839 application security manager jobs at 484 companies in United States
🚀PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yrOn-SiteFull Time
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
Simpson Thacher & Bartlett: Provides legal advisory and litigation services to global corporations.
10+ YOE5+ Mgmt10+ years in application security; hands-on with web apps, APIs, cloud, containers; leadership of enterprise security programs; strong collaboration and communication.
Prosper: Peer-to-peer lending marketplace for personal loans and credit.
10+ YOE3+ Mgmt10+ years in application security; 3+ years people leadership; strong security tooling, CI/CD, cloud (GCP); BS CS or related field; proficient in multiple programming languages.
Citizens Financial GroupNYSE: CFG: Provides retail, commercial, and private banking services to customers.
10+ YOE5+ Mgmt10+ years in cybersecurity focused on application security; 5+ years of leadership; strong communication; experience with SDLC, CI/CD, DevSecOps; regulatory/risk understanding.
DoubleVerifyNew York Stock Exchange: DV: Provides software for measuring and authenticating digital media quality.
10+ YOE3+ Mgmt10+ years in information security with technical management experience; expertise in application, API, cloud, supply chain or AI/ML security; hands-on AppSec tooling and scripting for automation.
Ox Security, Snyk, Veracode, Checkmarx, Wiz, Cursor, Claude Code, VS Code, GitLab, GitHub, ArgoCD, Terraform, Python, PromptFlow, OWASP Application Security Verification Standard (ASVS), OWASP API Security Top 10, OWASP Top 10 for LLMs, NIST AI RMF
Iru: AI-powered platform for identity, endpoint security, and compliance.
7+ YOE7+ years in application/product/security engineering, experience with threat modeling, security assessments, vulnerability management, penetration testing coordination, AppSec tooling and CI/CD integration; strong communication and stakeholder influence.
KPMG: Global professional services network providing audit, tax, and advisory.
6+ YOE6+ years in application security/DevSecOps, strong appsec and AI-related risk knowledge, experience with SDLC/CI-CD and cloud (preferably Azure), bachelor's preferred, relevant certs preferred.
New York or Connecticut or Texas or Rhode Island or Massachusetts
$118k-$261k/yrRemoteFull Time
CVS HealthNYSE: CVS: Provides retail pharmacy, health insurance, and pharmacy benefit management services.
7+ YOE2+ Mgmt7+ years in enterprise security and security program leadership; experience with cloud-native architectures, application security, vulnerability management, SAST/SCA/SBOM, developer enablement, and security automation.
Marriott InternationalNASDAQ: MAR: Operates and franchises a global network of hotels and resorts.
7+ YOE4+ Mgmt7+ years IT/security experience with 4+ years security leadership, bachelor\u0002s degree or equivalent, experience with AppSec testing (SAST/DAST/IAST), SCA, release management, and GitHub/JIRA/ServiceNow/Jenkins/Harness.
Salmon: AI-powered neobank providing digital banking and consumer credit services.
7+ YOE7+ years in application security with secure SDLC ownership, threat modeling, vulnerability management, mobile security testing, supply chain risk management, and ability to script in Python or Bash.
FigureNASDAQ: FIGR: Provides blockchain-based lending and capital market technology solutions.
Experienced application security engineer to run vulnerability management, embed security into SDLC, perform threat modeling, manage pen tests, participate in incident response, and mentor engineers.
HeartFlowNASDAQ: HTFL: Provides AI-driven non-invasive cardiac diagnostic software and analysis.
5+ YOE5+ years experience, ≥1 year in application security or security work in development; BS or equivalent/certifications; experience with secure SDLC, threat modeling, SAST/DAST/SCA, and vulnerability management.
Ivo: AI-powered contract review and intelligence platform for legal teams.
4+ YOE5+ years in application security; hands-on web pen testing; TypeScript/Node and Python; cloud security in GCP/Azure; manage pen tests; secure coding; strong communication.
Sound Physicians: Physician-led medical group providing comprehensive hospital-based clinical services.
4+ YOE4+ years application security or related experience, bachelor’s in CS/InfoSec or related, knowledge of SAST/DAST/SCA/IaC, cloud and CI/CD security, scripting, and vulnerability management.
Monarch Money: A subscription-based platform for personal budgeting and wealth management.
5+ YOE5+ years security engineering experience with application and AI security, proficiency in Python, SAST/DAST, secure code review, vulnerability management, and experience with Semgrep, Burp Suite, and Nuclei.
Publicis GroupeEuronext Paris: PUB: Global communications, advertising, and digital transformation holding.
10+ YOEBS/MS in CS or similar,10+ years experience,software development and CI/CD experience,SAST/DAST/MAST/RAST/IAST and vulnerability management,OWASP/CWE knowledge,cloud and auth expertise,threat modeling and cryptography.
Washington Health Benefit Exchange: Operates Washington state's health insurance enrollment marketplace.
7+ YOE7+ years in information security with application security, secure SDLC, DevSecOps, cloud/Azure experience; experience with code reviews, threat modeling, vulnerability management, and tools like Nessus, Rapid7, Nmap, and Burp Suite.