Security Engineer Jobs in New York, USA

Looking for a security engineer job in New York? Choose from 73 open roles at 32 employers. Explore real salary data and skills breakdown across remote, hybrid and on-site roles.

73 Open roles
32 Companies hiring
255K Average salary

What do Security engineers in New York work on?

The titles and summaries together point to three broad clusters of work. The first is defensive and detection-oriented: roles such as vulnerability management involve continuous scanning across multi-cloud environments, triaging findings, and coordinating remediation, as seen in the Datadog vulnerability management role. The second cluster is application and product security, where engineers embed into engineering teams to conduct threat modelling, review code, design secure APIs, and build automated controls using DevSecOps tooling — the Writer application security role is a clear example. The third and growing cluster is AI-specific security: protecting generative AI systems against prompt injection, jailbreaks, and anomalous agent behaviour, as described in the Point72 GenAI role and the Zscaler AI security specialist role. Across all clusters, most postings expect hands-on coding alongside security knowledge, not security awareness alone.

Skills and experience employers ask for

Python appears in the majority of postings, making it the most consistently mentioned skill in this sample of 72. Cloud platforms — AWS, GCP, and Azure — are each referenced in roughly a third to just over half the postings. Kubernetes, Terraform, and CI/CD appear in around a quarter to a third, reflecting the infrastructure-as-code and container-native environments these engineers work in. AI-specific terms such as agents and LLMs appear in a meaningful minority, consistent with the AI security titles in the sample. Counts reflect mentions in descriptions, not formal requirements.

Python 71%
AWS 53%
Kubernetes 38%
GCP 37%
Azure 34%
CI/CD 30%
Terraform 29%
Agents 26%
APIs 26%
LLMs 21%
TypeScript 15%
Java 15%
C\+\+ 15%
Evaluation 11%

Security Engineer roles that state a salary

The employers' own advertised ranges, for individual roles at different levels — not an average and not a market rate.

New York office, hybrid or remote?

Most postings in this sample specify onsite work, with a smaller proportion listed as hybrid. Only a handful indicate fully remote eligibility, so candidates who cannot commute to a New York office should check each posting carefully before applying. Hybrid arrangements, where stated, typically imply some weekly in-office presence, though the exact schedule is not stated in most postings. No postings have an unknown work mode in this set, meaning every listing does carry some location signal, even if it is simply "onsite".

Make your application specific to the work

  1. Read the full job description These roles vary considerably — offensive security, AI security, cloud infrastructure, and application security carry different day-to-day tasks and tool expectations. Confirm the specialisation and seniority match before investing time in an application.
  2. Prepare evidence of technical depth Most summaries expect hands-on coding alongside security knowledge; have examples ready of work in Python, cloud-native environments, or relevant security tooling such as SAST/DAST, Terraform, or container security.
  3. Check pay and visa details directly Fewer than half the postings in this sample advertise a pay range, and none of the postings state visa sponsorship availability; confirm both points on the employer's own listing before applying.
  4. Apply through the employer's listed channel Each posting links to the hiring employer; applications submitted there reach the relevant recruiting team directly and give you access to any updated requirements or closing information.

Questions about Security Engineer jobs in New York

Only a minority of postings on this page include an advertised pay range. Among those that do, figures vary widely by role and seniority — from around 150,000 at the lower end to over 400,000 at the top of the highest range. These are individual advertised ranges for specific roles, not a city-wide average, and the majority of postings do not disclose pay at all.

Most postings specify onsite work, with a smaller share listed as hybrid and only a few as fully remote. Every posting in this sample carries a stated work mode, so check the individual listing to confirm what is expected for the role you are interested in.

Python is mentioned in the majority of postings in this sample, making it the most common language reference. Java, TypeScript, and C++ each appear in a minority of postings. Several summaries also mention Go. Expectations differ by role type, so treat the skills table as a pattern guide rather than a universal requirement list.

Most postings either do not state a seniority level or specify senior or lead. Only one posting in this sample is marked as an internship. Entry-level and junior roles are not well represented in this current snapshot.

It appears as both. Some postings, such as those titled Staff AI Security Engineer or GenAI Security Engineer, treat it as a primary focus, including threat modelling for prompt injection, securing agent workflows, and LLM risk assessment. Others mention AI tools or LLMs as part of a broader infrastructure or application security role. The distinction is visible in the job titles and summaries on this page.

Jobs checked 4 hours ago. · Guide reviewed 9 September 2026.