First Dedicated Security Engineer
Directly addresses vibe coding: building guardrails and secure defaults for AI-assisted and non-technical "vibe" coding workflows.
About the Role
Senior Application Security Engineer based in NYC as Savvy Wealth's first dedicated security hire. Hands-on role executing AppSec strategy across product and SaaS tooling, focusing on vulnerability management, CI/CD/security tooling, cloud/SaaS hardening, and building guardrails for AI-assisted and 'vibe' coding workflows.
Job Description
Role
Savvy Wealth is hiring a Senior Application Security Engineer to be the companyβs first dedicated security hire at their NYC headquarters. This is a hands-on engineering role focused on technical AppSec work β finding and remediating vulnerabilities across product, codebases, cloud infrastructure, and the SaaS stack β and designing security guardrails for AI-assisted development.
Key Responsibilities
- Own vulnerability management end-to-end: identify, triage, prioritize by real-world risk, and drive remediation to closure across product, codebases, and cloud infrastructure (AWS, GCP, Cloudflare).
- Build and operate the AppSec tooling pipeline: secrets scanning in CI and at the git layer, SCA/dependency scanning with triage SLAs, and SAST rollout for sensitive repositories.
- Set and enforce security hygiene standards, including code review processes that account for AI-generated code and require human review on security-sensitive paths.
- Partner with the internal AI team to design guardrails for AI-assisted development and non-technical βvibeβ coding: sanctioned tooling, data handling boundaries, dependency vetting, and secure defaults.
- Secure SaaS configurations and integrations (OAuth reviews, third-party apps) across platforms such as Google Workspace, GitHub, Rippling, and Slack.
- Help establish conditional access and identity-layer controls (SSO, phishing-resistant MFA, managed-device posture) in partnership with IT.
- Define cloud and SaaS configuration baselines and contribute to detection and response readiness and incident response when needed.
- Communicate risk, remediation plans, and tradeoffs clearly to both technical and non-technical stakeholders.
Requirements
- 5+ years of hands-on security engineering experience, with significant time in application or product security within a small security team.
- Strong software engineering fundamentals: ability to read, write, and remediate code (not just file findings).
- Proven ability to enforce security across technical and non-technical teams without obstructing workflows.
- Experience embedding security into existing workflows and CI/CD (GitHub-centric).
- Deep familiarity with AppSec toolchain: secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration.
- Practical experience securing SaaS environments: OAuth and third-party app review, configuration hardening, least-privilege access design.
- Working knowledge of cloud security (AWS and/or GCP) and edge/CDN security (Cloudflare).
- Risk-based mindset that prioritizes exploitability and high-value remediation.
- Strong communication and writing skills and ability to work independently in a fast-paced environment.
Nice to have
- Experience building security programs at early-to-mid stage companies.
- Experience with SaaS security posture management (CSPM) or identity threat detection.
- Familiarity with securing LLM-based tooling, agentic workflows, or internal AI platforms.
- Detection engineering experience (SIEM/MDR, high-signal alerting).
- Fintech or financial services experience.
- Offensive security background (pentesting, bug bounty, red team).
Benefits
- Competitive salary and equity package
- Compensation Range: $220,000 - $235,000
- Unlimited PTO plus paid company holidays
- Medical, dental, and vision plans
- Company 401(k), commuter benefits, HSA/FSA plans
- NYC office in Manhattan; lunch and snacks provided
- Access to virtual mental health care (Spring Health) and health concierge (Rightway)
- Employee assistance program (Guardian WorkLifeMatters)