423 appsec jobs at 303 companies in United States

PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yr On-SiteFull Time
HiringCafe
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
Node.js, Python, Elasticsearch, Redis
1w
Save
Mark Applied
Hide
AppSec Engineer
United States or O'Fallon
$75k-$158k/yr RemoteFull Time
CACI
CACINYSE: CACI: Provides information technology and professional services to government clients.
6+ YOEActive Secret clearance,6+ years AppSec/pen testing experience, advanced Fortify and SonarQube proficiency, secure code review and SDLC experience, DoD 8140 certifications, bachelor’s degree preferred.
Fortify, SonarQube
1mo
Save
Mark Applied
Hide
AppSec Engineer
Austin or Chicago or Denver or Los Angeles or San Diego or San Francisco or United States or Australia or New Zealand or Canada or United Kingdom or Philippines
$131k-$169k/yr HybridFull Time
Karbon
Karbon: Practice management software for accounting firms.
4+ YOE4+ years security/development experience embedding AppSec in SDLC, cloud (Azure/AWS/GCP), SAST/SCA/DAST configuration, CI/CD security, code review, Python/PowerShell/Bash, and strong communication skills.
Microsoft .NET/C#, JavaScript, React, EmberJS, Python, Azure, AWS, GCP, PowerShell, Bash, Claude Code, GitHub Co-Pilot, Portswigger Burp, SAST, SCA, DAST, GitHub Actions, Azure Devops, EDR, MDM
1w
Save
Mark Applied
Hide
AppSec Engineer
United States or O'Fallon
$75k-$158k/yr RemoteFull Time
CACI International
CACI InternationalNYSE: CACI: Provides information technology and engineering services for government agencies.
6+ YOEActive Secret clearance,6+ years application security experience, advanced Fortify and SonarQube skills, penetration testing and secure code review experience, bachelor’s degree in a technical field, and DoD 8140-related certifications.
Fortify, SonarQube
1mo
Save
Mark Applied
Hide
AppSec Engineer
United States or Canada
RemoteFull Time
Theori
Theori: Provides AI-powered cybersecurity platforms and offensive security research services.
Experience in security engineering, vulnerability research or penetration testing; CTF or bug bounty experience preferred; proficiency auditing code; ability to triage AI-generated static analysis reports and write proof-of-concept exploits.
2mo
Save
Mark Applied
Hide
Senior Security Engineer - AppSec
Santa Clara, California, United States
$186k-$279k/yr OnsiteFull Time
Pure Storage
Pure StorageNYSE: PSTG: Provides all-flash enterprise data storage and management solutions.
Senior AppSec engineer with CI/CD security integration, automation, and collaboration across product and DevOps teams.
3mo
Save
Mark Applied
Hide
AppSec & DevSecOps Engineer
United States
$120k-$135k/yr HybridFull Time
Public Partnerships
Public Partnerships: Provides financial management services for self-directed home care.
5+ YOEExperience in application security and DevSecOps; secure SDLC, CI/CD security, vulnerability management, cloud security, governance/compliance.
SAST, DAST, SCA, IaC Scanning, Terraform, CloudFormation, Docker, Kubernetes, AWS, Azure, GCP
3mo
Save
Mark Applied
Hide
Lead Cloud Security/AppSec Engineer
Cambridge, Massachusetts, United States
$148k-$204k/yr OnsiteFull Time
Flagship Pioneering
Flagship Pioneering: Conceives, creates, and builds life science platform companies
5+ YOE5+ years in cloud security or security engineering; strong AWS security services; AppSec in CI/CD; IaC and scripting; AI-augmented security workflows; excellent collaboration with I&O and engineering teams.
AWS Security Hub, GuardDuty, IAM, SCPs, CloudTrail, Wiz, SAST, DAST, SCA, Terraform, Python, Bedrock, EKS, LLM APIs, agentic orchestration frameworks
2d
Save
Mark Applied
Hide
AppSec Sales Engineer - East
Tampa or Atlanta
RemoteFull Time
Harness
Harness: AI-powered platform for automating software delivery and DevOps.
Pre-sales experience supporting DevSecOps or cybersecurity SaaS, hands-on knowledge of application/API/AI security practices and tools, strong presentation and communication skills, willingness to travel occasionally.
SCA, SAST, DAST, API Security, AI Security, Zoom
1mo
Save
Mark Applied
Hide
Lead Enterprise AppSec Architect
Saint Petersburg or Memphis or Southfield
HybridFull Time
Raymond James
Raymond JamesNew York Stock Exchange: RJF: Provides wealth management, investment banking, and retail banking services.
7+ YOE7+ years in application security engineering or architecture; secure design reviews, threat modeling, vulnerability management; secure coding practices; cloud and on‑prem architectures; encryption, IAM, and secure communications; CI/CD integration.
AWS, Azure, OAuth, Single Sign-On, multi-factor authentication, certificate-based cryptography, token-based cryptography, SAST, DAST, SCA, CI/CD, encryption, IAM
1mo
Save
Mark Applied
Hide
Sr. Manager, Software Engineering (AppSec) (52017)
United States
$165k-$247k/yr HybridFull Time
OpenText
OpenTextNASDAQ: OTEX: Develops software for enterprise information management and digital transformation.
8+ YOE3+ Mgmt8+ years software engineering; 3+ years in leadership; SaaS/cloud-native; application security concepts; modern languages and cloud platforms; agile practices.
.NET, HTML/CSS/JS, AWS, Azure, GCP, SAST, DAST, Software Composition Analysis
2mo
Save
Mark Applied
Hide
Manager, Security Engineering, Cloud & AppSec
United States
$150k-$185k/yr RemoteFull Time
Horizon3.ai
Horizon3.ai: Autonomous penetration testing platform for continuous security assessment.
5+ YOE5+ MgmtLeads cloud and application security teams; strong AWS, Terraform, GitLab, SDLC security; 5+ years in cybersecurity; experienced in security programs and governance.
AWS, Terraform, Crossplane, ArgoCD, GitLab, CI/CD security tooling, Cloud security monitoring, IAM
2mo
Save
Mark Applied
Hide
Sr. Security Engineer, AppSec - Amazon Stores Security
New York, New York, United States
$175k-$237k/yr OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
8+ YOE4+ years troubleshooting; 5+ years security experience; 4+ years scripting; knowledge of multiple languages; bachelor's degree; threat modeling; 8+ years of Application Security/Development.
Scala, Java, Python, C/C++, Go, JavaScript
1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer (AppSec)
Austin, Texas, United States
OnsiteFull Time
webAI
webAI: Secure on-device AI infrastructure for distributed enterprise applications
7+ YOE7+ years in cybersecurity/appsec, offensive testing and secure SDLC experience; expertise securing distributed systems and Rust; strong cryptography and threat modeling skills; excellent communication.
Rust
2mo
Save
Mark Applied
Hide
Lead AppSec Engineer
Los Angeles or Washington or United States
$150k-$220k/yr RemoteFull Time
Virtualitics
Virtualitics: Provides an AI-native platform for readiness and analytics.
Technical leadership in application security with hands-on AI/ML experience, threat modeling, cloud and container security (AWS/GCP/Azure, Docker, Kubernetes), familiarity with SAST/DAST/container scanning and security platforms (Wiz, Snyk, GitHub Advanced Security), and experience designing secure AI workflows.
Claude Code, Cursor, AWS, GCP, Azure, Docker, Kubernetes, Wiz, Snyk, GitHub Advanced Security, SAST, DAST, container scanning, CI/CD
1w
Save
Mark Applied
Hide
AppSec Security Specialist
United States
HybridFull Time
Rezdy
Rezdy: B2B software for managing tour and activity bookings.
4+ YOE4+ years in application security or related field; experience with web app security testing, vulnerability management, SAST/DAST/SCA, EDR/DLP/SIEM/SOAR, CrowdStrike and KnowBe4; strong communication and remediation tracking skills.
EDR, DLP, SIEM, SOAR, CrowdStrike, KnowBe4, SAST, DAST, SCA, GRC platforms
1mo
Save
Mark Applied
Hide
Staff AppSec Engineer
Washington or United States
$210k-$230k/yr RemoteFull Time
Upside
Upside: Personalized cashback rewards platform for everyday brick-and-mortar purchases.
6+ YOE6+ years in application/product security, hands-on Python code review, vulnerability management, deep AWS security experience (Lambda, Control Tower), experience integrating AI tools, strong communication; Bachelor's preferred.
GitHub Advanced Security, GitHub Actions, GitHub Copilot, Python, Terraform, AWS, AWS Lambda, DynamoDB, S3, SNS, SQS, IAM, VPCs, AWS Control Tower, ChatGPT, Snowflake, SQL
1w
Save
Mark Applied
Hide
Team Lead, AppSec
Boston or United States or Dominican Republic or Canada
$175k-$200k/yr RemoteFull Time
Forward Financing
Forward Financing: Provides fast, flexible capital to underserved small businesses.
7+ YOE7+ years in application/product/offensive security with leadership experience; hands-on pentesting, code review, AWS and secure SDLC experience; proficiency with Ruby, Python, or Go; strong communication skills.
AWS, Ruby, Python, Go, LLM
3mo
Save
Mark Applied
Hide
Product Marketing Manager | AI AppSec
New York City or Paris or Amsterdam
HybridFull Time
Escape
Escape: AI-powered offensive security and API vulnerability detection platform
5+ YOE5+ years total experience, 2+ years product marketing, cybersecurity or developer tools, marketing to technical audiences, end-to-end launches, strong storytelling, cross-functional collaboration.
1mo
Save
Mark Applied
Hide
Senior Security Engineer, Product AppSec
United States or Texas or Seattle
$198k-$368k/yr RemoteFull Time
Veeam
Veeam: Data resilience and security for hybrid cloud environments
8+ YOEUS citizens only. 8+ years in application/product security or DevSecOps, 3+ years SAST/DAST/SCA/IAST and vulnerability management experience, experience with CI/CD, cloud, IaC, scripting, secure SDLC, and API integrations.
GitHub Actions, Microsoft Azure DevOps, Jenkins, GitLab CI, Jira, SIEM, SAST, DAST, SCA, IAST, CSPM, Azure, AWS, GCP, Terraform, Kubernetes, Docker, SLSA, Sigstore, SBOM, Python, Bash, PowerShell, OPA, Gatekeeper, LinkedIn Learning, O’Reilly
2w
Save
Mark Applied
Hide
Web Developer / Application Security (AppSec) Engineer
Washington, District of Columbia, United States
OnsiteFull Time
ASSYST
ASSYST: An IT firm specializing in digital transformation, DevSecOps, cybersecurity, and AI integration for government agencies.
Experience with secure SDLC, DevSecOps automation, vulnerability remediation, and protecting web applications; development experience with REST APIs, SQL, .NET/C#, JavaScript, Python, Node.js, React, TypeScript; familiarity with SIEM, IDS/IPS, EDR/NDR, Wireshark; U.S. citizenship required; security certifications preferred.
REST APIs, SQL, .NET/C#, JavaScript, Python, Node.js, React, TypeScript, SIEM, IDS/IPS, EDR/NDR, Wireshark, WAF, NIST, FISMA, FedRAMP