AppSec Jobs
← Back to all jobs

BNY

Vice President, Information Security full Stack Engineer

New York, NY / Pittsburgh, PAPosted 2 weeks ago$83,000 - $178,000 per yearWebsite
Apply on LinkedIn →

At a Glance

10+ years experiencePythonJavaKubernetesDockerOWASP

About This Role

At BNY, our culture allows us to run our company better and enables employees' growth and success. As a leading global financial services company at the heart of the global financial system, we influence nearly 20% of the world's investible assets. Every day, our teams harness cutting-edge AI and breakthrough technologies to collaborate with clients, driving transformative solutions that redefine industries and uplift communities worldwide. Recognized as a top destination for innovators and champions of inclusion, BNY is where bold ideas meet advanced technology and exceptional talent. Together, we power the future of finance – and this is what #LifeAtBNY is all about. Join us and be part of something extraordinary. We're seeking a future team member for the role of Vice President, Information Security full Stack Engineer to join our Cyber Technology team. Our Cyber Technology team builds and enhances secure applications that protect our enterprise IT environment. You'll develop internal platforms and tools used by cybersecurity teams to improve visibility, automate workflows, and strengthen controls across identity, endpoints, and network defenses. This role blends hands-on product delivery with secure engineering practices in a regulated financial services environment, with an emphasis on modern developer productivity and responsible use of AI-assisted tooling.

Responsibilities

  • Build and maintain full-stack web applications and services using modern engineering patterns
  • Design and consume REST and gRPC APIs with an emphasis on reliability, security, and maintainability
  • Apply secure coding standards (e.g., input validation, authentication/authorization, dependency hygiene, secrets handling)
  • Support vulnerability remediation efforts by addressing findings from scanning tools and security reviews
  • Create dashboards and reporting experiences that provide actionable insights (e.g., control health, risk posture, remediation progress)
  • Automate recurring operational processes to improve efficiency, reduce human error, and increase auditability
  • Collaborate with IAM, network security, endpoint, and governance teams to align applications with security strategy and controls
  • Participate in security assessments and contribute to compliance efforts aligned with organizational standards
  • Independently diagnose and resolve issues across the stack (frontend, backend, CI/CD, environments)
  • Contribute to documentation, runbooks, and operational best practices as needed
  • Apply DevOps/CI/CD and SDLC best practices including code reviews, testing, and release pipelines
  • Leverage modern AI-assisted development tools to improve code quality, velocity, and maintainability where appropriate

Requirements

JavaPythonOWASPDockerKubernetes
  • Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent work experience
  • 6 to 10 years of experience in software engineering with hands-on delivery
  • Deep understanding of a programming language such as C# or Java or Python (or similar), and delivering those solutions via production services
  • Experience developing APIs and integrations (REST/gRPC), including testing and basic observability (logs/metrics)
  • Hands-on experience with React or Angular (SwiftUI experience is a plus)
  • Familiarity with vulnerability management concepts and secure SDLC practices
  • Awareness of common application security risks (e.g., OWASP Top 10) and how to mitigate them
  • Practical understanding of core networking protocols and enterprise environments (e.g., TCP/UDP, SNMP, firewalls, proxies)
  • Working knowledge of Windows and Linux administration fundamentals
  • Experience using Python scripting to automate workflows and integrate systems/tools
  • Familiarity with IAM concepts (SSO, MFA, RBAC, OAuth/OIDC) and general Zero Trust principles
  • Strong problem-solving and communication skills; able to deliver independently while collaborating in a team
  • Experience building dashboards and reporting (security KPIs, trend reporting, operational metrics)
  • Familiarity with cloud platforms and containerization (Docker/Kubernetes) and secure deployment practices
  • Experience building client-server applications for macOS and Windows
  • Experience using AI-assisted development tools (e.g., Windsurf, Cursor, or similar) to accelerate development, refactoring, testing, or code comprehension in a secure and responsible manner

Benefits & Perks

Highly competitive compensation
Benefits and wellbeing programs
Pay-for-performance philosophy
Access to flexible global resources and tools
Health and personal resilience support
Financial goals assistance
Generous paid leaves
Paid volunteer time

About BNY

BNY Mellon, officially known as The Bank of New York Mellon Corporation, is a global financial services company founded in 1784. Headquartered in New York City, it is the world's largest custodian bank and securities services provider, managing over $55 trillion in assets for clients around the globe. The company has a rich history, having played a significant role in financing key U.S. infrastructure projects and pioneering innovations in financial technology. BNY Mellon specializes in institutional financial services, focusing on securities services and custody, asset management, investment services, and capital markets. Its technology-driven platforms enhance efficiency and support real-time payments, catering to a diverse range of clients, including Fortune 100 companies and leading investment managers. The company is committed to fostering long-term relationships and driving growth and resilience in the financial ecosystem.

Industry

financial services

Employees

51,000

4848 engineers

Revenue

$40B

Website

Visit →

Security at BNY

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • BNY's AppSec mission is to "defend future global capital markets through cyber resiliency." The team emphasizes developer enablement through the provision of reusable templates, libraries, and reference implementations.
  • Application Security strives to reduce risk by improving the security profile of high-risk applications, with a focus on embedding security controls across the SDLC, CI/CD, and MLOps pipelines.

Security Team

The AppSec team at BNY operates with limited public visibility regarding organizational structure and reporting lines. As of, there is 1 active AppSec job posting. The team focuses on SAST, DAST, IAST, dependency and SBOM governance. No public org chart or explicit reporting line to CISO/CTO has been found.

Key Initiatives

  • The team is focused on shifting left by embedding security controls across the SDLC, CI/CD, and MLOps pipelines.
  • Vulnerability Management is defined and operated to identify, quantify, classify, prioritize, and address vulnerabilities.
  • A formalized secure SDLC program is integrated with each phase of the development life cycle.
  • Recent initiatives include the integration of security controls into MLOps pipelines.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn