839 application security manager jobs at 484 companies in United States

PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yr On-SiteFull Time
HiringCafe
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
Node.js, Python, Elasticsearch, Redis
2mo
Save
Mark Applied
Hide
Senior Manager, Application Security
New York, New York, United States
$190k-$220k/yr HybridFull Time
Simpson Thacher & Bartlett
Simpson Thacher & Bartlett: Provides legal advisory and litigation services to global corporations.
10+ YOE5+ Mgmt10+ years in application security; hands-on with web apps, APIs, cloud, containers; leadership of enterprise security programs; strong collaboration and communication.
SAST, DAST, SCA, API testing, Container security, Kubernetes security, CI/CD security, Cloud security, Software supply chain security, Security automation
3mo
Save
Mark Applied
Hide
Sr. Manager, Application Security
United States
$226k-$270k/yr RemoteFull Time
Prosper
Prosper: Peer-to-peer lending marketplace for personal loans and credit.
10+ YOE3+ Mgmt10+ years in application security; 3+ years people leadership; strong security tooling, CI/CD, cloud (GCP); BS CS or related field; proficient in multiple programming languages.
SAST, DAST, IAST, RASP, SCA, CI/CD, GCP, Cloud security
3w
Save
Mark Applied
Hide
Application Security Manager
Chicago or New York City
HybridFull Time
Alter Domus
Alter Domus: Provides administrative and accounting services for alternative investment funds.
4+ YOE4+ years application security experience; experience with SAST/DAST/SCA, secure code review, CI/CD integrations, OWASP, cloud (AWS/Azure) and containerization; strong developer enablement and communication skills; bachelor’s preferred.
SAST, DAST, SCA, secrets scanning, Azure DevOps, GitHub Enterprise, GitHub Advanced Security, Azure Pipelines, GitHub Actions, Snyk, Cycode, Apiiro, Burp Suite, AWS, Azure, Docker, Kubernetes, Python, Java, C#
2mo
Save
Mark Applied
Hide
Manager Application Security
United States
$133k-$190k/yr HybridFull Time
Citizens Financial Group
Citizens Financial GroupNYSE: CFG: Provides retail, commercial, and private banking services to customers.
10+ YOE5+ Mgmt10+ years in cybersecurity focused on application security; 5+ years of leadership; strong communication; experience with SDLC, CI/CD, DevSecOps; regulatory/risk understanding.
SAST, DAST, SCA, CI/CD
1w
Save
Mark Applied
Hide
Sr. Application Security Manager
New York City, New York, United States
$153k-$260k/yr OnsiteFull Time
DoubleVerify
DoubleVerifyNew York Stock Exchange: DV: Provides software for measuring and authenticating digital media quality.
10+ YOE3+ Mgmt10+ years in information security with technical management experience; expertise in application, API, cloud, supply chain or AI/ML security; hands-on AppSec tooling and scripting for automation.
Ox Security, Snyk, Veracode, Checkmarx, Wiz, Cursor, Claude Code, VS Code, GitLab, GitHub, ArgoCD, Terraform, Python, PromptFlow, OWASP Application Security Verification Standard (ASVS), OWASP API Security Top 10, OWASP Top 10 for LLMs, NIST AI RMF
1mo
Save
Mark Applied
Hide
Application Security Lead / Manager
Miami, Florida, United States
HybridFull Time
Iru
Iru: AI-powered platform for identity, endpoint security, and compliance.
7+ YOE7+ years in application/product/security engineering, experience with threat modeling, security assessments, vulnerability management, penetration testing coordination, AppSec tooling and CI/CD integration; strong communication and stakeholder influence.
SAST, DAST, Software Composition Analysis (SCA), Secrets detection, Infrastructure-as-Code scanning, CI/CD, AWS, Azure, GCP, ServiceNow
3d
Save
Mark Applied
Hide
Senior Manager, Application Security
Irving or Chicago or Boston
$113k-$210k/yr OnsiteFull Time
Publicis Groupe
Publicis GroupeEuronext Paris: PUB: Global advertising and digital transformation agency holding.
10+ YOE10+ years experience in software security, BS/MS in CS, hands-on software development, CI/CD and application testing (SAST/DAST/IAST), vulnerability management, OWASP/CWE knowledge, cloud and cryptography expertise.
CI/CD, SAST, DAST, MAST, RAST, IAST, OWASP Top 10, WAF
3d
Save
Mark Applied
Hide
Manager, Application Security, DevSecOps
Dallas, Texas, United States
$127k-$247k/yr OnsiteFull Time
KPMG
KPMG: Global professional services network providing audit, tax, and advisory.
6+ YOE6+ years in application security/DevSecOps, strong appsec and AI-related risk knowledge, experience with SDLC/CI-CD and cloud (preferably Azure), bachelor's preferred, relevant certs preferred.
Azure, OWASP Top 10, CI/CD
2w
Save
Mark Applied
Hide
Senior Manager - Application Security Engineering
New York or Connecticut or Texas or Rhode Island or Massachusetts
$118k-$261k/yr RemoteFull Time
CVS Health
CVS HealthNYSE: CVS: Provides retail pharmacy, health insurance, and pharmacy benefit management services.
7+ YOE2+ Mgmt7+ years in enterprise security and security program leadership; experience with cloud-native architectures, application security, vulnerability management, SAST/SCA/SBOM, developer enablement, and security automation.
AWS, Azure, GCP, Kubernetes, SAST, SCA, CVA, SBOM, CI/CD, Infrastructure-as-Code (IaC), JFrog, Snyk, Veracode, Wiz, GitGuardian, Prisma Cloud, Claude, Claude Code, GitHub Copilot, Microsoft Copilot
1w
Save
Mark Applied
Hide
Sr. Manager, Application Security
Bethesda or United States
$110k-$190k/yr HybridFull Time
Marriott International
Marriott InternationalNASDAQ: MAR: Operates and franchises a global network of hotels and resorts.
7+ YOE4+ Mgmt7+ years IT/security experience with 4+ years security leadership, bachelor\u0002s degree or equivalent, experience with AppSec testing (SAST/DAST/IAST), SCA, release management, and GitHub/JIRA/ServiceNow/Jenkins/Harness.
GitHub, JIRA, ServiceNow, Jenkins, Harness, SAST, DAST, IAST, SCA, OWASP, MITRE CVE/CWE
1mo
Save
Mark Applied
Hide
Application Security Engineer
Georgia or Serbia or Poland or Europe
RemoteFull Time
Salmon
Salmon: AI-powered neobank providing digital banking and consumer credit services.
7+ YOE7+ years in application security with secure SDLC ownership, threat modeling, vulnerability management, mobile security testing, supply chain risk management, and ability to script in Python or Bash.
Python, Bash, SAST, DAST, SCA, SBOM, AWS, Containers, CI/CD, OWASP ASVS, OWASP MASVS, npm, PyPI
2w
Save
Mark Applied
Hide
Application Security Engineer
United States
$120k-$154k/yr RemoteFull Time, Contract
Figure
FigureNASDAQ: FIGR: Provides blockchain-based lending and capital market technology solutions.
Experienced application security engineer to run vulnerability management, embed security into SDLC, perform threat modeling, manage pen tests, participate in incident response, and mentor engineers.
CI/CD, blockchain, AI
1w
Save
Mark Applied
Hide
Application Security Engineer
San Francisco, California, United States
$145k-$180k/yr HybridFull Time
HeartFlow
HeartFlowNASDAQ: HTFL: Provides AI-driven non-invasive cardiac diagnostic software and analysis.
5+ YOE5+ years experience, ≥1 year in application security or security work in development; BS or equivalent/certifications; experience with secure SDLC, threat modeling, SAST/DAST/SCA, and vulnerability management.
C++, Python, Claude Code, GitHub Copilot, SAST, DAST, SCA, CI/CD, AWS, Terraform, Chef, Ansible, Docker, Kubernetes, GitHub Actions
2mo
Save
Mark Applied
Hide
Lead Application Security Engineer
San Francisco, California, United States
$225k-$400k/yr OnsiteFull Time
Ivo
Ivo: AI-powered contract review and intelligence platform for legal teams.
4+ YOE5+ years in application security; hands-on web pen testing; TypeScript/Node and Python; cloud security in GCP/Azure; manage pen tests; secure coding; strong communication.
SAST, DAST, SCA, IaC scanning, secrets detection, OWASP, Firebase Auth, WorkOS, SAML, OAuth, SSO, RBAC, Kubernetes security, cloud security
1w
Save
Mark Applied
Hide
Application Security Analyst
United States
$75k-$110k/yr RemoteFull Time
Sound Physicians
Sound Physicians: Physician-led medical group providing comprehensive hospital-based clinical services.
4+ YOE4+ years application security or related experience, bachelor’s in CS/InfoSec or related, knowledge of SAST/DAST/SCA/IaC, cloud and CI/CD security, scripting, and vulnerability management.
Azure, AWS, Azure DevOps, GitHub Actions, GitLab CI, Jenkins, Veracode, Checkmarx, Fortify, SonarQube, Snyk, Mend, Burp Suite, Rapid7 InsightAppSec, Python, Powershell, Bash, Docker, Kubernetes, OpenShift, AKS, EKS, GKE, Terraform, Java, JavaScript, C#, Go, OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, NIST Cybersecurity Framework
1d
Save
Mark Applied
Hide
Application Security Engineer
Phoenix, Arizona, United States
$63k-$125k/yr HybridFull Time
Cognizant
CognizantNasdaq: CTSH: Provides global information technology and business process outsourcing services.
8+ YOE8+ years in application/product security or software engineering; hands-on SAST/DAST/SCA/IAST, vulnerability management, threat modeling (STRIDE), secure coding (OWASP), CI/CD security (GitLab/Jenkins), Java/.NET code review.
SAST, DAST, SCA, IAST, STRIDE, OWASP, CVSS, Java, .NET, GitLab, Jenkins
3w
Save
Mark Applied
Hide
Senior Application Security Engineer
United States
$180k-$215k/yr RemoteFull Time
Monarch Money
Monarch Money: A subscription-based platform for personal budgeting and wealth management.
5+ YOE5+ years security engineering experience with application and AI security, proficiency in Python, SAST/DAST, secure code review, vulnerability management, and experience with Semgrep, Burp Suite, and Nuclei.
Python, Django, Semgrep, Burp Suite, Nuclei, AWS, ECS, EKS, OWASP Top 10
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
San Francisco or New York City or Pittsburgh
$228k-$290k/yr HybridFull Time
Abridge
Abridge: Automates medical documentation through AI-powered speech analysis
10+ YOE10+ years in application security, expertise in threat modeling, secure code review, vulnerability management, incident response, programming (Python, NextJS), cloud security (GCP), Kubernetes, and AI/ML security; strong communication and leadership skills.
Python, NextJS, GCP, Kubernetes
2d
Save
Mark Applied
Hide
Senior Manager, Application Security
Irving or Chicago or Boston
$113k-$210k/yr HybridFull Time
Publicis Groupe
Publicis GroupeEuronext Paris: PUB: Global communications, advertising, and digital transformation holding.
10+ YOEBS/MS in CS or similar,10+ years experience,software development and CI/CD experience,SAST/DAST/MAST/RAST/IAST and vulnerability management,OWASP/CWE knowledge,cloud and auth expertise,threat modeling and cryptography.
SAST, DAST, MAST, RAST, IAST, OWASP Top 10, CWE 25, WAF
1mo
Save
Mark Applied
Hide
Senior Application Security Analyst
Olympia, Washington, United States
$114k-$124k/yr HybridFull Time
Washington Health Benefit Exchange
Washington Health Benefit Exchange: Operates Washington state's health insurance enrollment marketplace.
7+ YOE7+ years in information security with application security, secure SDLC, DevSecOps, cloud/Azure experience; experience with code reviews, threat modeling, vulnerability management, and tools like Nessus, Rapid7, Nmap, and Burp Suite.
Microsoft Azure, Nessus, Rapid7, Nmap, Burp Suite, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), CI/CD, OWASP, STRIDE, MITRE ATT&CK, Security Information and Event Management (SIEM), Endpoint Detection & Response