391 application security jobs at 172 companies in Texas
🚀PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yrOn-SiteFull Time
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
5+ YOE5+ years OWASP, SAST, DAST, SCA, RASP; 7+ years in application security or related field; strong web security knowledge; secure SDLC; Bachelor's in CS; CISSP/OSCP/CASE preferred.
ToyotaNYSE: TM: Designs and manufactures vehicles and provides automotive financial services.
3+ YOE3-6 years in application security; experience with SAST/DAST/SCA; code review; CI/CD; cloud security; IaC; strong QA of web, APIs, and mobile apps.
Las Vegas SandsNYSE: LVS: Operates integrated resorts featuring casinos, hotels, and convention centers.
3+ YOE3+ years cyber security/IT experience or Bachelor’s in CS; strong CI/CD and application security experience; hands-on AI-assisted development and GitHub Copilot experience; threat modeling, security tooling integration, incident response, and system/network administration skills.
GitHub, GitHub Copilot, Claude Code, Microsoft, IBM, Linux, SIEM
Quincy or Princeton or Berwyn or Clifton or Austin
$120k-$203k/yrHybridFull Time
State StreetNYSE: STT: Provides investment servicing and management to institutional investors.
14+ YOEDesign and review secure architectures for applications, APIs, cloud-native and AI systems; conduct threat modeling and risk assessments; embed secure-by-design, DevSecOps, and AI security practices.
Large Language Models (LLMs), Retrieval-Augmented Generation (RAG), Kubernetes, CI/CD, DevSecOps, Infrastructure as Code (IaC), SAST, DAST, IAST, software composition analysis (SCA), OWASP Top 10
KPMG: Global professional services network providing audit, tax, and advisory.
6+ YOE6+ years in application security/DevSecOps, strong appsec and AI-related risk knowledge, experience with SDLC/CI-CD and cloud (preferably Azure), bachelor's preferred, relevant certs preferred.
Hewlett Packard EnterpriseNYSE: HPE: Providing global edge-to-cloud infrastructure and IT solutions for businesses.
5+ YOE5–8+ years in application security; CI/CD security; SBOM/NIST/SSDF knowledge; secrets management; WAF and API security; SAST/DAST/SCA; cloud security; programming in Python/Java/Go/Node.js.
Vanguard: Provides mutual funds, ETFs, and investment management services.
5+ YOE5+ years related experience (including 3 years in IT security or application development), undergraduate degree or equivalent, hands-on web/API/network pentesting, SAST/DAST tooling preferred, Python or Java proficiency, preferred pentesting certifications.
DAST, SAST, MITRE ATT&CK, OWASP Top 10, OWASP Top 10 API, SANS Top 25, Python, Java
AbbVieNYSE: ABBV: Develops and sells innovative pharmaceutical and biopharmaceutical medicines.
4+ YOEDegree (BS/MS/PhD) with relevant years of experience, strong application security expertise (OWASP, secure coding), cloud and container knowledge (AWS/Azure/GCP, Docker, Kubernetes), experience with code analysis and vulnerability scanning tools.
New York or Connecticut or Texas or Rhode Island or Massachusetts
$118k-$261k/yrRemoteFull Time
CVS HealthNYSE: CVS: Provides retail pharmacy, health insurance, and pharmacy benefit management services.
7+ YOE2+ Mgmt7+ years in enterprise security and security program leadership; experience with cloud-native architectures, application security, vulnerability management, SAST/SCA/SBOM, developer enablement, and security automation.
U.S. BankNYSE: USB: Provider of personal, business, and institutional financial services.
5+ YOE5+ years AppSec experience with SAST/SCA, CI/CD tool integration (Jenkins), Java experience (2+ years), Docker/cloud familiarity, vulnerability triage using ServiceNow, and development of security automation and AI-driven AppSec capabilities.
PepsiCoNASDAQ: PEP: Global manufacturer and distributor of snacks and beverages.
Advanced expertise in AI and application security, threat modeling (STRIDE/PASTA), OWASP, cloud-native security (AWS/Azure/GCP), Python/Go, CI/CD integration, and mitigation of AI-specific threats; strong communication and analytical skills.
STRIDE, PASTA, OWASP Top 10, OWASP Top 10 for LLM Applications, AWS, Azure, GCP, Python, Go, CI/CD, Promptfoo, NVIDIA Garak, Protect AI, Lakera, HiddenLayer, Microsoft AI Security, LangChain, LangGraph, Semantic Kernel, MCP, OpenAI SDK, Azure AI Foundry, Amazon Bedrock, RAG
PepsiCoNASDAQ: PEP: Global food and beverage manufacturer and distributor.
Expertise in AI application security, threat modeling, cloud-native architectures, Python/Go, CI/CD integration, and mentoring; familiarity with LLMs, RAG, MCP, and AI threat mitigation.
STRIDE, PASTA, OWASP Top 10, OWASP Top 10 for LLM Applications, AWS, Azure, GCP, Python, Go, Promptfoo, NVIDIA Garak, Protect AI, Lakera, HiddenLayer, Microsoft AI Security, LangChain, LangGraph, Semantic Kernel, MCP, OpenAI SDK, Azure AI Foundry, Amazon Bedrock
EquinixNASDAQ: EQIX: Provides global data center colocation and digital interconnection services.
8+ YOETrainee role under the SkillBridge program; familiarity with security concepts; experience with CI/CD security tooling and cloud environments preferred.
PepsiCoNASDAQ: PEP: Produces and distributes global snack and beverage products.
Advanced expertise in AI and application security, threat modeling, cloud-native architectures (AWS preferred), Python or Go, CI/CD/DevSecOps integration, and experience mitigating AI-specific threats.
STRIDE, PASTA, OWASP Top 10, OWASP Top 10 for LLM Applications, AWS, Azure, GCP, Python, Go, Promptfoo, NVIDIA Garak, Protect AI, Lakera, HiddenLayer, Microsoft AI Security, LangChain, LangGraph, Semantic Kernel, MCP, OpenAI SDK, Azure AI Foundry, Amazon Bedrock
3MNYSE: MMM: Manufacturers diversified industrial, safety, consumer, and electronics products.
3+ YOEBachelor's in cybersecurity/computer science/technology, 3+ years application security experience, hands-on SAST/DAST/SCA and CI/CD integration, threat modeling knowledge, strong communication; must be authorized to work without sponsorship.