1

Shadow Security Jobs in New York (NOW HIRING)

Sr. Application Security Manager

New York, NY · On-site

$64.25 - $86/hr

Oversee DV's API security program (OWASP API Security Top 10, e.g., Escape API Security) and attack surface management (ASM) capabilities, including discovery of shadow/zombie APIs. * Assist with Web ...

This is a security engineering role focused on building scalable controls and automation across ... shadow IT, and configuration drift. * Write code (Python, Terraform) to automate access reviews ...

Senior Staff Security Engineer, AI Security

New York, NY · On-site

$125K - $171K/yr

As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest technical ... Build and scale Ripple's Shadow AI detection capability, surfacing unsanctioned AI usage, driving ...

New

AI Security Specialist

New York, NY · On-site

$140K - $180K/yr

Threat Detection - Monitor for AI-specific threats: prompt injection, model poisoning, data exfiltration via LLMs, and shadow AI usage. * Vendor & Model Review - Conduct security reviews of AI ...

AI Security Specialist

Manhattan, NY · On-site

$140K - $180K/yr

Threat Detection - Monitor for AI-specific threats: prompt injection, model poisoning, data exfiltration via LLMs, and shadow AI usage. * Vendor & Model Review - Conduct security reviews of AI ...

AI Security Specialist

Manhattan, NY · On-site

$140 - $180/hr

Threat Detection -- Monitor for AI-specific threats: prompt injection, model poisoning, data exfiltration via LLMs, and shadow AI usage. * Vendor & Model Review -- Conduct security reviews of AI ...

Threat Detection -- Monitor for AI-specific threats: prompt injection, model poisoning, data exfiltration via LLMs, and shadow AI usage. * Vendor & Model Review -- Conduct security reviews of AI ...

This is a security engineering role focused on building scalable controls and automation across ... shadow IT, and configuration drift. * Write code (Python, Terraform) to automate access reviews ...

AI Security Specialist

Manhattan, NY · On-site

$140K - $180K/yr

Threat Detection - Monitor for AI-specific threats: prompt injection, model poisoning, data exfiltration via LLMs, and shadow AI usage. * Vendor & Model Review - Conduct security reviews of AI ...

Senior Staff Security Engineer, AI Security

New York, NY · On-site

$125K - $171K/yr

As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest technical ... Build and scale Ripple's Shadow AI detection capability, surfacing unsanctioned AI usage, driving ...

New

next page

Showing results 1-20

Shadow Security information

See New York salary details

$31.2K

$48.1K

$64.5K

How much do shadow security jobs pay per year?

As of Aug 24, 2026, the average yearly pay for shadow security in New York is $48,097.00, according to ZipRecruiter salary data. Most workers in this role earn between $41,600.00 and $52,000.00 per year, depending on experience, location, and employer.

What is shadow security?

Shadow Security professionals are experts who deal with unauthorized or unapproved security measures, tools, or processes within an organization. They identify hidden or unofficial security practices—often referred to as 'shadow security'—which can arise when employees implement their own solutions outside the official IT or security protocols. These professionals work to ensure that all security practices are standardized, compliant, and do not introduce vulnerabilities. Their role is crucial in minimizing risks associated with unvetted security tools and maintaining robust cybersecurity across the organization.

What are the key skills and qualifications needed to thrive as a shadow security professional?

To thrive as a Security Guard, you need a strong understanding of safety protocols, situational awareness, and often a high school diploma or equivalent. Familiarity with surveillance systems, access control software, and sometimes state-required security certifications is typical. Strong communication, problem-solving, and the ability to remain calm under pressure are crucial soft skills. These skills and qualifications are vital for protecting people and property, responding effectively to incidents, and maintaining a safe environment.

What are some typical challenges faced by professionals working in shadow security roles, and how can they be addressed?

Professionals in Shadow Security roles often encounter challenges such as identifying and managing unauthorized IT assets or applications that operate outside standard security protocols. This can make it difficult to maintain visibility and enforce consistent security policies across the organization. Addressing these challenges involves proactive communication with other departments, implementing robust monitoring tools, and fostering a culture of security awareness. Collaboration with IT and compliance teams is essential to ensure that shadow IT risks are identified early and mitigated effectively.

What is the difference between Shadow Security vs Security Analyst?

AspectShadow SecuritySecurity Analyst
CertificationsTypically no formal certifications required, but knowledge of security tools helpsOften requires certifications like CompTIA Security+, CISSP, or CEH
Work EnvironmentPrimarily in cybersecurity teams, monitoring systems, and assisting security operationsAnalyzes security data, investigates incidents, and develops security strategies
Employer & Industry UsageUsed within cybersecurity teams, often as a role assisting or shadowing security analystsCommonly employed across industries to protect digital assets and infrastructure

Shadow Security typically involves assisting or observing security professionals without formal responsibilities, while Security Analysts actively monitor, analyze, and respond to security threats. Both roles are integral to cybersecurity teams, but Security Analysts have more defined responsibilities and certifications.

What training is needed for shadow security?

Shadow security roles typically require training in cybersecurity principles, network security, and surveillance techniques. Many positions prefer candidates with certifications such as CompTIA Security+ or Certified Ethical Hacker (CEH), along with experience in security systems and monitoring tools.

What are popular job titles related to Shadow Security jobs in New York?

For Shadow Security jobs in New York, the most frequently searched job titles are:

Infographic showing various Shadow Security job openings in New York as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $48,097 per year, or $23.1 per hour.

Sr. Application Security Manager

DoubleVerify

New York, NY • On-site

$64.25 - $86/hr

Full-time

Re-posted 10 days ago


Job description

Who we are
DoubleVerify is the leading independent provider of marketing measurement software, data, and analytics that authenticates the quality and effectiveness of digital media for the world's largest brands and media platforms. DV provides media transparency and accountability to deliver the highest level of impression quality for maximum advertising performance. Since 2008, DV has helped hundreds of Fortune 500 companies gain the most from their media spend by delivering best-in-class solutions across the digital ecosystem, helping to build a better industry. Learn more at www.doubleverify.com.
Role Summary
As Application & AI Security leadership within DV InfoSec, you will own and evolve DoubleVerify's Secure Software Development Lifecycle (SSDLC), application security, API security, and AI/LLM security. You will lead the people, processes, and tooling that keep DV's code, pipelines, cloud workloads, APIs, and AI systems secure, partnering across the engineering organization. (This role replaces and expands the scope of DV's Senior Application Security Manager position to formally include AI security ownership.)
Responsibilities
Application & Product Security
  • Own and evolve DV's application security program, including SAST, SCA, DAST, and Application Security Posture Management (ASPM) tooling (e.g., Ox Security) - advancing findings from non-blocking warnings toward enforced, risk-based merge gates.
  • Drive the OWASP Application Security Verification Standard (ASVS) adoption program across engineering repositories, including reporting, dashboards, and branch-level coverage.
  • Drive SBOM management, license compliance, and software supply chain security practices across development teams.
  • Partner with DevOps and engineering to embed security across the CI/CD pipeline and Secure SDLC (SSDLC).
  • Develop and maintain application security metrics and reporting for engineering leadership, including vulnerability burn-down and mean-time-to-remediate (MTTR).
  • Lead the bi-weekly vulnerability remediation touchpoints and the monthly Application Security Leadership Forums with engineering organizations (Pinnacle, Measurement, Programmatic, Architecture, Publisher, Social, QA, TechOps/SRE, CorpIT, DevOps, and M&A) to drive progress and accountability.
  • Oversee DV's API security program (OWASP API Security Top 10, e.g., Escape API Security) and attack surface management (ASM) capabilities, including discovery of shadow/zombie APIs.
  • Assist with Web Application Firewall (WAF) configuration, deployment, and monitoring.
  • Partner with DevOps/SRE on cloud and container security (e.g., Wiz) to deliver code-to-cloud coverage.
AI & Emerging Technology Security
  • Lead AI security governance, engineering, and threat assessment functions across DV's AI/ML ecosystem.
  • Secure AI agents, LLM-based applications, MCP gateway, and agentic SDLC workflows against threats such as prompt injection, jailbreaking, excessive agency, and supply chain compromise - including guardrails, telemetry, logging, and detections for developer AI tooling (Cursor, Claude Code, VS Code).
  • Evaluate and operationalize AI security platforms to provide detection, response, and AI supply chain governance across teams building or operating AI systems (e.g., AI security gateway, shadow-AI discovery/DLP, AI identity and software management).
  • Build threat models and controls for first- and third-party AI/ML workloads, including data pipelines, model provenance, and RAG architectures.
  • Advance AI-assisted security testing (e.g., DV's PromptFlow-driven web/API security test generation) to scale coverage across teams.
Security Engineering, Offensive Security & DevSecOps Enablement
  • Lead DV's offensive security and penetration testing program, working with external vendors and conducting internal security assessments.
  • Build and maintain security automation capabilities to reduce manual effort and increase detection coverage.
  • Partner with the DevOps and CloudOps organizations on cloud security (primarily GCP/Kubernetes), shared responsibility model execution, and infrastructure-as-code security.
  • Own and conduct threat modeling for DV products and infrastructure.
  • Deliver secure coding training and developer enablement programs across global engineering teams.
Team Leadership & Management
  • Recruit, onboard, and manage a team of security engineers and contractors, including software security developers and offensive security testers.
  • Set goals, track performance, and provide ongoing coaching and mentorship to team members.
  • Administer budgets, vendor relationships, and tool procurement within the security engineering function.
  • Collaborate cross-functionally with GRC, Security Operations, IT Security, Legal, and Privacy teams.
  • Meet with senior leadership, engineering managers, and developers across DV's global engineering departments on a regularly scheduled basis to share the security roadmap and best practices.
  • Represent the application security and AI security programs to senior leadership and in audit/compliance contexts (SOC 2, ISO 27001, NIST CSF 2.0).
Qualifications
  • 10+ years of progressive experience in information security, with at least 3 years in a technical management or lead role.
  • Demonstrated expertise in two or more of the following domains: application security, AI/ML security, software supply chain security, penetration testing, cloud security.
  • Hands-on experience with AppSec tooling such as SAST, SCA, DAST, ASPM platforms (e.g., Ox Security, Snyk, Veracode, Checkmarx) and API security.
  • Experience securing AI/ML systems, including familiarity with the OWASP Top 10 for LLMs, NIST AI RMF, agent architectures, and LLM attack vectors.
  • Proficiency in cloud-native environments, particularly GCP; experience with Kubernetes and infrastructure-as-code (e.g., Terraform) is highly desirable.
  • Experience managing or directly executing penetration testing programs (web, API, cloud, AI) and bug bounty programs.
  • Familiarity with DevSecOps principles and integrating security into CI/CD pipelines (GitLab/GitHub/GitOps/ArgoCD).
  • Strong understanding of software supply chain security: SBOM, license compliance, OSV/CVE triage, and dependency chain risk.
  • Experience collaborating with compliance and audit programs (SOC 2, ISO 27001) from a security engineering perspective.
  • Excellent written and verbal communication skills with demonstrated ability to present complex security topics to both technical and non-technical audiences.
  • Proficiency in at least one scripting/programming language (e.g., Python) for security automation.
  • Industry certification preferred (CISSP, CSSLP, GWAPT, OSCP, or equivalent).
  • Bachelor's degree or higher in Computer Science, Information Systems, or a related field, or equivalent technical experience.
Why This Role Matters
DV protects the integrity of digital advertising for the world's biggest brands. Securing the applications, APIs, pipelines, and AI systems behind that mission directly protects DV's customers, revenue, and reputation. You'll have executive support, real budget, modern tooling, and the mandate to build a best-in-class Application, AI, and Security Engineering program.
DoubleVerify is an equal opportunity employer.
The successful candidate's starting salary will be determined based on a number of non-discriminating factors, including qualifications for the role, level, skills, experience, location, and balancing internal equity relative to peers at DV.
The estimated salary range for this role based on the qualifications set forth in the job description is between [$153,000 - $260,000]. This role will also be eligible for bonus/commission (as applicable), equity, and benefits.
The range above is for the expectations as laid out in the job description; however, we are often open to a wide variety of profiles, and recognize that the person we hire may be more or less experienced than this job description as posted.
Not-so-fun fact: Research shows that while men apply to jobs when they meet an average of 60% of job criteria, women and other marginalized groups tend to only apply when they check every box. So if you think you have what it takes but you're not sure that you check every box, apply anyway!