Summary
✨ AI‑Generated
Join an application security program focused on embedding security into business applications and data from the start. You will help define and promote secure development practices, assess application security, and measure security outcomes while collaborating with technology professionals on high-impact digital services serving a large population.
Highlights
Contribute to security-by-design software across a large public-sector environment, work with modern technology, collaborate with experienced professionals, and deliver technology with broad public impact.
Description
The Office of Technology and Innovation (OTI) leverages technology to drive opportunity, improve public safety, and help government run better across New York City.
From delivering affordable broadband to protecting against cybersecurity threats and building digital government services, OTI is at the forefront of how the city delivers for New Yorkers in the 21st century.
Follow us on social media @NYCOfficeofTech, and visit www.nyc.gov/oti to learn more.
At OTI, we offer great benefits, and the chance to work on projects that have a meaningful impact on millions of people.
You'll have the opportunity to work with cutting-edge technology and collaborate with other passionate professionals who share your drive and commitment to making a difference through technology.
Job Description
The Application Security program defines, promotes, assures, and measures the security of business applications and data, empowering city agencies to build and operate secure-by-design software.
As a senior technical member of the team, the Senior Application Security Engineer serves as an expert-level specialist and lead resource for the Software Security Assurance Program (SSAP).
The selected candidate will be responsible for identifying, validating, and providing definitive remediation guidance for vulnerabilities across the City’s application portfolio.
This role focuses on operating and optimizing security scanning platforms, performing deep-dive manual validation, and serving as a key technical resource and mentor to guide other team members performing assessments.
Responsibilities will include:
Operate, configure, and optimize enterprise-level static, dynamic, and software composition testing platforms (SAST/DAST/SCA); Perform advanced manual testing and exploit reproduction to validate automated findings and uncover complex logic flaws; Partner with development teams across city agencies to translate vulnerability findings into actionable, design-level remediation requirements and coding guidance; Identify recurring vulnerability patterns and systemic security weaknesses to help shape long-term secure coding practices; Serve as the lead technical resource and mentor for internal team members performing scans and learning to execute full security assessments; Generate defensible, high-quality technical reports and executive summaries on application vulnerability statuses.
Handle special projects and initiatives as assigned.
HOURS/SHIFT
Day - Due to the necessary technical duties of this position in a 24/7 operation, candidate may be required to work various shifts such as weekends and/or nights/evenings.
WORK LOCATION
Brooklyn, NY
TO APPLY
Interested applicants with other civil service titles who meet the preferred requirements should also submit a resume for consideration
Please go to www.cityjobs/jobs/search and search for Job ID #791073
SUBMISSION OF A RESUME IS NOT A GUARANTEE THAT YOU WILL RECEIVE AN INTERVIEW
APPOINTMENTS ARE SUBJECT TO OVERSIGHT APPROVAL
OTI participates in E-Verify
IT SECURITY SPECIALIST - 95622
Minimum Qualifications
A baccalaureate degree from an accredited college and four years of satisfactory full-time experience related to projects and policies required by the particular position; or,
Education and/or experience which is equivalent to "1" above.
Preferred Skills
The successful candidate should possess the following: - At least 8 years of experience in cybersecurity, specializing in application security, vulnerability assessments, or penetration testing - Domain specialist in application security vulnerabilities, security testing methodologies, and enterprise testing platforms - Expertise in manual deep-dive validation testing to confirm technical risk and business impact - Proven experience explaining complex technical vulnerabilities to developers and providing specific, code-level remediation guidance - Demonstrated experience serving as a mentor or technical lead, assisting others in adopting assessment methodologies and security workflows - Strong understanding of modern software development pipelines (CI/CD), APIs, container security, and cloud-native application architectures - Excellent analytical and communication skills, with the ability to bridge the gap between technical teams and management.
Public Service Loan Forgiveness
As a prospective employee of the City of New York, you may be eligible for federal loan forgiveness programs and state repayment assistance programs.
For more information, please visit the U.S.
Department of Education’s website at https://studentaid.gov/pslf/.
Residency Requirement
New York City Residency is not required for this position
Additional Information
The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.