3,177 application security jobs at 1,330 companies in United States
🚀PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yrOn-SiteFull Time
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
D&H Distributing: Distributes technology products and IT solutions to resellers.
3+ YOEDesigns and implements secure software practices; assesses application security; supports SDLC; proficient in at least one programming language; familiar with OWASP Top 10; experience with security assessments and vendor security.
CVS HealthNYSE: CVS: Provides retail pharmacy, health insurance, and pharmacy benefit management services.
12+ YOE5+ Mgmt12+ years in information security with 5+ years leading application security; hands-on software development experience; expertise in SAST, DAST, SCA, WAF, CI/CD, cloud-native and secure SDLC; strong leadership and communication.
Simpson Thacher & Bartlett: Provides legal advisory and litigation services to global corporations.
10+ YOE5+ Mgmt10+ years in application security; hands-on with web apps, APIs, cloud, containers; leadership of enterprise security programs; strong collaboration and communication.
Prosper: Peer-to-peer lending marketplace for personal loans and credit.
10+ YOE3+ Mgmt10+ years in application security; 3+ years people leadership; strong security tooling, CI/CD, cloud (GCP); BS CS or related field; proficient in multiple programming languages.
Awardco: Software platform for employee recognition and corporate rewards programs.
6+ YOE6+ years in application security or secure software engineering; cloud SaaS security; web/API security; experience with SAST/DAST and CI/CD; mentoring developers.
SmartRentNYSE: SMRT: Provides smart home and building automation for rental housing.
4+ YOE4–6 years in application security; secure SDLC; cloud and web security; strong communication; experience with OWASP, SAST/DAST/SCA; AWS and WAF knowledge.
Oneleet: Provides an all-in-one cybersecurity and compliance automation platform.
5+ YOE5+ years of application security experience; skilled in Go, Python, or TypeScript; experienced with production security tooling; strong communication; startup experience.
Salmon: AI-powered neobank providing digital banking and consumer credit services.
7+ YOE7+ years in application security with secure SDLC ownership, threat modeling, vulnerability management, mobile security testing, supply chain risk management, and ability to script in Python or Bash.
HeartFlowNASDAQ: HTFL: Provides AI-driven non-invasive cardiac diagnostic software and analysis.
5+ YOE5+ years experience, ≥1 year in application security or security work in development; BS or equivalent/certifications; experience with secure SDLC, threat modeling, SAST/DAST/SCA, and vulnerability management.
The Wolfe Companies: Provides comprehensive gift card management and fintech gifting solutions.
2+ YOE2+ years in application security/DevSecOps or software development with security exposure; coding background; CI/CD and secure-coding knowledge; bachelor\u0002s degree in related field (or equivalent experience).
Snyk, SemGrep, Cycode, GitHub, GitLab, Jenkins, AWS DevOps, OWASP, SANS CWE Top 25, DSOMM, BSIMM, AI/ML, LLM
Sequoia: A business advisory firm specializing in employee compensation and benefits.
5+ YOE5+ years in application security or application development; 3+ years programming (Python, Ruby, Go, Swift, Java, .Net, C++); 2+ years threat modeling/secure coding or related; appsec tooling, SAST/DAST, AWS; Bachelor's in CS.
5+ YOE5+ years OWASP, SAST, DAST, SCA, RASP; 7+ years in application security or related field; strong web security knowledge; secure SDLC; Bachelor's in CS; CISSP/OSCP/CASE preferred.
4+ YOE4+ years in application security or software security engineering; writing production code; strong auth: OAuth 2.0, OIDC, SAML; experience with AWS and containers; Go/TypeScript; security tooling; incident response.
Ivo: AI-powered contract review and intelligence platform for legal teams.
4+ YOE5+ years in application security; hands-on web pen testing; TypeScript/Node and Python; cloud security in GCP/Azure; manage pen tests; secure coding; strong communication.