Interactive Brokers
ApplicationSecurityEngineer
Neural analysis suggests this role is
optimal for Mid+ candidates.
“Application Security Engineer at Interactive Brokers. Skills: Application security, DevSecOps, Security tooling, CI/CD security. Operate scanning platforms. Onboard new repositories”
Industry & Context.
Reason about exploitability; Reason about code
What They're Looking For.
Must Have
5-7 years application security, 5-7 years DevSecOps, 5-7 years security engineering, Foundational knowledge of web application vulnerabilities, Ability to reason about exploitability, Hands-on SAST platform experience, Experience integrating security tooling into CI/CD, Proficiency in scripting language, Experience with DAST tooling, Familiarity with SCA concepts, Ability to read and reason about code
Nice to Have
Development background, Background spans both sides of SDLC
What You'll Do.
Operate scanning platforms
Onboard new repositories
Maintain coverage metrics
Build CI/CD security gates
Enforce scan policies
Write custom detection rules
Prioritize scan findings
Distinguish true positives
Explain real-world impact
Build suppression workflows
Develop automation for findings
Integrate dynamic scanning
Partner on remediation
Provide exploit context
Tie third-party vulnerabilities
Contribute to security champions
Help developers understand
Run tooling evaluations
Drive buy vs build decisions
How You'll Work.
Team & Collaboration
Across engineering teams; With engineering teams; With developers
Full Job Description
About the Role We are looking for an Application Security Engineer who lives at the intersection of security and engineering. This is not a policy role — you will be hands-on building, tuning, and scaling the security scanning infrastructure that protects our software delivery pipeline. You will own SAST, DAST, and SCA tooling end to end, drive false positive reduction, and embed security gates directly into CI/CD workflows across engineering teams. A deep understanding of how vulnerabilities actually work — not just what scanners report — is fundamental to success in this role. The Problem We're Solving We operate in a complex, regulated environment — multiple languages, layered network boundaries, and delivery velocity that cannot be sacrificed for security theater. We are building a scanning program that works in that reality. Tuned, automated, trusted — coverage that is measurable and findings that engineers actually act on. This role exists to solve that problem. What You'll Do Own and operate static, dynamic, and software composition analysis scanning platforms across all engineering pipelines — onboarding new repositories, tuning rulesets, and maintaining coverage metrics Build and maintain CI/CD security gates that enforce scan policies at pull request, merge, and release stages across engineering workflows Write custom detection rules tailored to the organization's tech stack and threat model — covering vulnerability classes specific to the languages and frameworks in use Triage and prioritize scan findings with a deep understanding of actual exploitability — distinguish true positives from noise, explain the real-world impact of each finding, and build suppression workflows that reduce false positive rates without creating blind spots Develop automation to ticket, deduplicate, and route findings to the right engineering teams with enough context for developers to understand and act on them Integrate dynamic scanning into pre-production environments with au
Applying for this Application Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Greenhouse
- Create a Greenhouse profile before applying — it saves time across multiple applications.
- Upload your resume as a PDF; the parser handles it better than Word.
- Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
- Enable email notifications to track application status in real time.
ANONYMOUS · UNFILTERED
What do employees actually say about Interactive Brokers?
Real rants from real employees. Read before you apply.