Senior Application Security Engineer

Full-time Job Type
On-site Work Arrangement
Senior-Level Experience
Apply Now Posted 2 weeks ago

On-site in NYC, this senior-level role at Savvy Wealth focuses on application security engineering. Savvy Wealth is a fintech company modernizing wealth management with AI-driven solutions, offering financial advisors a comprehensive tech platform.

Skills / Requirements

  • AI-assisted Development
  • Application security
  • AWS
  • CI/CD
  • Cloud Security
  • Cloudflare
  • Code Review
  • Detection Engineering
  • GCP
  • GitHub
  • Incident Response
  • OAuth
  • Risk Management
  • SaaS Security
  • SAST
  • Secrets Scanning
  • Security Hygiene
  • Security Tooling
  • Vibe Coding
  • Vulnerability Management

Why Apply

This role is ideal for someone skilled in AI-assisted development security. You'll work with AI tools like Claude and help build secure AI coding environments, crucial for Savvy's AI-native approach.

What You'll Be Doing

You'll identify and remediate security vulnerabilities in Savvy's products and SaaS tools, ensuring secure AI-assisted development. Collaborating with the internal AI team, you'll set security standards and build guardrails for AI coding.

Working in NYC Office, United States

  • NYC is a global tech hub with a vibrant job market, offering numerous opportunities in fintech and AI.
  • The city boasts an extensive public transit system, making commuting to the Manhattan office convenient.
  • NYC offers a dynamic lifestyle with cultural diversity, world-class dining, and entertainment options.
  • Living in NYC provides access to numerous networking events and professional meetups, enhancing career growth.

Pay and Career Growth

Savvy Wealth offers a competitive salary and equity package, along with unlimited PTO and comprehensive health benefits. The company is in a high-growth phase, backed by significant venture capital, providing ample career advancement opportunities.

Benefits and Perks

  • 401k
  • Commuter plans
  • competitive salary
  • Counseling services
  • Dental plans
  • Equity Package
  • Health concierge
  • HSA/FSA plans
  • Medical plans
  • Office snacks
  • Unlimited PTO
  • Virtual mental health care
  • Vision plans

Is This Role Right for You?

Good fit if you...

  • Experienced in application security with a focus on AI-assisted development.
  • Comfortable working independently in a fast-paced environment.
  • Strong communicator who can articulate security risks to both technical and non-technical stakeholders.

May not be for you if...

  • Looking for a remote or hybrid work arrangement.
  • Prefers a compliance-focused security role with audits and certifications.
  • Uncomfortable with AI tools and AI-driven development environments.

Original Job Description

About Savvy Wealth:
Wealth management is a $545 billion industry that still runs on manual work. 75% of advisors offer no digital communication beyond email, and most still build financial plans by hand in Excel. Savvy is reinventing what it looks like to be a financial advisor. Founder Ritik Malhotra saw the fragmentation firsthand after seeking out his own advisor, and started Savvy to give independent advisors a modern, AI-native home.
Savvy is a registered investment advisor (RIA), and we partner with experienced financial advisors who want to grow without running the back office themselves. Advisors bring their book and join Savvy, running under their own brand (or ours), and Savvy earns a percentage of the assets they manage. In return, they get a true business-in-a-box: a proprietary tech platform and client portal, an in-house marketing team that helps them grow, a world-class investment management team, and a dedicated client services team that runs day-to-day operations and support. Advisors at Savvy service up to 50% more households and save 19 hours a week.
AI runs through everything we do. On the product side, Savvy Intelligence (released April 2026) is the only AI built for wealth managers that can see a client’s complete financial picture. Internally, everyone at Savvy uses Claude and is encouraged to experiment with it, backed by a dedicated AI enablement team and a RevOps org building agents in-house.
We’re a Series B company hitting our stride, with roughly 150 employees and over 500% year-over-year growth, backed by $105M from Thrive Capital, Index Ventures, Canvas Ventures, and Mark Casady (former CEO of LPL Financial). Come help us scale!

Recognition:
We’re a Certified Great Place to Work and have been honored for our culture and our growth:

Newsweek’s America’s Greatest Startup Workplaces (2026)

Fortune Best Workplaces in New York™ (2026)

Great Place to Work Certified™
The Role
We are seeking a Senior Application Security Engineer to join Savvy Wealth at our NYC headquarters. This is a hands-on, in-the-weeds engineering role. You will execute the security strategy set by our Director of IT & Information Security and our CTO, with day-to-day work centered on identifying vulnerabilities, remediating them, and closing the longer-term gaps that make us exposed, both in our product and in the SaaS tools our teams use every day.
Savvy is an AI-forward company. Most of our engineering is AI-assisted, and we enable people across the business, including non-technical roles, to build with AI coding tools. That enablement is a core part of how we work, and we intend to keep it. Your job is to make it safe: setting security hygiene standards in our codebases, building guardrails around AI-assisted development, and partnering closely with our internal AI team so that speed and security move together. You will make the secure path the easy path.
This role is deliberately not a compliance or GRC position. There are no audits to run, no certifications to chase, and no questionnaires to fill out. This is purely technical security work: finding and eliminating the vectors that make us vulnerable.

Responsibilities:

Own vulnerability management end to end: identify, triage, prioritize by real-world risk, and drive remediation to closure across our product, codebases, and cloud infrastructure (AWS, GCP, Cloudflare)

Build and operate our AppSec tooling pipeline: secrets scanning in CI and at the git layer, SCA/dependency scanning with triage SLAs, and SAST rollout on our most sensitive repos, tuned for signal over noise

Set and enforce security hygiene standards within our codebases, including code review standards that explicitly account for AI-generated code (authorship transparency, mandatory human review on security-sensitive paths)

Partner with our internal AI team to design guardrails that keep AI-assisted development, including vibe coding by non-technical builders, safe by default: sanctioned tooling, data handling boundaries, dependency vetting, and secure defaults for AI-built integrations

Secure the SaaS stack: harden configurations, review OAuth grants and third-party integrations, reduce misconfiguration risk across platforms like Google Workspace, GitHub, Rippling, and Slack

Help establish conditional access and identity-layer controls in partnership with IT (SSO, phishing-resistant MFA, managed-device posture)

Define cloud and SaaS configuration baselines for the infrastructure footprint we operate

Contribute to detection and response readiness: high-signal detections (new OAuth grants, mass code-host downloads, credential anomalies) and participate in incident response when needed

Work cross-functionally with Engineering, IT, and the internal AI team; clearly articulate risk, remediation paths, and tradeoffs to both technical and non-technical stakeholders

Must have:

5+ years of hands-on security engineering experience, with significant time in application security or product security

Strong software engineering fundamentals; comfortable reading, writing, and remediating code, not just filing findings

Deep experience with the modern AppSec toolchain: secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration (GitHub-centric)

Practical experience securing SaaS environments: OAuth and third-party app review, configuration hardening, and least-privilege access design

Working knowledge of cloud security across AWS and/or GCP, and edge/CDN security (Cloudflare)

A pragmatic, risk-based mindset: you prioritize by what actually gets exploited, ship iteratively, and avoid drowning teams in noise

Strong perspective on AI-assisted development security: you understand how AI coding tools change the shape of AppSec risk (hallucinated dependencies, leaked secrets, insecure patterns at scale) and how to build guardrails without killing velocity

Track record of partnering with engineering teams as an enabler, embedding security into existing workflows rather than bolting it on

Excellent communication skills and ability to work independently in a fast-paced environment

Strong writing skills; Savvy is a written culture

Nice to have:

Experience building security programs at an early-to-mid stage company, taking a function from reactive to systematic

Experience with SaaS security posture management, CSPM, or identity threat detection

Familiarity with securing LLM-based tooling, agentic workflows, or internal AI platforms

Detection engineering experience (SIEM/MDR, high-signal alerting)

Fintech or financial services environment experience

Offensive security background (pentesting, bug bounty, red team) that informs how you defend
Benefits:

Competitive salary and equity package

Unlimited PTO + paid company holidays

Access to holistic medical, dental, and vision plans

Company 401(k), Commuter, and HSA/FSA plans

NYC office in the heart of Manhattan

Lunch and snacks provided in the office

Access to virtual mental health care (Spring Health) and health concierge (Rightway) to help you find the right care

Access to counseling for stress management, dependent care, nutrition, fitness, legal, and financial issues (Guardian WorkLifeMatters EAP)