1,497 application security engineer jobs at 856 companies in United States
2w
Save
Mark Applied
Hide
2w
Application Security Engineer
Annapolis Junction, Maryland, United States
$87k-$198k/yrRemoteFull Time
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
5+ YOERequires 5+ years in cybersecurity, application or product security, or software engineering; Secure SDLC, security tools, cloud architectures, frameworks, communication, and a relevant bachelor's degree.
Wolfe: Private Pittsburgh fintech providing personalized digital and physical gift cards to businesses and consumers.
2+ YOE2+ years in application security/DevSecOps or software development with security exposure; coding background; CI/CD and secure-coding knowledge; bachelor\u0002s degree in related field (or equivalent experience).
Snyk, SemGrep, Cycode, GitHub, GitLab, Jenkins, AWS DevOps, OWASP, SANS CWE Top 25, DSOMM, BSIMM, AI/ML, LLM
Monarch Money: Personal finance technology helping consumers track, budget, plan, and manage money across accounts in one app.
5+ YOE5+ years security engineering experience with application and AI security, proficiency in Python, SAST/DAST, secure code review, vulnerability management, and experience with Semgrep, Burp Suite, and Nuclei.
Bespoke Technologies, Inc.: Woman-owned U.S. technology consultancy delivering digital transformation, engineering, mission operations, and IT solutions to national-security customers.
8+ YOERequires active Poly clearance, 8+ years in application security, software engineering, DevSecOps, or cybersecurity, and a bachelor's degree in engineering, computer science, or related technical field.
Virtru: Private data security platform providing encryption and access controls for enterprises and government agencies.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
CarGurusNasdaq Global Select Market: CARG: Public online automotive marketplace helping consumers and dealers buy and sell new and used vehicles.
0+ YOE0–2 years in cybersecurity, application security, software engineering, or related fields; familiarity with secure coding, vulnerability management, threat modeling, cloud infrastructure, SDLC tools, and a programming or scripting language.
AWS, Kubernetes, GitHub, CI/CD, Python, Go, Java, AI, ML
BrexNew York Stock Exchange: COF: Intelligent finance platform for corporate card and spend management.
8+ YOE8+ years in application/product security or related software engineering; technical leadership and mentorship experience; expertise in AI security, threat modeling, cloud-native container security (AWS, Kubernetes); proficiency in Python/Go; strong communication skills.
PepsiCoNASDAQ: PEP: Multinational food and beverage.
3+ YOEBachelor's in CS/Engineering or related and 3+ years experience; application security, vulnerability management, cloud-native security, Python/Go, SAST/SCA/DAST, WAF, and CI/CD security experience.
Bloomberg Industry Group: Private Bloomberg affiliate providing legal, tax, government, and accounting intelligence, news, analysis, and workflow technology to professionals.
5+ YOELead application security engineering, design scalable security architectures, perform risk assessments, integrate security across the SDLC, and drive automation.
D&H Distributing: Employee-owned technology distributor serving North American resellers and retailers with IT, electronics, and supply-chain services.
3+ YOEDesigns and implements secure software practices; assesses application security; supports SDLC; proficient in at least one programming language; familiar with OWASP Top 10; experience with security assessments and vendor security.
BitGoNYSE: BTGO: Public digital asset infrastructure providing custody, wallets, staking, trading, financing, stablecoins, and settlement for institutions.
8+ YOE8+ years building and scaling application security programs for FinTech/Web3; strong engineering background in distributed systems, Python or Java, Kubernetes, AWS, Terraform; experience with SAST/DAST, CI/CD security automation, KMS/encryption, SOC 2/GDPR controls, and securing AI/ML lifecycles.
Zeta GlobalNYSE: ZETA: AI-powered marketing cloud for consumer intelligence and automation.
5+ YOE5+ years in application security or DevSecOps, strong threat modeling and secure design knowledge, experience with app/cloud/API security, AI/ML security familiarity, and ability to build automated security workflows.
PepsiCoNASDAQ: PEP: Multinational food and beverage.
3+ YOEBachelor's in computer science/engineering or equivalent, 3+ years experience, hands-on application security and vulnerability management, cloud and tooling experience, Python or Go proficiency.
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
5+ YOERequires 5+ years in cybersecurity, application security, product security, or software engineering; Secure SDLC, application security tools, cloud-native architectures, risk management, and client leadership experience; bachelor's degree.
Microsoft Internet Explorer, Google Chrome, Mozilla Firefox, Microsoft Edge, Apple Safari, Opera Browser, Blackberry Browser, SAST, DAST, SCA, IaC, API, Agile, Scrum, DevSecOps, Kubernetes, SBOM, OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, MITRE ATT&CK, ATLAS
Boston or New York City or Los Angeles or San Francisco
$230k-$330k/yrOnsiteFull Time
Suno: Private AI music platform that helps people create complete songs from text prompts.
6+ YOE6+ years in security engineering with hands-on application security, secure SDLC tooling, AWS experience, ability to write production code and threat-model AI/LLM surfaces.
Reltio: Cloud-native master-data-management SaaS provider helping enterprises unify, govern, and activate data across SAP and non-SAP systems.
8+ YOE8+ years in application security or software development in cloud-native/SaaS environments; expertise in secure SDLC, CI/CD security, SAST/SCA/DAST, API and AI security; strong cloud and web technology knowledge.