77 application security engineer jobs at 52 companies in Santa Rosa, CA

1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
San Francisco or United States
$240k-$300k/yr HybridFull Time
Brex
Brex: Corporate cards and spend management software for businesses.
8+ YOE8+ years in application/product security or related software engineering; technical leadership and mentorship experience; expertise in AI security, threat modeling, cloud-native container security (AWS, Kubernetes); proficiency in Python/Go; strong communication skills.
Python, Go, Kotlin, gRPC, GraphQL, Kubernetes, AWS, LLM
3w
Save
Mark Applied
Hide
Lead Application Security Engineer
San Francisco, California, United States
$140k-$180k/yr RemoteFull Time
Zeta Global
Zeta GlobalNYSE: ZETA: Provides an AI-powered marketing platform for enterprise customer engagement.
5+ YOEBachelor's or equivalent,5+ years application security experience,knowledge of OWASP and threat modeling,AI/ML security familiarity,cloud and container experience,experience with security automation and tooling.
React, Node.js, Django, FastAPI, OAuth2, OIDC, JWT, AWS, GCP, Azure, Docker, Kubernetes, Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security
1mo
Save
Mark Applied
Hide
Security Engineer, Application Security
San Francisco, California, United States
$200k-$325k/yr OnsiteFull Time
Serval
Serval: AI platform for automating IT and enterprise service workflows.
10+ YOE10+ years in cybersecurity with deep expertise in application security, secure SDLC, vulnerability management, secure cloud-native architecture, leadership experience, and strong software engineering skills.
SAST, DAST, SCA, secrets scanning, fuzzing, CI/CD
2mo
Save
Mark Applied
Hide
Senior Application Security Engineer
New York or Los Angeles or San Francisco
$165k-$190k/yr HybridFull Time
Tatari
Tatari: A platform for buying and measuring TV advertising campaigns.
Production Python experience, significant hands-on application security experience, threat modeling, building security tooling/automation, familiarity with AWS and Kubernetes, and SAST/DAST/SCA/CI-CD integration.
Python, Java, Rust, AWS, Kubernetes, OWASP Top 10, API Security Top 10, ASVS, SPVS, AISVS, SAST, DAST, SCA, CI/CD
2mo
Save
Mark Applied
Hide
Application Security Engineer
San Francisco, California, United States
HybridFull Time
Opal Security
Opal Security: Provides intelligent identity governance and enterprise access management solutions.
4+ YOE4+ years in application security or software security engineering; writing production code; strong auth: OAuth 2.0, OIDC, SAML; experience with AWS and containers; Go/TypeScript; security tooling; incident response.
Go, TypeScript, React, PostgreSQL, Redis, GraphQL, AWS, Kubernetes, Docker
2w
Save
Mark Applied
Hide
Application Security Engineer
San Francisco, California, United States
$145k-$180k/yr HybridFull Time
HeartFlow
HeartFlowNASDAQ: HTFL: Provides AI-driven non-invasive cardiac diagnostic software and analysis.
5+ YOE5+ years experience, ≥1 year in application security or security work in development; BS or equivalent/certifications; experience with secure SDLC, threat modeling, SAST/DAST/SCA, and vulnerability management.
C++, Python, Claude Code, GitHub Copilot, SAST, DAST, SCA, CI/CD, AWS, Terraform, Chef, Ansible, Docker, Kubernetes, GitHub Actions
4w
Save
Mark Applied
Hide
Senior Security Application Engineer
San Francisco, California, United States
$200k-$235k/yr OnsiteFull Time
BitGo
BitGoNYSE: BTGO: Provides secure infrastructure for institutional digital asset management.
8+ YOE8+ years building and scaling security programs; experience with cloud security, Kubernetes, Terraform, Python/Java, SOC 2/GDPR controls, and securing AI/ML lifecycles; Bachelor’s in a technical field required.
SAST, DAST, Terraform, Kubernetes, AWS, Python, Java, CI/CD, KMS, LLM
2mo
Save
Mark Applied
Hide
Lead Application Security Engineer
San Francisco, California, United States
$225k-$400k/yr OnsiteFull Time
Ivo
Ivo: AI-powered contract review and intelligence platform for legal teams.
4+ YOE5+ years in application security; hands-on web pen testing; TypeScript/Node and Python; cloud security in GCP/Azure; manage pen tests; secure coding; strong communication.
SAST, DAST, SCA, IaC scanning, secrets detection, OWASP, Firebase Auth, WorkOS, SAML, OAuth, SSO, RBAC, Kubernetes security, cloud security
1mo
Save
Mark Applied
Hide
Senior Application Security Engineer
United States or Canada or San Francisco or New York City or Seattle
$190k-$273k/yr RemoteFull Time
Apollo.io
Apollo.io: AI-powered platform for B2B sales intelligence and outreach automation.
5+ YOE5+ years software engineering or application security experience; strong coding skills (Ruby, Python), Linux and GCP familiarity, deep AppSec/vulnerability management, pen-testing and SAST experience, AI security, and strong communication.
Ruby, Python, Linux, GCP, SAST
3w
Save
Mark Applied
Hide
Staff+ Application Security Engineer - M&A
San Francisco or Seattle or New York City
$320k-$485k/yr HybridFull Time
Anthropic
Anthropic: Developing safe and reliable artificial intelligence systems.
Hands-on application and infrastructure security experience, production-quality coding in Python/Go/Rust/TypeScript, threat-modeling, vulnerability ID, clear communication, and ability to assess unfamiliar codebases under time pressure.
Python, Go, Rust, TypeScript, Claude, SAST, DAST, LLMs, bug bounty
2mo
Save
Mark Applied
Hide
AI Application Security Engineer
San Francisco, California, United States
HybridFull Time
Brain Co.
Brain Co.: Builds AI software platforms for governments and large enterprises.
5+ YOE5+ years in application or product security; hands-on security tooling and coding; strong knowledge of application security fundamentals; experience with AI-enabled security.
Python, Go, TypeScript, SAST/DAST tooling
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
San Francisco or New York City or Pittsburgh
$228k-$290k/yr HybridFull Time
Abridge
Abridge: Automates medical documentation through AI-powered speech analysis
10+ YOE10+ years in application security, expertise in threat modeling, secure code review, vulnerability management, incident response, programming (Python, NextJS), cloud security (GCP), Kubernetes, and AI/ML security; strong communication and leadership skills.
Python, NextJS, GCP, Kubernetes
1mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Seattle or Los Angeles or San Francisco or California or Colorado or Connecticut or Delaware or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or Nevada or New Jersey or New York or Rhode Island or Virginia or Washington or Washington DC or United States
$141k-$259k/yr OnsiteFull Time
Nordstrom
Nordstrom: Operates luxury department stores and off-price retail outlets.
4+ YOE4+ years in application security or related field; experience shipping security tooling and automation; expert threat modeling, security design review, and manual code review; fluent reading/writing code in Java, Kotlin, C#, or Python; cloud-native and LLM/AI security knowledge.
Java, Kotlin, C#, Python, SAST, SCA, DAST, secrets scanning, GitHub Advanced Security, JFrog Artifactory, AWS, GCP, Azure, Kubernetes, LLM
1mo
Save
Mark Applied
Hide
Application Security Engineer [Remote-US]
United States or San Francisco or Providence
$175k-$215k/yr RemoteFull Time
Quanata
Quanata: Developing risk prediction and telematics software for insurance companies.
4+ YOEAssociate's degree (required); 4+ years software engineering experience with ≥2 years in application security; familiarity with OWASP/ASVS/MASVS, threat modeling (STRIDE/PASTA), cloud architectures, and strong communication skills.
OWASP Top 10, ASVS, MASVS, STRIDE, PASTA, LLM
2mo
Save
Mark Applied
Hide
Security engineer, application security
San Francisco or New York City
$119k-$210k/yr HybridFull Time
Writer
Writer: Platform for building and deploying enterprise generative AI agents.
4+ YOE4+ years in application security; strong coding in Python/Java/Go/JavaScript/TypeScript; SAST/DAST in CI/CD; threat modeling; secure SDLC; security reviews; automation.
Python, Java, Go, JavaScript, TypeScript, SAST, DAST, CI/CD, DevSecOps
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
Minneapolis or Birmingham or San Francisco or United States
$96k-$180k/yr HybridFull Time
Shipt
Shipt: Provides same-day delivery services from local retailers via app.
5+ YOEBachelor's degree or equivalent, 5+ years programming in Go, Python, or JavaScript/TypeScript, experience with WAF, containerization, cloud platforms, APIs, Terraform, secure coding, and system design.
Go, Python, JavaScript, TypeScript, WAF, Terraform, CDN
5d
Save
Mark Applied
Hide
Staff Security Application Engineer
Chicago or Scottsdale or San Francisco or New York City
$149k-$218k/yr HybridFull Time
Early Warning Services
Early Warning Services: Operates payment and risk solutions for the financial industry.
8+ YOE8+ years network security experience with 5+ years in proxy and DLP; hands-on with Microsoft Defender, Palo Alto Prisma Access, Netskope; scripting (PowerShell, Python); experience with compliance and control testing.
Microsoft Defender, Palo Alto Prisma Access, Netskope, PowerShell, Python
1w
Save
Mark Applied
Hide
Security Engineer
San Francisco, California, United States
$200k-$230k/yr OnsiteFull Time
LiteLLM
LiteLLM: Open-source AI gateway for standardizing LLM API access.
Startup security engineering experience with hands-on offensive/white-hat hacking, application and CI/CD security, demonstrated security projects and CTF success.
Python, GitHub, OpenAI, CI/CD
1mo
Save
Mark Applied
Hide
Security Engineer — Application Security & Identity
Boston or Carmel or Chicago or Lambertville or New York City or San Francisco or United States
$60k-$80k/yr HybridFull Time
Real Chemistry
Real Chemistry: Provides marketing and communication services for healthcare companies.
5+ YOE5+ years cloud security experience (3+ in high-growth acceptable), including 2 years focused on application security; hands-on with AWS IAM, SAML/OIDC, GitHub security tooling, threat modeling, penetration testing, and familiarity with SOC 2/GDPR/HIPAA-adjacent controls.
AWS, AWS IAM, Microsoft Entra ID, SAML, OIDC, GitHub, GitHub OIDC, GitHub Advanced Security, CodeQL, SAST, Dependabot, Secret scanning, Semgrep, Snyk, Trivy, ECR scanning, OPA, Sentinel, tfsec, SIEM
1w
Save
Mark Applied
Hide
Senior Security Engineer - Product Security
San Francisco or New York City
$100k-$300k/yr OnsiteFull Time
Cogent Security
Cogent Security: Autonomous AI agents for enterprise vulnerability remediation.
5+ years security engineering experience in application/product security, secure SDLC, threat modeling, code scanning, supply-chain security, strong software engineering skills, and familiarity with modern AI security concerns.
Python, Go, TypeScript, SAST, DAST, CI/CD

Explore Jobs

Expand Your Job Search