About the Role
We are seeking a Lead Application Security Engineer to enhance Zeta Global's application and platform security using AI-native practices, intelligent automation, and scalable engineering. This role is crucial for integrating security throughout the software development lifecycle by employing AI-driven tools and automated controls to ensure secure system and platform development.
Responsibilities
- Use AI-assisted threat modeling to identify application, platform, API, cloud, data, and AI/ML security risks.
- Leverage automated security review tools to evaluate architecture, design documents, code changes, APIs, and data flows for security gaps.
- Drive AI-assisted code security reviews using SAST, DAST, SCA, secrets detection, IaC scanning, container scanning, and contextual risk analysis.
- Use automation and intelligent correlation to assess third-party libraries, APIs, vendor integrations, and open-source dependencies for security, compliance, and supply-chain risk.
- Support AI-enabled red team, blue team, and incident response simulations.
- Partner with developers and QA engineers to embed AI-driven security testing and automated risk detection into CI/CD pipelines.
- Build and improve security automation that provides real-time feedback to developers.
- Use AI-assisted analysis to review architecture and design artifacts and recommend secure implementation patterns.
- Contribute to intelligent security checkpoints that reduce manual review effort.
- Help design scalable guardrails, reusable security controls, and policy-as-code capabilities.
- Monitor evolving application, cloud, API, AI/ML, and data security risks using AI-assisted threat intelligence.
- Identify and evaluate AI-specific threats such as prompt injection, data poisoning, model abuse, model leakage, insecure tool use, and sensitive data exposure.
- Assist in designing and deploying proactive defense mechanisms.
- Use automated signals, telemetry, and risk scoring to support investigations and continuous improvement.
- Translate recurring vulnerabilities and incidents into feedback loops for threat models and SDLC controls.
- Promote secure coding and design practices through AI-assisted guidance and documentation.
- Contribute to internal security standards, secure engineering patterns, and AI-native security playbooks.
- Help teams adopt security self-service capabilities.
- Collaborate with Engineering, DevOps, QA, Product, and AI platform teams to foster a security-first and automation-first culture.
- Use metrics and insights to measure control effectiveness and security maturity.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience.
- 5+ years of experience in Application Security, DevSecOps, Secure Software Development, or Security Engineering.
- Strong understanding of OWASP Top 10, SANS CWE Top 25, secure design principles, and application threat modeling.
- Familiarity with AI/ML security concepts such as prompt injection, data poisoning, adversarial testing, model integrity, model abuse, and AI supply-chain risks.
- Experience building or integrating AI-assisted security workflows, security bots, automated triage systems, or risk scoring models.
- Experience using AI-assisted or automation-driven approaches to improve security testing, vulnerability analysis, code review, or risk prioritization.
- Experience with modern application frameworks and architectures such as React, Node.js, Django, FastAPI, or similar technologies.
- Knowledge of securing APIs, microservices, authentication, and authorization mechanisms such as OAuth2, OIDC, JWT, and service-to-service authentication.
- Experience with cloud platforms such as AWS, GCP, or Azure, and containerized environments such as Docker and Kubernetes.
- Working knowledge of security testing and automation tools such as Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security, or similar tools.
- Ability to analyze security findings, correlate risk context, and drive practical remediation guidance.
- Strong collaboration and communication skills.
Skills
- AI-assisted threat modeling
- Automated security review
- SAST
- DAST
- SCA
- Secrets detection
- IaC scanning
- Container scanning
- Contextual risk analysis
- Third-party risk assessment
- API security
- Cloud security
- Data security
- AI/ML security
- CI/CD security
- Secure coding practices
- Secure design principles
- OWASP Top 10
- SANS CWE Top 25
- Prompt injection
- Data poisoning
- Adversarial testing
- Model integrity
- Model abuse
- AI supply-chain risks
- Policy-as-code
- Infrastructure-as-code security
- Automation frameworks
- Scripting
- React
- Node.js
- Django
- FastAPI
- Microservices security
- OAuth2
- OIDC
- JWT
- AWS
- GCP
- Azure
- Docker
- Kubernetes
- Semgrep
- SonarQube
- Burp Suite
- OWASP ZAP
- Trivy
- Snyk
- GitHub Advanced Security
Experience Level
- 5+ years of experience
Education Level
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience.
Salary/Compensations
- $140,000 - $180,000
Benefits
- Unlimited PTO
- Excellent medical, dental, and vision coverage
- Employee Equity
- Employee Discounts
- Virtual Wellness Classes
- Pet Insurance
About the Company
- Zeta Global (NYSE: ZETA) is the AI-Powered Marketing Cloud that leverages advanced artificial intelligence (AI) and trillions of consumer signals to make it easier for marketers to acquire, grow, and retain customers more efficiently.
- Through the Zeta Marketing Platform (ZMP), our vision is to make sophisticated marketing simple by unifying identity, intelligence, and omnichannel activation into a single platform – powered by one of the industry’s largest proprietary databases and AI.
- Our enterprise customers across multiple verticals are empowered to personalize experiences with consumers at an individual level across every channel, delivering better results for marketing programs.
- Zeta was founded in 2007 by David A. Steinberg and John Sculley and is headquartered in New York City with offices around the world.
- To learn more, go to www.zetaglobal.com.
Equal Opportunity
- Zeta considers applicants for employment without regard to, and does not discriminate on the basis of an individual’s sex, race, color, religion, age, disability, status as a veteran, or national or ethnic origin; nor does Zeta discriminate on the basis of sexual orientation, gender identity or expression.
- We’re committed to building a workplace culture of trust and belonging, so everyone feels invited to bring their whole selves to work.
- We provide a forum for employees to celebrate, support and advocate for one another.
- Learn more about our commitment to diversity, equity and inclusion here: https://zetaglobal.com/blog/a-look-into-zetas-ergs/
