1,497 application security engineer jobs at 856 companies in United States

2w
Save
Mark Applied
Hide
Application Security Engineer
Annapolis Junction, Maryland, United States
$87k-$198k/yr RemoteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
5+ YOERequires 5+ years in cybersecurity, application or product security, or software engineering; Secure SDLC, security tools, cloud architectures, frameworks, communication, and a relevant bachelor's degree.
Secure SDLC, SBOM, SAST, DAST, SCA, IaC, Kubernetes, OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, MITRE ATT&CK, MITRE ATLAS, Artificial Intelligence
2mo
Save
Mark Applied
Hide
Application Security Engineer
Miami, Florida, United States
HybridFull Time
Opendoor
OpendoorNasdaq: OPEN: Public U.S. real estate technology that buys and sells homes for residential sellers and buyers.
5+ YOE5+ years application security or software engineering experience; hands-on with Python/Go/TypeScript/Ruby, AppSec toolchain (GitHub Advanced Security, Semgrep, secret scanning), cloud and Kubernetes security, threat modeling, and AI/automation for vulnerability triage.
Go, Python, TypeScript, Ruby, Terraform, AWS, GCP, Azure, Kubernetes, Apollo GraphQL, GitHub Advanced Security, CodeQL, Dependabot, secret scanning, Semgrep, HackerOne, Burp Suite, Cloudflare WAF, Claude, OpenAI, MCP
2mo
Save
Mark Applied
Hide
Application Security Engineer
Pittsburgh, Pennsylvania, United States
$110k-$120k/yr OnsiteFull Time
Wolfe
Wolfe: Private Pittsburgh fintech providing personalized digital and physical gift cards to businesses and consumers.
2+ YOE2+ years in application security/DevSecOps or software development with security exposure; coding background; CI/CD and secure-coding knowledge; bachelor\u0002s degree in related field (or equivalent experience).
Snyk, SemGrep, Cycode, GitHub, GitLab, Jenkins, AWS DevOps, OWASP, SANS CWE Top 25, DSOMM, BSIMM, AI/ML, LLM
1mo
Save
Mark Applied
Hide
Senior Application Security Engineer
United States
$180k-$215k/yr RemoteFull Time
Monarch Money
Monarch Money: Personal finance technology helping consumers track, budget, plan, and manage money across accounts in one app.
5+ YOE5+ years security engineering experience with application and AI security, proficiency in Python, SAST/DAST, secure code review, vulnerability management, and experience with Semgrep, Burp Suite, and Nuclei.
Python, Django, Semgrep, Burp Suite, Nuclei, AWS, ECS, EKS, OWASP Top 10
5d
Save
Mark Applied
Hide
Application Security Engineer
Reston, Virginia, United States
OnsiteFull Time
Bespoke Technologies, Inc.
Bespoke Technologies, Inc.: Woman-owned U.S. technology consultancy delivering digital transformation, engineering, mission operations, and IT solutions to national-security customers.
8+ YOERequires active Poly clearance, 8+ years in application security, software engineering, DevSecOps, or cybersecurity, and a bachelor's degree in engineering, computer science, or related technical field.
Python, JavaScript, SQL, Shell, PL/SQL, SAST, DAST, SCA, Kubernetes, Docker, REST APIs, CI/CD, Oracle Cloud Infrastructure (OCI), NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, Oracle RDBMS, Agile, CISSP, CSSLP, Security+, GIAC, CEH, OSCP
2mo
Save
Mark Applied
Hide
Application Security Engineer
Washington, District of Columbia, United States
$180k-$200k/yr RemoteFull Time
Virtru
Virtru: Private data security platform providing encryption and access controls for enterprises and government agencies.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
1w
Save
Mark Applied
Hide
Application Security Engineer I
Boston, Massachusetts, United States
$96k-$120k/yr HybridFull Time
CarGurus
CarGurusNasdaq Global Select Market: CARG: Public online automotive marketplace helping consumers and dealers buy and sell new and used vehicles.
0+ YOE0–2 years in cybersecurity, application security, software engineering, or related fields; familiarity with secure coding, vulnerability management, threat modeling, cloud infrastructure, SDLC tools, and a programming or scripting language.
AWS, Kubernetes, GitHub, CI/CD, Python, Go, Java, AI, ML
2mo
Save
Mark Applied
Hide
Staff Application Security Engineer
San Francisco or United States
$240k-$300k/yr HybridFull Time
Brex
BrexNew York Stock Exchange: COF: Intelligent finance platform for corporate card and spend management.
8+ YOE8+ years in application/product security or related software engineering; technical leadership and mentorship experience; expertise in AI security, threat modeling, cloud-native container security (AWS, Kubernetes); proficiency in Python/Go; strong communication skills.
Python, Go, Kotlin, gRPC, GraphQL, Kubernetes, AWS, LLM
3w
Save
Mark Applied
Hide
Application Security | Application Security Engineer
Plano, Texas, United States
$80k-$134k/yr OnsiteFull Time
PepsiCo
PepsiCoNASDAQ: PEP: Multinational food and beverage.
3+ YOEBachelor's in CS/Engineering or related and 3+ years experience; application security, vulnerability management, cloud-native security, Python/Go, SAST/SCA/DAST, WAF, and CI/CD security experience.
Python, Go, AWS, Azure, GCP, SAST, SCA, DAST, WAF, OPA, HashiCorp Sentinel, OAuth, JWT, CDN
1mo
Save
Mark Applied
Hide
Senior Application Security Engineer
New York, New York, United States
$220k-$235k/yr HybridFull Time
Savvy Wealth
Savvy Wealth: Technology-enabled wealth management platform serving independent financial advisors with software, operations, compliance, and marketing support.
5+ YOE5+ years hands-on security engineering with application/product security, strong coding skills, AppSec toolchain experience (secrets, SCA, SAST), cloud (AWS/GCP) and Cloudflare experience, OAuth/SaaS hardening, GitHub/CICD security, and strong communication.
AWS, GCP, Cloudflare, Google Workspace, GitHub, Rippling, Slack, Claude
1mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Canada or United States
RemoteFull Time
BioRender
BioRender: Canadian SaaS helping scientists create and share professional scientific figures and communicate research visually.
Proven software engineering experience securing web applications and cloud infrastructure; expertise in Node.js/React/Python, Terraform, AWS, SAST/DAST/SCA integration, threat modeling, and secure SDLC; familiarity with bug bounty programs.
Node.js, React, Python, Terraform, AWS, Cloudflare, SAST, DAST, SCA, HackerOne, OWASP, CI/CD
3mo
Save
Mark Applied
Hide
Application Security Engineer 3
Arlington, Virginia, United States
OnsiteFull Time
Bloomberg Industry Group
Bloomberg Industry Group: Private Bloomberg affiliate providing legal, tax, government, and accounting intelligence, news, analysis, and workflow technology to professionals.
5+ YOELead application security engineering, design scalable security architectures, perform risk assessments, integrate security across the SDLC, and drive automation.
Python, Java, JavaScript, SAST, DAST, SCA, IaC, Container, Cloud Security, Kubernetes, DevSecOps
3mo
Save
Mark Applied
Hide
Application Security Engineer
Harrisburg, Pennsylvania, United States
OnsiteFull Time
D&H Distributing
D&H Distributing: Employee-owned technology distributor serving North American resellers and retailers with IT, electronics, and supply-chain services.
3+ YOEDesigns and implements secure software practices; assesses application security; supports SDLC; proficient in at least one programming language; familiar with OWASP Top 10; experience with security assessments and vendor security.
OWASP, OAUTH, ADFS, PowerShell, Python, Perl, Java, .NET, C#, SIEM, Security
1mo
Save
Mark Applied
Hide
Senior Security Application Engineer
Palo Alto, California, United States
$200k-$235k/yr OnsiteFull Time
BitGo
BitGoNYSE: BTGO: Public digital asset infrastructure providing custody, wallets, staking, trading, financing, stablecoins, and settlement for institutions.
8+ YOE8+ years building and scaling application security programs for FinTech/Web3; strong engineering background in distributed systems, Python or Java, Kubernetes, AWS, Terraform; experience with SAST/DAST, CI/CD security automation, KMS/encryption, SOC 2/GDPR controls, and securing AI/ML lifecycles.
SAST, DAST, CI/CD, Terraform, Kubernetes, AWS, Python, Java, KMS, MLOps, LLM
3mo
Save
Mark Applied
Hide
Application Security Engineer
United States
OnsiteFull Time
Wawa
Wawa: Convenience store and fuel retail chain.
2+ YOE2+ years in application security engineering; experience with containers, cloud security, Java; secure coding practices; DevSecOps.
Java, Golang, React, React Native, Python, PowerShell, Unix shell, JavaScript, TypeScript, Containers, Cloud, SAST, DAST, SCA, IaC, APIs
1mo
Save
Mark Applied
Hide
Lead Application Security Engineer
United States
$140k-$180k/yr RemoteFull Time
Zeta Global
Zeta GlobalNYSE: ZETA: AI-powered marketing cloud for consumer intelligence and automation.
5+ YOE5+ years in application security or DevSecOps, strong threat modeling and secure design knowledge, experience with app/cloud/API security, AI/ML security familiarity, and ability to build automated security workflows.
Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security, React, Node.js, Django, FastAPI, OAuth2, OIDC, JWT, Docker, Kubernetes, AWS, GCP, Azure
3w
Save
Mark Applied
Hide
Application Security | Application Security Engineer
Plano, Texas, United States
$80k-$134k/yr OnsiteFull Time
PepsiCo
PepsiCoNASDAQ: PEP: Multinational food and beverage.
3+ YOEBachelor's in computer science/engineering or equivalent, 3+ years experience, hands-on application security and vulnerability management, cloud and tooling experience, Python or Go proficiency.
Python, Go, AWS, Azure, GCP, OPA, HashiCorp Sentinel, SAST, SCA, DAST, WAF, CDN
2w
Save
Mark Applied
Hide
Application Security Engineer
Annapolis Junction or Bethesda
$87k-$198k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
5+ YOERequires 5+ years in cybersecurity, application security, product security, or software engineering; Secure SDLC, application security tools, cloud-native architectures, risk management, and client leadership experience; bachelor's degree.
Microsoft Internet Explorer, Google Chrome, Mozilla Firefox, Microsoft Edge, Apple Safari, Opera Browser, Blackberry Browser, SAST, DAST, SCA, IaC, API, Agile, Scrum, DevSecOps, Kubernetes, SBOM, OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, MITRE ATT&CK, ATLAS
3w
Save
Mark Applied
Hide
Senior / Staff Application Security Engineer
Boston or New York City or Los Angeles or San Francisco
$230k-$330k/yr OnsiteFull Time
Suno
Suno: Private AI music platform that helps people create complete songs from text prompts.
6+ YOE6+ years in security engineering with hands-on application security, secure SDLC tooling, AWS experience, ability to write production code and threat-model AI/LLM surfaces.
AWS, SAST, DAST
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
United States
$114k-$240k/yr OnsiteFull Time
Reltio
Reltio: Cloud-native master-data-management SaaS provider helping enterprises unify, govern, and activate data across SAP and non-SAP systems.
8+ YOE8+ years in application security or software development in cloud-native/SaaS environments; expertise in secure SDLC, CI/CD security, SAST/SCA/DAST, API and AI security; strong cloud and web technology knowledge.
Jenkins, ArgoCD, SAST, SCA, DAST, Model Context Protocol (MCP), LLM, Burp Suite Pro, Java, Java Spring Boot, JavaScript, Node.js, C#, AWS, GCP, Azure, Kubernetes, Wiz, NeMo Guardrails, AWS Bedrock Guardrails, DefectDojo, Wiz Code, Veracode, Checkmarx, Cycode, SonarQube, OWASP