AppSec Jobs
← Back to all jobs

The Depository Trust & Clearing Corporation (DTCC)

Cyber Security Architect - ZTNA

Jersey City, New Jersey, United StatesWebsite

Full details on LinkedIn

The complete job description, requirements, and application details are available on the original posting.


About The Depository Trust & Clearing Corporation (DTCC)

The Depository Trust & Clearing Corporation (DTCC) is a financial services company established in 1999, formed by the merger of The Depository Trust Company (DTC) and the National Securities Clearing Corporation (NSCC). Its mission is to automate and streamline processes in the capital markets, building on its origins from 1973 when DTC was created to enhance the clearing and settlement of securities. DTCC provides a wide range of services, including clearing, settlement, and information services for various financial instruments such as equities, bonds, and derivatives. It also processes mutual fund and insurance transactions, connecting funds with their distribution networks. With custody and asset servicing for millions of securities from the U.S. and over 130 countries, DTCC plays a vital role in the global financial system. Its key subsidiaries include DTC, NSCC, and the Fixed Income Clearing Corporation (FICC), each specializing in different aspects of financial transactions. DTCC serves a diverse clientele, including broker-dealers, institutional investors, and mutual funds, contributing to market efficiency and stability.

Industry

financial services

Employees

7,100

1503 engineers

Revenue

$2.5B

Website

Visit →

Security at The Depository Trust & Clearing Corporation (DTCC)

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

Embed security into the Software Development Life Cycle (SDLC) through automated, scalable DevSecOps practices and close collaboration with development, product and vendor teams. Emphasizes shift-left testing, continuous integration of SAST/DAST/SCA/container security into CI/CD pipelines, measurable vulnerability remediation SLAs, least-privilege access controls, encryption and proactive third-party risk management to support operational resilience and regulatory compliance.

Security Team

  • Team label: 'Application Security Assurance' (public job postings).
  • Mission: ensure secure software delivery enterprise-wide by integrating security into SDLC, collaborating with developers/product owners/vendors, and managing application risks.
  • Core responsibilities: execute/manage SAST and DAST scans, analyze scan results, coordinate remediation with development teams, integrate security tooling into CI/CD (shift-left), track metrics and document findings.
  • Organizational placement: within DTCC Information Technology / Technology Risk Management / Information Security context.
  • Locations & working model: Dallas / Coppell, TX.
  • Hybrid (3 days onsite, 2 days remote). Hiring profile: Associate and Senior Associate roles (example Senior Associate minimum ~6–8 years).
  • Preferred certifications include CSSLP, CASE, GSSP-JAVA/GSSP-.NET, CAST, GWAPT, OSWE, eWPT/eWPTX, PNPT.

Key Initiatives

  • Shift-left security and DevSecOps automation (CI/CD integration of security tools).
  • Programmatic SAST/DAST/SCA scanning with remediation tracking.
  • Container security and supply-chain software composition analysis.
  • Governance through ASPM/DAVS and VAST.
  • Adherence to vendor security requirements for penetration testing, incident response, encryption, logging/monitoring, least-privilege access and multifactor authentication.
  • Third-party risk management and periodic security assessments. Publicly noted absence of a DTCC-hosted public bug-bounty or formal public vulnerability disclosure program in reviewed sources.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.