161 application security jobs at 66 companies in Colorado

PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yr On-SiteFull Time
HiringCafe
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
Node.js, Python, Elasticsearch, Redis
1w
Save
Mark Applied
Hide
Application Security Engineer, Lead
Colorado Springs, Colorado, United States
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
5+ YOE5+ years application security experience with micro/macro-segmentation, WAFs, next-generation firewalls, application delivery, DoD networks, and eligibility for Secret clearance.
Palo Alto, Cisco, Fortinet, Juniper, Illumio, F5, Nginx, A10, NetScaler, Panorama, F5 BIG-IP Application Security Manager (ASM), Advanced Web Application Firewall (AWAF), Terraform, Visual Studio Code, Azure, AWS
1w
Save
Mark Applied
Hide
Application Security Engineer, Lead
Colorado Springs, Colorado, United States
$99k-$225k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
5+ YOE5+ years implementing application security (micro/macro-segmentation, WAFs), experience with next-gen firewalls and application delivery, DoD networks, Secret clearance, HS diploma/GED.
Palo Alto, Cisco, Fortinet, Juniper, Illumio, F5, Nginx, A10, NetScaler, Panorama, F5 BIG-IP Application Security Manager (ASM), Advanced Web Application Firewall (AWAF), Terraform, VS Code, Azure, AWS
1mo
Save
Mark Applied
Hide
Sr. Application Security Engineer
Denver, Colorado, United States
$130k-$165k/yr HybridFull Time
Vertafore
VertaforeNYSE: ROP: Provides cloud-based software solutions for the insurance industry.
7+ YOE7+ years in application/product/cloud security; Bachelor's in relevant field or equivalent experience; hands-on experience with threat modeling, secure SDLC, vulnerability management, CI/CD security, cloud (AWS/Azure), API and AI security; strong communication skills.
SAST, DAST, SCA, IaC scanning, container scanning, API security testing, secrets scanning, AI runtime scanning, WAF, CNAPP, CSPM, CI/CD, SIEM, AWS, Azure, OWASP ASVS, NIST CSF, NIST SSDF, OWASP SAMM
1mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Seattle or Los Angeles or San Francisco or California or Colorado or Connecticut or Delaware or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or Nevada or New Jersey or New York or Rhode Island or Virginia or Washington or Washington DC or United States
$141k-$259k/yr OnsiteFull Time
Nordstrom
Nordstrom: Operates luxury department stores and off-price retail outlets.
4+ YOE4+ years in application security or related field; experience shipping security tooling and automation; expert threat modeling, security design review, and manual code review; fluent reading/writing code in Java, Kotlin, C#, or Python; cloud-native and LLM/AI security knowledge.
Java, Kotlin, C#, Python, SAST, SCA, DAST, secrets scanning, GitHub Advanced Security, JFrog Artifactory, AWS, GCP, Azure, Kubernetes, LLM
3mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Denver or Long Beach
$145k-$205k/yr HybridFull Time
True Anomaly
True Anomaly: Develops autonomous spacecraft and software for space security missions.
5+ YOE5+ years in application security; experience with NIST 800-171/800-53, FedRAMP or CMMC; code in Python/Elixir/C++/JS; cloud security (Azure/AWS/GCP); DoD clearance eligibility.
CodeQL, Semgrep, JFrog Xray, DAST tools, Terraform, Bicep, Pulumi, Kubernetes
3mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Spring or Durham or Alpharetta or Fort Collins
$106k-$243k/yr HybridFull Time
Hewlett Packard Enterprise
Hewlett Packard EnterpriseNYSE: HPE: Providing global edge-to-cloud infrastructure and IT solutions for businesses.
5+ YOE5–8+ years in application security; CI/CD security; SBOM/NIST/SSDF knowledge; secrets management; WAF and API security; SAST/DAST/SCA; cloud security; programming in Python/Java/Go/Node.js.
GitHub, GitLab, Jenkins, Sigstore, Cosign, WAF, SAST, DAST, SCA, container scanning, AWS, Azure, GCP, Python, Java, Go, JavaScript
3mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Spring or Durham or Alpharetta or Fort Collins
$112k-$212k/yr HybridFull Time
Hewlett Packard Enterprise
Hewlett Packard EnterpriseNYSE: HPE: Provides edge-to-cloud IT infrastructure and platform services.
5+ YOE5–8+ years in application security; secure CI/CD pipelines; SLSA/NIST SSDF; secrets management; WAF; API security; SAST/DAST/SCA; cloud security; programming languages (Python/Java/Go/Node.js).
GitHub, GitLab, Jenkins, Sigstore, Cosign, SAST, DAST, SCA, WAF, OWASP, MITRE ATLAS, Cloud security (AWS/Azure/GCP)
3mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Spring or Durham or Alpharetta or Fort Collins
$112k-$243k/yr HybridFull Time
Hewlett Packard Enterprise
Hewlett Packard EnterpriseNYSE: HPE: Provides global edge-to-cloud technology solutions and IT infrastructure services.
5+ YOE5–8+ years in Application Security; hands-on pipeline security; SLSA/NIST SSDF; secrets management; WAF and API security; multiple programming languages; cloud security; OWASP Top 10; SBOM/CI-CD tooling.
GitHub, GitLab, Jenkins, Sigstore, Cosign, SAST, DAST, SCA, Container scanning, WAF, SBOM tooling, IaC scanning
6d
Save
Mark Applied
Hide
Senior Application Security Engineering Lead
Boulder, Colorado, United States
$155k-$185k/yr OnsiteFull Time
SciTec
SciTec: Provides advanced remote sensing and missile defense technology solutions.
8+ YOEBachelor's plus 8+ years cybersecurity/software experience (or equivalent), 2+ years application security, source-code analysis, secure SD practices, ability to obtain DoD Secret clearance and meet DoD 8140.01, strong communication and collaboration skills.
C++, Python, JavaScript, Rust, Coverity, Klocwork, SonarQube, Snyk, Sonatype, Anchore, JFrog Xray, AFL, AFL++, honggfuzz, strace, eBPF, Ghidra, IDA Pro, MITRE ATT&CK
6d
Save
Mark Applied
Hide
Security Specialist - Application Security
Pittsburgh or Phoenix or Lakewood or Birmingham or Strongsville or Farmers Branch
$91k-$186k/yr OnsiteFull Time
PNC Financial Services
PNC Financial ServicesNYSE: PNC: Provides banking, lending, and investment services to customers.
5+ YOEHands-on application security experience including threat modeling, remediation guidance for OWASP/API vulnerabilities, secure design/authentication, SAST/DAST/RASP and CI/CD knowledge; 5+ years' experience typically expected; strong communication skills.
OWASP, API Security, SAST, DAST, RASP, CI/CD, SD Elements, BSIMM, SAMM, AWS, Azure, GCP, Scrum, Kanban
1mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Broomfield, Colorado, United States
HybridFull Time
Recurly
Recurly: Automates subscription billing and management for recurring revenue businesses.
Experience developing in multiple languages, DevSecOps collaboration, managing bug bounty programs, integrating AI/ML into security pipelines, using SAST/DAST/SCA tools, Burp Suite, Terraform, Graylog, GCP, and Kubernetes.
Ruby, Go, Rust, JavaScript, Cloud Armor WAF, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Bug Bounty Programs, Containers, Git, Terraform, Graylog, GCP, Kubernetes, Burp Suite, AI/ML
2w
Save
Mark Applied
Hide
Staff Security Engineer, Application Security
Chicago or California or Colorado or Florida or Georgia or Illinois or Indiana or Minnesota or Missouri or Montana or New Jersey or New York or North Carolina or Ohio or Oregon or Pennsylvania or South Carolina or Texas or Utah or Vermont or Virginia or Washington or Washington or Wisconsin
$210k-$260k/yr HybridFull Time
NinjaTrader
NinjaTrader: Provides futures brokerage services and a trading software platform.
7+ YOE7+ years in application/product/security engineering; hands-on threat modeling, vulnerability management, secure design, CI/CD integration, automation using Python/Go; experience with cloud-native AWS/GCP environments.
AWS, GCP, Python, Go, SAST, SCA, DAST, CI/CD, AI/LLMs
1w
Save
Mark Applied
Hide
Senior Associate, Application Security, DevSecOps
Birmingham or Bentonville or Phoenix or Tempe or Irvine or Los Angeles or Sacramento or San Diego or San Francisco or Santa Clara or Boulder or Denver or Hartford or Stamford or Washington or Fort Lauderdale or Jacksonville or Miami or Orlando or Tallahassee or Tampa or Atlanta or Des Moines or Boise or Chicago or Indianapolis or Louisville or Baton Rouge or New Orleans or Shreveport or Boston or Baltimore or Detroit or Minneapolis or Kansas City or St Louis or Jackson or Charlotte or Raleigh or Winston-Salem or Lincoln or Omaha or Montvale or Short Hills or Albuquerque or Las Vegas or Albany or Buffalo or Melville or New York or Rochester or Cincinnati or Cleveland or Columbus or Oklahoma City or Portland or Harrisburg or Philadelphia or Pittsburgh or Providence or Greenville or Knoxville or Memphis or Nashville or Austin or Dallas or Fort Worth or Houston or San Antonio or Salt Lake City or Ashburn or McLean or Richmond or Seattle or Milwaukee or Virginia Beach or El Segundo
$90k-$168k/yr OnsiteFull Time
KPMG
KPMG: Global professional services network providing audit, tax, and advisory.
4+ YOE4+ years application security/DevSecOps experience, familiarity with CI/CD, SAST/DAST, cloud (preferably Azure), programming in Java/C#/JavaScript/Python/SQL, strong threat modeling and risk assessment skills, and U.S. work authorization without sponsorship.
Java, C#, JavaScript, Python, SQL, CI/CD, SAST, DAST, Azure, OWASP
3d
Save
Mark Applied
Hide
Cloud Security Application Control Owner
Denver or Washington or Chicago
$92k-$145k/yr OnsiteFull Time
Bank of America
Bank of AmericaNYSE: BAC: Provides global banking, investing, and financial risk management services.
Experience with public cloud platforms (Azure, AWS, GCP), cloud security controls, application lifecycle governance, compliance tracking, Change/Incident/Problem management, and strong communication.
Azure, AWS, GCP, Jira, Confluence, ServiceNow, Horizon
1mo
Save
Mark Applied
Hide
Principal Application Security Architect - 861
Broomfield, Colorado, United States
$184k-$230k/yr OnsiteFull Time
Quantinuum
Quantinuum: Building full-stack quantum computing hardware and software systems.
10+ YOEBachelor's degree; 10+ years in app security; 5+ years software engineering; US person; security and compliance expertise.
SAST, DAST, CI/CD, OWASP Top 10, AWS, Azure, GCP, Python, Java, JavaScript, Go, Jenkins, Git
2mo
Save
Mark Applied
Hide
Oracle EPM Application Security & Access Management Lead
Fort Worth or Littleton or Marietta or Moorestown or Sunnyvale or California or Colorado or Georgia or New Jersey or Texas
$82k-$144k/yr RemoteFull Time
Lockheed Martin
Lockheed MartinNYSE: LMT: Designs and manufactures global security and aerospace systems.
Strong Oracle EPM security experience, capturing security requirements and translating to role design, leading role build/test/deploy/maintenance across SDLC, familiarity with Oracle EPM modules, strong communication and analytical skills; US Citizenship required.
Oracle EPM, Focused Build, Service Central, Jira
1mo
Save
Mark Applied
Hide
Sales Engineer (Application Security)
Texas or Oklahoma or Arizona or Washington or Missouri or Illinois or Colorado or Oregon
RemoteFull Time
Thales
ThalesEuronext Paris: HO: Develops electronics and digital systems for aerospace and defense.
5+ YOE5+ years sales engineering experience in application/security domains (DDoS, WAF, API management, bot management); strong application security knowledge; foundational networking protocols; hands-on cloud/container experience (AWS/Azure/GCP, K8s, Docker); strong presentation and consultative-selling skills.
AWS, Azure, GCP, K8s, Docker, SIEM, DevOps, DevSecOps, TCP/IP, DNS, TLS, HTTP, CDN
1w
Save
Mark Applied
Hide
Application Support Administrator I
Colorado Springs, Colorado, United States
$61k-$73k/yr OnsiteFull Time
City of Colorado Springs
City of Colorado Springs: Provides municipal services and infrastructure to the Colorado Springs community.
Install, configure, support and troubleshoot COTS and SaaS applications; perform user setup and security; follow ITIL processes; bachelor’s degree required; obtain CompTIA Security+ within six months.
COTS, SaaS, Cloud, ITSM, ITIL
1mo
Save
Mark Applied
Hide
Lead Application Administrator, Public Safety Applications
Rhode Island or California or Colorado or Connecticut or Florida or Maryland or Massachusetts or New York or New Hampshire or New Jersey or North Carolina or District of Columbia
RemoteFull Time
Brown University
Brown University: Private research university offering undergraduate and graduate degree programs.
5+ YOE5+ years enterprise application support/administration, 1–2 years lead or supervisory experience, experience with public safety/security applications, SQL/SSRS, Active Directory, documentation and end-user training; CJIS and criminal background checks required.
CCure 9000, CCURE9000, Genetec Security Center, Genetec, Zetron Communication Solution, IMC, NICE 911 Voice & Radio Recording Suite, NICE 911 Recording Suite, RILETS (Rhode Island Law Enforcement Telecommunications System), SQL, SSRS (SQL Server Reporting Services), Active Directory, Group Policy, Wowza Media Service, TheoPlayer Cloud, Google Suite, Microsoft Excel, Word, Microsoft Office, TCP/IP
1mo
Save
Mark Applied
Hide
Sales Engineer (Application Security)
Texas or Oklahoma or Arizona or Washington or Missouri or Illinois or Colorado or Oregon
RemoteFull Time
Thales
ThalesEuronext Paris: HO: Designs and manufactures electronic systems for aerospace and defense.
5+ YOE5+ years sales engineering experience in application security (DDoS, WAF, API, bot management); strong networking fundamentals (TCP/IP, DNS, TLS, HTTP, CDN); hands-on with AWS/Azure/GCP, K8s, Docker; consultative selling; up to 30% travel; must be authorized to work in the US.
AWS, Azure, GCP, K8s, Docker, TCP/IP, DNS, TLS, HTTP, CDN, SIEM