCP
+4 more

3 months ago

Expired
Pragmatike Soluciones TecnolĂłgicas S.L. logo

Pragmatike Soluciones TecnolĂłgicas S.L.

Argentina
Full-time
Expired Aug 18, 2026
Python
Git
Linux
+5 more

3 months ago