Skip to main content
NBCUniversal

Staff Application Security Engineer

RemoteUnited States only
Published
Role
Security
Experience
Staff
Employment
Full-time
Company size
Enterprise
$120k–$145k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Staff-level application security engineer with 8+ years in AppSec, Security Engineering, DevSecOps, Software Engineering, or related technical work. Needs strong Python or similar scripting, AppSec tooling integration, software supply chain security, automation, and secure AI workflow familiarity. Fully remote, US-based role signaled by New York location and US benefits.

Core skills

PythonCI/CD securityApplication Security

Required skills

SASTSCAsecrets detectioncontainer securityvulnerability management

Optional skills

SnykWiz CodeGitHub Advanced SecurityCheckmarxVeracodeKubernetesinfrastructure as codeCSPM

What you'll do

  • Design, build, and improve application security capabilities that support secure software development across NBCUniversal.
  • Build reusable security automations, integrations, APIs, workflows, and developer tools that reduce manual effort and improve scalability.
  • Implement secure-by-default golden paths, paved roads, and engineering patterns that make secure development easier to adopt.
  • Design and implement scalable security solutions spanning source code, open source dependencies, containers, cloud-native applications, CI/CD pipelines, infrastructure as code, developer platforms, and software supply chains.
  • Partner with Cloud Security on capabilities spanning application code, containers, CI/CD, infrastructure as code, cloud platforms, and software supply chain workflows.
  • Improve vulnerability prioritization, triage, remediation, validation, reporting, and speed to remediation.
  • Build security patterns, guardrails, and reusable implementations that support safe use of AI-assisted development tools and coding assistants.
  • Build capabilities that secure agentic workflows, AI-enabled developer tooling, and machine-assisted software delivery.
  • Use automation and AI-enabled techniques to improve vulnerability triage, remediation planning, developer guidance, and workflow efficiency.
  • Build integrations between application security platforms, GitHub, CI/CD systems, developer portals, ticketing systems, reporting platforms, and other engineering tools.
  • Create telemetry, dashboards, and reporting pipelines for actionable visibility into application risk, coverage, and remediation progress.
  • Serve as a senior technical expert for application security engineering, secure software development, software supply chain security, and secure AI development.
  • Partner with architects, platform engineers, cloud security engineers, and development teams to turn security direction into working technical solutions.
  • Mentor engineers and improve the team’s engineering practices, automation skills, and technical depth.

What they require

  • 8+ years of experience in Application Security, Security Engineering, DevSecOps, Software Engineering, or a related technical field.
  • Deep experience with secure software development, application security, vulnerability management, and software supply chain security.
  • Hands-on experience building security automations, integrations, APIs, platforms, developer tooling, or similar engineering solutions.
  • Strong software engineering and scripting skills using Python or similar languages.
  • Hands-on experience integrating AppSec technologies such as SAST, SCA, secrets detection, container security, CI/CD security, and vulnerability management into developer workflows.
  • Ability to solve complex, ambiguous technical problems and influence adoption through implementation, documentation, and collaboration.
  • Familiarity with AI-assisted development, agentic workflows, and related security considerations.
  • Preferred: Experience building secure developer platforms, internal tools, paved roads, golden paths, or reusable engineering services.
  • Preferred: Experience across AppSec and CloudSec domains, including cloud-native architectures, containers, Kubernetes, infrastructure as code, CI/CD security, CSPM, CNAPP, or related technologies.
  • Preferred: Experience with software supply chain security, SBOM capabilities, dependency risk workflows, or artifact security processes.
  • Preferred: Experience using AI to improve vulnerability management, remediation workflows, security operations, or developer productivity.
  • Fully Remote : This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee’s residence.
  • External candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision.

Benefits

  • This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks.
  • Bonus eligible

American media and entertainment conglomerate

🇺🇸 United StatesMediaEnterprisenbcuniversal.com
$120k–$145k/yr