Full-Time

Lead Security Engineer

Posted on 5/12/2025

TripleLift

TripleLift

201-500 employees

Programmatic advertising solutions and creative services

No salary listed

Senior, Expert

Pune, Maharashtra, India

In Person

Category
Cybersecurity
IT & Security
Required Skills
Python
JavaScript
Java
AWS
Go
Requirements
  • 8+ years of experience in security engineering or cloud security roles, with proven expertise in securing cloud-native, highly distributed environments.
  • Strong programming proficiency in Java, Javascript, GoLang and/or Python with a focus on secure coding, automation, and infrastructure tooling.
  • Deep hands-on experience with AWS services such as IAM, Security Hub, GuardDuty, VPC, S3, CloudTrail, CloudWatch, Config, and Lambda.
  • Proficient in the use of SIEM systems, IDS/IPS, vulnerability scanning, and penetration testing tools.
  • Strong understanding of cloud networking concepts including VPC peering, security groups, NACLs, private link, and hybrid connectivity (VPN/direct connect).
  • Understanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of: PCI, SOC2, HITRUST, ISO 27001/2, or similar is a plus.
  • Holds a Cybersecurity certification, e.g. CISSP, CISA, Security+, or AWS Certified Security Specialty.
Responsibilities
  • Oversee and manage cloud infrastructure components, ensuring proper configuration, resource provisioning, and adherence to security best practices for AWS.
  • Collaborate with engineering teams to integrate security into CI/CD pipelines, version control systems, and infrastructure as code practices.
  • Design and implement secure network architectures aligned with a zero-trust model.
  • Develop and maintain robust IAM policies, roles, and permissions, implementing least privilege access controls, multi-factor authentication, and identity federation across cloud platforms.
  • Architect, implement, and maintain an endpoint privilege management strategy to enforce least privilege principles across all user workstations and servers.
  • Establish and manage security monitoring tools, SIEM systems, and incident response processes to detect, respond, and mitigate security incidents in cloud environments.
  • Implement and maintain compliance controls, ensuring adherence to industry regulations and cloud-specific compliance requirements.
  • Assess security risks, identify vulnerabilities, and propose effective solutions to mitigate risks within cloud environments.
  • Stay up-to-date with cloud security best practices, emerging trends, and technologies.
  • Collaborate effectively with cross-functional teams and stakeholders to communicate security requirements, provide guidance on secure cloud practices, and ensure alignment with organizational objectives.
Desired Qualifications
  • Proven ability to lead technical projects independently with minimal oversight, from design to deployment.
  • Track record of mentoring junior engineers and influencing secure design across multiple teams.
  • Strong communication skills with the ability to translate technical concepts for engineering, product, and compliance stakeholders.
  • Comfortable engaging cross-functionally (engineering, DevOps, legal, compliance) to drive security improvements and cultural change.
  • Experience integrating security controls in CI/CD pipelines, including GitHub Actions or similar.
  • Proven ability to analyze and effectively address security issues and incidents.
  • Experience supporting internal audits, user access reviews, and policy exception workflows using tools like Jira or GRC platforms.
  • Openness to adapt in response to emerging cloud technologies and security threats.
  • Receptive to feedback and open to constructive criticism for continuous improvement.

TripleLift specializes in programmatic advertising, using automated technology to buy and sell online ads across various formats like online video, Connected TV (CTV), display ads, and native ads. The company is integrated with leading Demand-Side Platforms (DSPs), allowing clients to access diverse advertising experiences easily. Unlike many competitors, TripleLift emphasizes privacy and transparency in its advertising practices, building trust with consumers and clients. Their goal is to provide effective, privacy-conscious advertising solutions that help brands engage their audiences.

Company Size

201-500

Company Stage

Acquired

Total Funding

$1.4B

Headquarters

New York City, New York

Founded

2012

Simplify Jobs

Simplify's Take

What believers are saying

  • Partnership with DIRECTV for programmatic pause ads showcases innovative ad format leadership.
  • Collaboration with Scope3 aligns with sustainability trends, attracting eco-conscious brands.
  • Partnership with iSpot enhances data analytics, offering precise targeting and measurement.

What critics are saying

  • Layoffs in early 2023 may indicate financial instability or restructuring challenges.
  • Sustainability initiatives may increase scrutiny and operational costs if not managed well.
  • Programmatic Pause Ads may face user acceptance challenges, affecting their success.

What makes TripleLift unique

  • TripleLift uses computer vision to create ads that blend with user experience.
  • The company offers innovative ad solutions across online video, CTV, and native ads.
  • TripleLift is integrated with leading DSPs, providing easy access to diverse ad formats.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical, dental, & vision

Unlimited PTO

401k w/ employer match

Short-term & long-term disability insurance

Company-wide weekly events

Learning & development

Tenure celebrations

Work-life balance

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
AdExchanger
Jul 11th, 2025
TripleLift Quietly Lays Off A Double-Digit Percentage Of Its Workforce

Turning back the clock, in early 2023 TripleLift laid off more than 100 employees in the US and Canada, which translated to roughly one-fifth of its workforce.

TripleLift
Jul 1st, 2025
Shaping the Future of Advertising: Two Case Studies From TripleLift and Vodafone

Vodafone partnered with TripleLift to evaluate the impact of native advertising on brand perception, leveraging Sticky's eye-tracking technology to go beyond standard performance metrics.

Streaming Better
Jun 10th, 2025
DirecTV And TripleLift Partner To Launch Programmatic Pause Ads

DirecTV and TripleLift have teamed up to launch programmatic pause ads.

MarTech Series
Jun 10th, 2025
TripleLift Expands Creative Leadership with Launch of Programmatic Pause Ads in Partnership with DIRECTV Advertising

In the latest demonstration of its leadership in developing unique creative formats, TripleLift, the world's leading Creative SSP, announced the launch of programmatic Pause Ads in partnership with DIRECTV Advertising.

TripleLift
Apr 25th, 2025
TripleLift Drives Awareness for Mastercard's Partnership with Stand Up to Cancer

Mastercard collaborated with TripleLift to launch Native Image and Native Scroll formats designed to capture audience attention and enhance engagement.

INACTIVE