远程工作雷达

应用安全工程师负责人

Lead Application Security Engineer

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Zeta Global
薪资$140,000 - $180,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间26 天前
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

**我们是谁**

Zeta Global(纽约证券交易所代码:ZETA)是基于人工智能的营销云平台,利用先进的人工智能(AI)和数万亿的消费者数据信号,帮助营销人员更高效地获取、增长和保留客户。通过 Zeta 营销平台(ZMP),我们的愿景是通过将身份识别、智能分析和全渠道激活统一到一个平台中——由行业内最大的专有数据库和 AI 驱动——让复杂的营销变得简单。我们的企业客户在多个垂直领域中,能够通过每个渠道为每位消费者提供个性化的体验,从而提升营销活动的效果。Zeta 由 David A. Steinberg 和 John Sculley 于 2007 年创立,总部位于纽约市,并在全球设有办事处。如需了解更多信息,请访问 [www.zetaglobal.com](https://www.zetaglobal.com)。

**职位简介**

我们正在寻找一位高级应用安全工程师,通过 AI 原生的安全实践、智能自动化和可扩展的安全工程,提升 Zeta Global 的应用和平台安全态势。你将在整个软件开发生命周期中嵌入安全措施,使用 AI 驱动的工具、自动化控制和数据驱动的风险优先级排序,确保我们的系统、应用和 AI 驱动的平台从底层开始构建得更加安全。

Zeta 在大规模环境下运行,为数十亿的消费者资料和跨实时、AI 驱动的营销平台的 PB 级数据提供支持。在这个职位上,你将与工程、产品、QA、DevOps 和 AI 平台团队合作,识别风险,设计默认安全的模式,并构建自动化安全能力,以实现快速的安全创新。

该职位提供了广泛的技术范围、跨职能的可见性,以及通过 AI 支持的威胁建模、自动化验证、智能漏洞管理和主动防御,直接推动公司安全成熟度的机会。

**主要职责**

**AI 驱动的威胁建模与安全验证**

- 使用 AI 辅助的威胁建模功能,在设计和开发过程中早期识别应用、平台、API、云、数据和 AI/ML 安全风险。
- 利用自动化安全评审工具,评估架构、设计文档、代码变更、API 和数据流中的安全缺口和控制弱点。
- 驱动安全评审流程,确保所有新功能和系统在部署前符合安全标准。

查看英文原文

**WHO WE ARE**

Zeta Global (NYSE: ZETA) is the AI-Powered Marketing Cloud that leverages advanced artificial intelligence (AI) and trillions of consumer signals to make it easier for marketers to acquire, grow, and retain customers more efficiently. Through the Zeta Marketing Platform (ZMP), our vision is to make sophisticated marketing simple by unifying identity, intelligence, and omnichannel activation into a single platform – powered by one of the industry’s largest proprietary databases and AI. Our enterprise customers across multiple verticals are empowered to personalize experiences with consumers at an individual level across every channel, delivering better results for marketing programs. Zeta was founded in 2007 by David A. Steinberg and John Sculley and is headquartered in New York City with offices around the world. To learn more, go to [www.zetaglobal.com](https://www.zetaglobal.com).

**About the Role**

We’re seeking a Lead Application Security Engineer to help advance Zeta Global’s application and platform security posture through AI-native security practices, intelligent automation, and scalable security engineering. You’ll play a critical role in embedding security throughout the software development lifecycle by using AI-driven tools, automated controls, and data-informed risk prioritization to ensure our systems, applications, and AI-powered platforms are built securely from the ground up.

Zeta operates at massive scale, powering billions of consumer profiles and petabytes of data across real-time, AI-powered marketing platforms. In this role, you’ll collaborate with Engineering, Product, QA, DevOps, and AI platform teams to identify risks, design secure-by-default patterns, and build automated security capabilities that enable secure innovation at speed.

This position offers significant technical scope, cross-functional visibility, and the opportunity to directly influence the company’s security maturity through AI-enabled threat modeling, automated validation, intelligent vulnerability management, and proactive defense.

**Key Responsibilities**

**AI-Driven Threat Modeling & Security Validation**

- Use AI-assisted threat modeling capabilities to identify application, platform, API, cloud, data, and AI/ML security risks early in the design and development process.
- Leverage automated security review tools to evaluate architecture, design documents, code changes, APIs, and data flows for security gaps and control weaknesses.
- Drive AI-assisted code security reviews using SAST, DAST, SCA, secrets detection, IaC scanning, container scanning, and contextual risk analysis.
- Use automation and intelligent correlation to assess third-party libraries, APIs, vendor integrations, and open-source dependencies for security, compliance, and supply-chain risk.
- Support AI-enabled red team, blue team, and incident response simulations to validate detection, prevention, and response capabilities.

**Embedding AI-Native Security into the SDLC**

- Partner with developers and QA engineers to embed AI-driven security testing and automated risk detection into CI/CD pipelines.
- Build and improve security automation that provides real-time feedback to developers during design, coding, testing, release, and deployment.
- Use AI-assisted analysis to review architecture and design artifacts, identify risks earlier, and recommend secure implementation patterns.
- Contribute to intelligent security checkpoints that reduce manual review effort while improving consistency, traceability, and developer velocity.
- Help design scalable guardrails, reusable security controls, and policy-as-code capabilities across application and platform teams.

**Emerging Threat Monitoring & Proactive Defense**

- Monitor evolving application, cloud, API, AI/ML, and data security risks using AI-assisted threat intelligence, vulnerability intelligence, and attack-pattern analysis.
- Identify and evaluate AI-specific threats such as prompt injection, data poisoning, model abuse, model leakage, insecure tool use, and sensitive data exposure.
- Assist in designing and deploying proactive defense mechanisms across applications, APIs, data platforms, and AI-powered systems.
- Use automated signals, telemetry, and risk scoring to support investigations, post-incident analysis, and continuous improvement of prevention and detection capabilities.
- Translate recurring vulnerabilities and incidents into feedback loops that improve threat models, secure design patterns, and SDLC controls.

**Security Awareness, Standards & Scalable Enablement**

- Promote secure coding and secure design practices through AI-assisted guidance, reusable playbooks, automated recommendations, and developer-friendly documentation.
- Contribute to internal security standards, secure engineering patterns, and AI-native security playbooks.
- Help teams adopt security self-service capabilities that reduce dependency on manual AppSec review.
- Collaborate closely with Engineering, DevOps, QA, Product, and AI platform teams to foster a security-first and automation-first culture.
- Use metrics and insights to measure control effectiveness, remediation trends, developer adoption, and overall security maturity.

**What You Need to Succeed**

- Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience.
- 5+ years of experience in Application Security, DevSecOps, Secure Software Development, or Security Engineering.
- Strong understanding of OWASP Top 10, SANS CWE Top 25, secure design principles, and application threat modeling.
- Familiarity with AI/ML security concepts such as prompt injection, data poisoning, adversarial testing, model integrity, model abuse, and AI supply-chain risks.
- Experience building or integrating AI-assisted security workflows, security bots, automated triage systems, or risk scoring models.
- Experience using AI-assisted or automation-driven approaches to improve security testing, vulnerability analysis, code review, or risk prioritization.
- Experience with modern application frameworks and architectures such as React, Node.js, Django, FastAPI, or similar technologies.
- Knowledge of securing APIs, microservices, authentication, and authorization mechanisms such as OAuth2, OIDC, JWT, and service-to-service authentication.
- Experience with cloud platforms such as AWS, GCP, or Azure, and containerized environments such as Docker and Kubernetes.
- Working knowledge of security testing and automation tools such as Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security, or similar tools.
- Ability to analyze security findings, correlate risk context, and drive practical remediation guidance for engineering teams.
- Strong collaboration and communication skills with the ability to work across Engineering, Product, QA, DevOps, and Security teams.

**Nice to Have**

- Experience with policy-as-code, infrastructure-as-code security, CI/CD security controls, and automated governance.
- Experience with automation frameworks and scripting for security testing, vulnerability validation, and remediation workflows.
- Relevant certifications such as OSCP, GWAPT, CSSLP, cloud security certifications, or AI/ML-specific security certifications.

**BENEFITS & PERKS**

- Unlimited PTO
- Excellent medical, dental, and vision coverage
- Employee Equity
- Employee Discounts, Virtual Wellness Classes, and Pet Insurance And more!!

**SALARY RANGE**

The salary range for this role is $220,000-$250,000 TC, depending on location and experience.

**PEOPLE & CULTURE AT ZETA**

Zeta considers applicants for employment without regard to, and does not discriminate on the basis of an individual’s sex, race, color, religion, age, disability, status as a veteran, or national or ethnic origin; nor does Zeta discriminate on the basis of sexual orientation, gender identity or expression.

We’re committed to building a workplace culture of trust and belonging, so everyone feels invited to bring their whole selves to work. We provide a forum for employees to celebrate, support and advocate for one another. Learn more about our commitment to diversity, equity and inclusion here:  [https://zetaglobal.com/blog/a-look-into-zetas-ergs/](https://zetaglobal.com/blog/a-look-into-zetas-ergs/)

**ZETA IN THE NEWS!**

[https://zetaglobal.com/press/?cat=press-releases](https://zetaglobal.com/press/?cat=press-releases)

#LI-TS1

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级软件工程师,身份认证

Zeta GlobalUnited States$150,000 - $180,000/年permanent昨天
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

高级客户成功经理

Zeta GlobalUnited Statespermanent6 天前
职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

合作营销经理

Zeta GlobalUnited Statespermanent19 天前
AI市场运营限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位