Application Security Engineer • New York City

Your Guide to Application Security Engineer Jobs in New York City

New York City offers a dynamic landscape for Application Security Engineers, blending the fast pace of Wall Street with the innovative spirit of Silicon Alley. As digital transformation accelerates across the city's robust fintech, media, adtech, SaaS, and AI sectors, the demand for skilled professionals who can secure software at every stage of development is skyrocketing. You'll find yourself at the forefront of securing critical applications for some of the world's most influential companies, from nascent startups to established global enterprises.Securing an Application Security Engineer role in New York means navigating a competitive yet rewarding market. This guide provides an inside look at what you need to succeed, offering insights into local salary benchmarks, the top hiring companies, and actionable strategies to streamline your job search in this vibrant metropolis. Get ready to make your mark on NYC's digital defense.

The Market

New York City hiring landscape

New York City's market for Application Security Engineers is currently experiencing high demand, particularly within its dominant fintech, media, and rapidly expanding AI sectors. Companies are heavily investing in product security, shifting left, and integrating AppSec earlier in the SDLC. The hiring temperature is warm, driven by a strong focus on regulatory compliance, data privacy, and protecting high-value digital assets. You'll find consistent openings as businesses scale their security efforts to counter increasingly sophisticated threats.

Demand

High demand

Competition

Moderately competitive

Hub for

fintech, media, adtech

Salary range

Quoted in USD · base + typical equity for New York City

Junior$110k$160k
Mid$160k$220k
Senior$220k$320k

Salaries in New York City are typically higher than the national average due to the elevated cost of living and concentration of high-value industries. Total compensation packages often include significant equity (RSUs) for tech companies and substantial cash bonuses for finance/fintech roles, which can significantly boost overall earnings beyond base salary. Always consider the full total compensation when evaluating offers in NYC.

See full application security engineer salary breakdown for New York City

Where to apply

Top employers in New York City

JPMorgan Chase & Co.

A global leader in financial services with a massive technology footprint in NYC, heavily investing in application security for its vast array of products and platforms.

Enterprise Java, Python, .NET, cloud security (AWS/Azure), SAST/DAST, threat modeling, regulatory compliance, large-scale application ecosystems.

Google

Google's substantial NYC presence focuses on advertising, search, cloud, and AI. Their AppSec teams here work on securing core products and innovative new ventures.

Go, Python, Java, C++, cloud security (GCP), large-scale distributed systems, advanced threat detection, privacy-enhancing technologies.

Meta (Facebook)

Meta's New York office is a critical engineering hub, contributing to core products like Instagram and Messenger, requiring robust application security expertise.

PHP (Hack), Python, C++, React, large-scale web applications, mobile security, data privacy, secure coding practices.

Bloomberg L.P.

Headquartered in NYC, Bloomberg powers global financial markets. Their AppSec teams secure critical data terminals, news platforms, and enterprise software.

C++, Java, Python, JavaScript, Linux, real-time data security, low-latency applications, secure development lifecycle (SDL) implementation.

Datadog

A fast-growing SaaS observability platform with a strong NYC presence. AppSec engineers secure their critical monitoring infrastructure and customer data.

Go, Python, Ruby, AWS, Kubernetes, microservices security, cloud-native applications, API security, infrastructure-as-code security.

Etsy

Headquartered in Brooklyn, Etsy's e-commerce platform connects millions of buyers and sellers, demanding strong application security to protect transactions and user data.

PHP, Python, JavaScript, Google Cloud, microservices, e-commerce security, fraud prevention, secure payment processing.

Spotify

With a significant NYC office, Spotify's AppSec team works on securing its streaming service, user data, and creator tools globally.

Java, Python, Go, Scala, Google Cloud, microservices, API security, DRM, content protection, data privacy by design.

Two Sigma

A quantitative hedge fund based in NYC, Two Sigma leverages technology and data science extensively, requiring elite application security to protect its proprietary trading strategies and research.

Python, Java, C++, high-performance computing (HPC) security, low-latency systems, cryptographic applications, intellectual property protection.

Playbook

Apply smarter, not faster

01

Showcase your fintech or media security experience prominently.

Many top NYC employers are in finance and media tech. Tailor your resume to highlight experience with financial regulations, data privacy (e.g., SOX, GDPR for fintech), or media content protection.

02

Prepare deeply for threat modeling and code review scenarios specific to cloud and API security.

NYC companies, especially those in SaaS and fintech, rely heavily on cloud-native architectures and extensive APIs. Expect detailed technical rounds on identifying vulnerabilities in these environments and articulating mitigation strategies.

03

Quantify your impact on reducing risk or improving security posture.

NYC hiring managers want to see tangible results. Instead of just listing responsibilities, describe projects where you measurably reduced critical vulnerabilities, improved SAST/DAST coverage, or streamlined security processes.

04

Network actively within NYC's cybersecurity meetups and conferences.

Many opportunities in New York are found through connections. Attend local events like OWASP NYC, BSides NYC, or industry-specific tech meetups (fintech, adtech) to meet hiring managers and expand your professional circle.

05

Demonstrate proficiency in modern application frameworks and languages common in NYC.

Given NYC's tech landscape, strong skills in Python, Java, JavaScript/TypeScript (Node.js/React), and Go are highly valued. Be ready to discuss secure coding principles within these contexts and common frameworks like Spring Boot or Django.

06

Research the specific ATS (Greenhouse/Lever) usage of your target companies.

Most major tech and finance companies in NYC use Greenhouse or Lever. Understanding how to optimize your resume and application for these systems can improve your chances of getting past initial screening filters.

Visa & relocation

Working in New York City

For non-US citizens, a visa is typically required to work as an Application Security Engineer in New York City. Common visa types include H-1B (often sponsored by larger tech and finance firms), O-1 (for individuals with extraordinary ability), TN (for Canadian and Mexican citizens under NAFTA/USMCA), and E-3 (for Australian citizens). Sponsorship is prevalent, especially in finance and major tech companies, though competition for H-1B visas remains high. English is the universal language for professional work. Relocation packages, including temporary housing and moving cost assistance, are often provided by larger employers for senior roles, though these vary widely.

FAQ

Application Security Engineer jobs in New York City
What you should know.

The typical process involves an initial recruiter screen, followed by a technical phone screen (often focused on secure coding or OWASP Top 10), then an onsite or virtual loop. This loop usually includes a code review/vulnerability spotting exercise, a threat modeling session, system design with security considerations, and behavioral interviews. Expect scenarios specific to the company's tech stack and industry.

Stop hand-applying to application security engineers roles in New York City.
Let ApplyGhost do it.

ApplyGhost matches you to application security engineer openings in New York City and applies on your behalf with tailored applications.