Interactive Brokers

ApplicationSecurityEngineer

₹25–45L ~AI est. India Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid+ candidates.

The Brief

“Application Security Engineer at Interactive Brokers. Skills: Application security, DevSecOps, Security tooling, CI/CD security. Operate scanning platforms. Onboard new repositories”

Industry & Context.

Problems you'll solve

Reason about exploitability; Reason about code

What They're Looking For.

Must Have

5-7 years application security, 5-7 years DevSecOps, 5-7 years security engineering, Foundational knowledge of web application vulnerabilities, Ability to reason about exploitability, Hands-on SAST platform experience, Experience integrating security tooling into CI/CD, Proficiency in scripting language, Experience with DAST tooling, Familiarity with SCA concepts, Ability to read and reason about code

Nice to Have

Development background, Background spans both sides of SDLC

What You'll Do.

Operate scanning platforms

Onboard new repositories

Maintain coverage metrics

Build CI/CD security gates

Enforce scan policies

Write custom detection rules

Prioritize scan findings

Distinguish true positives

Explain real-world impact

Build suppression workflows

Develop automation for findings

Integrate dynamic scanning

Partner on remediation

Provide exploit context

Tie third-party vulnerabilities

Contribute to security champions

Help developers understand

Run tooling evaluations

Drive buy vs build decisions

How You'll Work.

Team & Collaboration

Across engineering teams; With engineering teams; With developers

Full Job Description

About the Role We are looking for an Application Security Engineer who lives at the intersection of security and engineering. This is not a policy role — you will be hands-on building, tuning, and scaling the security scanning infrastructure that protects our software delivery pipeline. You will own SAST, DAST, and SCA tooling end to end, drive false positive reduction, and embed security gates directly into CI/CD workflows across engineering teams. A deep understanding of how vulnerabilities actually work — not just what scanners report — is fundamental to success in this role. The Problem We're Solving We operate in a complex, regulated environment — multiple languages, layered network boundaries, and delivery velocity that cannot be sacrificed for security theater. We are building a scanning program that works in that reality. Tuned, automated, trusted — coverage that is measurable and findings that engineers actually act on. This role exists to solve that problem. What You'll Do Own and operate static, dynamic, and software composition analysis scanning platforms across all engineering pipelines — onboarding new repositories, tuning rulesets, and maintaining coverage metrics Build and maintain CI/CD security gates that enforce scan policies at pull request, merge, and release stages across engineering workflows Write custom detection rules tailored to the organization's tech stack and threat model — covering vulnerability classes specific to the languages and frameworks in use Triage and prioritize scan findings with a deep understanding of actual exploitability — distinguish true positives from noise, explain the real-world impact of each finding, and build suppression workflows that reduce false positive rates without creating blind spots Develop automation to ticket, deduplicate, and route findings to the right engineering teams with enough context for developers to understand and act on them Integrate dynamic scanning into pre-production environments with au

Free ATS check

Applying for this Application Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Greenhouse

  • Create a Greenhouse profile before applying — it saves time across multiple applications.
  • Upload your resume as a PDF; the parser handles it better than Word.
  • Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
  • Enable email notifications to track application status in real time.

ANONYMOUS · UNFILTERED

What do employees actually say about Interactive Brokers?

Real rants from real employees. Read before you apply.

Read Company Rants →