Staff Security Engineer, Application Security

NinjaTrader is a futures trading provider offering integrated desktop, web, and mobile trading platforms alongside futures brokerage services. It serves new and experienced active futures traders with market access, charting, simulation, education, and support.

Distributed

Funding history

Investors

About NinjaTrader

NinjaTrader provides futures brokerage and proprietary trading-platform services for retail and professional traders. Its offering includes access to global futures markets, trading and charting tools, market data, simulated trading, risk-management features, developer customization through a C# framework, education, and customer support. NinjaTrader Clearing, LLC provides brokerage services as a CFTC-registered futures commission merchant and NFA member.

View jobs by NinjaTrader

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You'll help scale and mature the security program by owning key security domains and initiatives end-to-end, working closely with engineering to ensure systems are secure by design. This role is highly hands-on, with opportunities to drive meaningful impact through automation, secure design, and developer enablement. You'll operate with significant autonomy while partnering with senior engineers and security leadership to scale security across the organization.

Requirements

  • 7+ years of experience in Application Security, Product Security, or Security Engineering.
  • Hands-on experience with threat modeling and secure design.
  • Experience with vulnerability management and application security tooling.
  • Experience in cloud-native environments such as AWS and GCP.
  • Experience integrating security into CI/CD pipelines and developer workflows.
  • Ability to write Python, Go, or similar languages for automation and tooling.
  • Strong cross-functional collaboration skills.
  • Bonus: experience scaling security in a high-growth or late-stage startup.
  • Bonus: familiarity with AI-driven security workflows or automation.
  • Bonus: API security, data protection, or multi-tenant systems experience.
  • Bonus: bug bounty and penetration testing experience.
  • Bonus: security certifications such as CISSP.

Responsibilities

  • Own vulnerability management, application security, API security, and supply chain security domains.
  • Improve security coverage, prioritization, and remediation workflows.
  • Integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows.
  • Provide pragmatic security guidance to engineering teams.
  • Develop security tooling and automation.
  • Implement and tune SAST, SCA, DAST, dependency, and container security tools.
  • Use AI and LLMs to improve triage, detection, and review processes.
  • Triage and prioritize vulnerabilities using risk-based approaches.
  • Define and improve SLAs, metrics, and reporting.
  • Conduct threat modeling, design reviews, and security assessments.
  • Contribute to incident response and security postmortems.
  • Identify and remediate systemic risks.

Benefits

  • Annual target bonus of 12%
  • 401K plan with company match up to 3.5%
  • 23 days paid time off per year
  • Seven paid holidays
  • 20 additional flex remote days annually
  • Five company-wide office-optional weeks
  • One annual service day
  • Paid parental bonding leave
  • Health, vision, and dental coverage
  • Life and disability insurance covered 100% by NinjaTrader
Staff Security Engineer, Application Security at NinjaTrader | JobStash