3,177 application security jobs at 1,330 companies in United States

PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yr On-SiteFull Time
HiringCafe
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
Node.js, Python, Elasticsearch, Redis
2mo
Save
Mark Applied
Hide
Application Security Engineer
Harrisburg, Pennsylvania, United States
OnsiteFull Time
D&H Distributing
D&H Distributing: Distributes technology products and IT solutions to resellers.
3+ YOEDesigns and implements secure software practices; assesses application security; supports SDLC; proficient in at least one programming language; familiar with OWASP Top 10; experience with security assessments and vendor security.
OWASP, OAUTH, ADFS, PowerShell, Python, Perl, Java, .NET, C#, SIEM, Security
2mo
Save
Mark Applied
Hide
Application Security Engineer 3
Arlington, Virginia, United States
OnsiteFull Time
Bloomberg Industry Group
Bloomberg Industry Group: Provides legal, tax, and government intelligence and news services.
5+ YOELead application security engineering, design scalable security architectures, perform risk assessments, integrate security across the SDLC, and drive automation.
Python, Java, JavaScript, SAST, DAST, SCA, IaC, Container, Cloud Security, Kubernetes, DevSecOps
3d
Save
Mark Applied
Hide
AVP, Application Security
Rhode Island or New York or Arizona
$185k-$376k/yr RemoteFull Time
CVS Health
CVS HealthNYSE: CVS: Provides retail pharmacy, health insurance, and pharmacy benefit management services.
12+ YOE5+ Mgmt12+ years in information security with 5+ years leading application security; hands-on software development experience; expertise in SAST, DAST, SCA, WAF, CI/CD, cloud-native and secure SDLC; strong leadership and communication.
Java, Python, Go, JavaScript, SAST, DAST, SCA, WAF, CI/CD, Containerization, Cloud-native, GitHub Copilot
2mo
Save
Mark Applied
Hide
Senior Manager, Application Security
New York, New York, United States
$190k-$220k/yr HybridFull Time
Simpson Thacher & Bartlett
Simpson Thacher & Bartlett: Provides legal advisory and litigation services to global corporations.
10+ YOE5+ Mgmt10+ years in application security; hands-on with web apps, APIs, cloud, containers; leadership of enterprise security programs; strong collaboration and communication.
SAST, DAST, SCA, API testing, Container security, Kubernetes security, CI/CD security, Cloud security, Software supply chain security, Security automation
2mo
Save
Mark Applied
Hide
Application Security Engineer
United States
OnsiteFull Time
Wawa
Wawa: Operates a chain of convenience stores and gas stations.
2+ YOE2+ years in application security engineering; experience with containers, cloud security, Java; secure coding practices; DevSecOps.
Java, Golang, React, React Native, Python, PowerShell, Unix shell, JavaScript, TypeScript, Containers, Cloud, SAST, DAST, SCA, IaC, APIs
3mo
Save
Mark Applied
Hide
Sr. Manager, Application Security
United States
$226k-$270k/yr RemoteFull Time
Prosper
Prosper: Peer-to-peer lending marketplace for personal loans and credit.
10+ YOE3+ Mgmt10+ years in application security; 3+ years people leadership; strong security tooling, CI/CD, cloud (GCP); BS CS or related field; proficient in multiple programming languages.
SAST, DAST, IAST, RASP, SCA, CI/CD, GCP, Cloud security
3mo
Save
Mark Applied
Hide
Application Security Engineer
Lindon, Utah, United States
OnsiteFull Time
Awardco
Awardco: Software platform for employee recognition and corporate rewards programs.
6+ YOE6+ years in application security or secure software engineering; cloud SaaS security; web/API security; experience with SAST/DAST and CI/CD; mentoring developers.
SAST, DAST, Dependency scanning, Container scanning, GitHub Advanced Security, Snyk, Wiz
1w
Save
Mark Applied
Hide
Application Security Analyst
United States
$75k-$110k/yr RemoteFull Time
Sound Physicians
Sound Physicians: Physician-led medical group providing clinical services to hospital partners.
4+ YOE4+ years application security experience, strong app/cloud security knowledge, secure coding and DevSecOps skills, familiarity with SAST/DAST/SCA, CI/CD, container security, and scripting.
Azure, AWS, Azure DevOps, GitHub Actions, GitLab CI, Jenkins, Veracode, Checkmarx, Fortify, SonarQube, Snyk, Mend, Burp Suite, Rapid7 InsightAppSec, Python, Powershell, Bash, Docker, Kubernetes, OpenShift, AKS, EKS, GKE, Terraform, Java, JavaScript, C#, Go, OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, NIST Cybersecurity Framework
1mo
Save
Mark Applied
Hide
Application Security Engineer
Phoenix, Arizona, United States
OnsiteFull Time
SmartRent
SmartRentNYSE: SMRT: Provides smart home and building automation for rental housing.
4+ YOE4–6 years in application security; secure SDLC; cloud and web security; strong communication; experience with OWASP, SAST/DAST/SCA; AWS and WAF knowledge.
SAST, DAST, SCA, GHAS, Burp Suite, Fortra, OWASP, JWT, OAuth, AWS, WAF, CloudFlare
1w
Save
Mark Applied
Hide
Application Security Engineer
Nashville, Tennessee, United States
OnsiteFull Time
Universal Music Group
Universal Music GroupEuronext Amsterdam: UMG: Global music recording, publishing, merchandising, and content production.
5+ YOE5+ years application security or security engineering experience; perform app security assessments, threat modeling, secure design reviews; experience with cloud-native architectures, CI/CD integration, and developer enablement.
SAST, DAST, SCA, API security testing, GitHub Advanced Security, Microsoft Defender for Cloud, Checkmarx, Veracode, Burp Suite, Semgrep, Python, PowerShell, AWS, Azure, Google Cloud Platform, OAuth, OpenID Connect (OIDC), SAML, JWT, CI/CD, Kubernetes, Infrastructure as Code, OWASP, NIST Cybersecurity Framework, ISO 27001
1mo
Save
Mark Applied
Hide
Application Security Engineer
Beaverton, Oregon, United States
RemoteFull Time
Oneleet
Oneleet: Provides an all-in-one cybersecurity and compliance automation platform.
5+ YOE5+ years of application security experience; skilled in Go, Python, or TypeScript; experienced with production security tooling; strong communication; startup experience.
Go, Python, TypeScript
1mo
Save
Mark Applied
Hide
Application Security Engineer
Georgia or Serbia or Poland or Europe
RemoteFull Time
Salmon
Salmon: AI-powered neobank providing digital banking and consumer credit services.
7+ YOE7+ years in application security with secure SDLC ownership, threat modeling, vulnerability management, mobile security testing, supply chain risk management, and ability to script in Python or Bash.
Python, Bash, SAST, DAST, SCA, SBOM, AWS, Containers, CI/CD, OWASP ASVS, OWASP MASVS, npm, PyPI
1w
Save
Mark Applied
Hide
Application Security Engineer
San Francisco, California, United States
$145k-$180k/yr HybridFull Time
HeartFlow
HeartFlowNASDAQ: HTFL: Provides AI-driven non-invasive cardiac diagnostic software and analysis.
5+ YOE5+ years experience, ≥1 year in application security or security work in development; BS or equivalent/certifications; experience with secure SDLC, threat modeling, SAST/DAST/SCA, and vulnerability management.
C++, Python, Claude Code, GitHub Copilot, SAST, DAST, SCA, CI/CD, AWS, Terraform, Chef, Ansible, Docker, Kubernetes, GitHub Actions
3w
Save
Mark Applied
Hide
Application Security Engineer
Pittsburgh, Pennsylvania, United States
$110k-$120k/yr OnsiteFull Time
The Wolfe Companies
The Wolfe Companies: Provides comprehensive gift card management and fintech gifting solutions.
2+ YOE2+ years in application security/DevSecOps or software development with security exposure; coding background; CI/CD and secure-coding knowledge; bachelor\u0002s degree in related field (or equivalent experience).
Snyk, SemGrep, Cycode, GitHub, GitLab, Jenkins, AWS DevOps, OWASP, SANS CWE Top 25, DSOMM, BSIMM, AI/ML, LLM
1mo
Save
Mark Applied
Hide
Application Security Engineer
Tempe, Arizona, United States
HybridFull Time
Sequoia
Sequoia: A business advisory firm specializing in employee compensation and benefits.
5+ YOE5+ years in application security or application development; 3+ years programming (Python, Ruby, Go, Swift, Java, .Net, C++); 2+ years threat modeling/secure coding or related; appsec tooling, SAST/DAST, AWS; Bachelor's in CS.
Python, Ruby, Go, Swift, Java, .Net, C++, OWASP Dependency-Check, Bytesafe Dependency Checker, Patton, PHP Security Checker, Nmap, NetCat, OWASP Zed Attack Proxy, Burp Suite, MetaSploit, AppScan, WebInspect, AWS, PASTA, STRIDE
3mo
Save
Mark Applied
Hide
Application Security Engineer
United States
RemoteFull Time
H.W. Kaufman Group
H.W. Kaufman Group: Global network of specialty insurance brokerage and underwriting companies.
5+ YOE5+ years in application security with SDLC integration, threat modeling, SAST/DAST, and regulatory alignment.
SAST, DAST, SCA, Burp Suite, Fortify, Veracode, Docker, Kubernetes
1mo
Save
Mark Applied
Hide
Application Security Engineer
Miami, Florida, United States
HybridFull Time
Opendoor
OpendoorNASDAQ: OPEN: Online platform for buying and selling residential real estate.
5+ YOE5+ years application security or security-focused software engineering, strong coding skills in Python/Go/TypeScript/Ruby, experience with AppSec tooling (GitHub Advanced Security, Semgrep, HackerOne), cloud and Kubernetes security, threat modeling, and automation
Go, Python, TypeScript, Ruby, Terraform, AWS, GCP, Azure, Kubernetes, Apollo GraphQL, GraphQL, gRPC, REST, GitHub Advanced Security, CodeQL, Dependabot, Semgrep, HackerOne, Burp Suite, Cloudflare WAF, Claude, OpenAI, GitHub, Linear, Slack, MCP
3mo
Save
Mark Applied
Hide
Application Security Engineer
Coral Gables or Florida or Texas or South Carolina or Pennsylvania or Massachusetts or Illinois or Georgia or North Carolina or Florida
$110k-$130k/yr HybridFull Time
Ryder
RyderNYSE: R: Provides commercial vehicle leasing, logistics, and supply chain solutions.
5+ YOE5+ years OWASP, SAST, DAST, SCA, RASP; 7+ years in application security or related field; strong web security knowledge; secure SDLC; Bachelor's in CS; CISSP/OSCP/CASE preferred.
SAST, DAST, OWASP, SCA, RASP, WAF, CI/CD, Azure DevOps, Terraform, Python, JavaScript, .NET
2mo
Save
Mark Applied
Hide
Application Security Engineer
San Francisco, California, United States
HybridFull Time
Opal Security
Opal Security: Provides intelligent identity governance and enterprise access management solutions.
4+ YOE4+ years in application security or software security engineering; writing production code; strong auth: OAuth 2.0, OIDC, SAML; experience with AWS and containers; Go/TypeScript; security tooling; incident response.
Go, TypeScript, React, PostgreSQL, Redis, GraphQL, AWS, Kubernetes, Docker
2mo
Save
Mark Applied
Hide
Lead Application Security Engineer
San Francisco, California, United States
$225k-$400k/yr OnsiteFull Time
Ivo
Ivo: AI-powered contract review and intelligence platform for legal teams.
4+ YOE5+ years in application security; hands-on web pen testing; TypeScript/Node and Python; cloud security in GCP/Azure; manage pen tests; secure coding; strong communication.
SAST, DAST, SCA, IaC scanning, secrets detection, OWASP, Firebase Auth, WorkOS, SAML, OAuth, SSO, RBAC, Kubernetes security, cloud security