Security Engineer for Threat Modeling and Code Reviews

3 days ago


New York, New York, United States Capital Group Full time

Capital Group Job Description

The AppSec Engineer is an essential role at Capital Group, where you will contribute to the company's commitment to security. This position requires a strong understanding of threat modeling, code reviews, and network security.

We are seeking an experienced individual with a bachelor's degree in computer science or a related field, preferably with 7+ years of experience. You will work independently and collaboratively with the development teams to ensure secure coding practices. Your responsibilities will include:

  • Performing threat models and code reviews
  • Validating cloud configurations and DAST, SAST, and SCA findings
  • Writing clear, concise technical documentation
  • Collaborating with technology stakeholders to advise on risks for technology solutions

In this role, you will leverage various tools, including Threat modeler/Threat Dragon, Scoutsuite, Veracode, Checkmarx, Netsparker, and DAST scanners like Burpsuite. Your strong communication skills will enable you to simplify complex technical details for both technical and non-technical audiences.

We offer a highly competitive base salary ($140,000 - $180,000), plus an individual annual performance bonus, Capital's annual profitability bonus, and a retirement plan with a 15% employer contribution.



  • New York, New York, United States Amazon Full time

    About the TeamThe AppSec AI team is a dynamic group tasked with ensuring AI applications meet the highest standards of security. As an AI Security Engineer, you will be part of this team, working closely with software development teams to review code, identify security issues, and develop frameworks to improve protection.We are looking for someone with...

  • Cloud Security Expert

    3 weeks ago


    New York, New York, United States Amazon Full time

    About the RoleWe are seeking a skilled Cloud Security Expert to join our team at Amazon. As a key member of our security organization, you will be responsible for developing and implementing threat models for various software projects.Responsibilities include:Creating, updating, and maintaining threat models for a wide range of software projectsManual and...


  • New York, New York, United States Crescens Full time

    Crescens is seeking a highly skilled Cyber Security Threat Modeling Integration Specialist to enhance our cybersecurity posture.Job Description:This is an 8-month contract role that requires the successful candidate to contribute to the development and implementation of threat models, integration of security solutions, and improvement of process...


  • New York, New York, United States Capital Group Full time

    Job OverviewCAPITAL GROUP IS SEEKING A HIGHLY MOTIVATED AND EXPERIENCED APPSEC ENGINEER TO JOIN OUR TEAM!As an AppSec Engineer, you will be responsible for identifying and mitigating potential security threats to our web applications. This role requires a deep understanding of software security, threat modeling, and code reviews.Your daily tasks will include...


  • New York, New York, United States META Full time

    META is seeking a highly skilled Security Analyst, Advanced Threats to lead our efforts in investigating and mitigating advanced cyber threats. As a key member of our team, you will track threat clusters, identify potential risks, and develop effective countermeasures to protect our infrastructure and employees.You will work closely with incident responders...


  • New York, New York, United States Amazon Full time

    Job OverviewWe are looking for a skilled Cloud Security Engineer II to join our Application Security Automation team at Amazon. This role involves developing and delivering automated security testing solutions for all of Amazon, requiring expertise in threat modeling, secure coding, identity management, software development, cryptography, and system...


  • New York, New York, United States Intuit Inc Full time

    About UsWe are Intuit Inc., a leading provider of financial management solutions. Our team is passionate about delivering high-quality products that meet the evolving needs of our customers.Job DescriptionWe are seeking a talented engineer to join our DevSecOps team as a DevSecOps Lead Engineer. This role requires a strong background in software development,...


  • New York, New York, United States Capital Group Full time

    About the RoleAt Capital Group, we value our employees' contributions to the company's success. As an AppSec Engineer, you will play a critical role in ensuring the security of our web applications. With a strong background in software security and threat modeling, you will help us identify and mitigate potential vulnerabilities.You will work closely with...


  • New York, New York, United States Integrated Resources Full time

    Job Title: Cybersecurity Threat Detection EngineerAt Integrated Resources, we are looking for a skilled Cybersecurity Threat Detection Engineer to join our team. As a key member of our cybersecurity team, you will play a critical role in enhancing our organization's security posture by automating security processes and developing advanced threat detection...


  • New York, New York, United States Hudson River Trading Full time

    Hudson River Trading is a pioneer in algorithmic trading, leveraging cutting-edge technology to drive innovation. We're seeking an accomplished Cybersecurity Threat Hunter to join our elite Security Operations team.About the Role:We're on the hunt for someone with extensive experience in cybersecurity, specifically in security operations and detection...


  • New York, New York, United States KPMG Full time

    Job Title: Director, Senior Cloud Security ArchitectJob Summary: KPMG is currently seeking a Director, Senior Cloud Security Architect to join our Global Information Solution Group organization.Responsibilities:1. Engage with key stakeholders to understand the current state of application security, contributing to the security program to address gaps.2....


  • New York, New York, United States Datadog Full time

    Cybersecurity Engineer - Threat Response SpecialistAt Datadog, we are committed to creating a culture that fosters innovation and collaboration. The Core Security Response team plays a vital role in keeping our systems and data safe from security threats.The Cybersecurity Engineer - Threat Response Specialist will work with engineers across the organization...


  • New York, New York, United States Uniswap Labs Full time

    About Uniswap LabsAt Uniswap Labs, we're dedicated to unlocking value through universal exchange. Our vision is a future where digital economies flourish, and markets are transparent, global, and equitable.SalaryThe estimated salary for this role is $264,000-$294,000 per year, based on industry standards and location.Job DescriptionWe're seeking a highly...

  • Cyber Security Leader

    2 weeks ago


    New York, New York, United States Mizuho Bank Ltd Full time

    Job SummaryWe are seeking an experienced Cyber Security Leader to join our team at Mizuho Americas. This role will play a critical part in safeguarding the company's digital assets and ensuring business continuity.About the RoleThis is a leadership position responsible for overseeing the Threat and Vulnerability Management program. The successful candidate...


  • New York, New York, United States Intelligent Staffing Full time

    Cyber Security Threat Analyst Job Summary:At Intelligent Staffing, we are seeking a skilled Cyber Security Threat Analyst to review, monitor, and resolve security findings within our organization. This role involves conducting risk and vulnerability assessments, validation testing, compliance reviews, and audits following NIST standards.Key...


  • New York, New York, United States Intuit Inc Full time

    Job Summary:We are seeking a highly skilled Senior Cybersecurity Architect with over 10 years of experience in security reviews, threat modeling, and incident response. This role requires a unique combination of advanced software development skills and deep expertise in security to perform thorough security reviews and threat modeling for both regular and...


  • New York, New York, United States Intuit Inc Full time

    Job SummaryWe are seeking a seasoned cybersecurity expert to lead our DevSecOps efforts as a Senior Cybersecurity Architect. This role requires a unique blend of technical expertise, business acumen, and leadership skills to drive security innovation across our organization.About the RoleThe ideal candidate will have a strong background in software...


  • New York, New York, United States News Corp Full time

    We are seeking a Product Security Specialist to secure our digital products at News Corp, supporting the NY POST. The successful applicant will contribute expertise, embrace emerging trends, and provide overall guidance on security best practices across all of News Corp businesses and technology groups.Key Responsibilities:Develop, maintain, and execute a...


  • New York, New York, United States Code and Theory Full time

    We are seeking an experienced Lead ML+DevOps Engineer to join our team at Code and Theory, a digital-first creative agency.**Job Overview:**The ideal candidate will have strong expertise in cloud deployment, containerization, and related technologies, playing a crucial role in the scalability and reliability of our AI/ML infrastructure.**Key...


  • New York, New York, United States Sumitomo Mitsui Banking Corporation Full time

    About the RoleAs a Threat Detection Analyst, you will play a key role in identifying and mitigating potential security threats to SMBC Group. You will work closely with our Threat Intelligence and Threat Hunting functions to conduct attack surface risk modeling and articulate high-risk areas to stakeholders.In this role, you will assist in the production of...