296 appsec engineer jobs at 197 companies in United States

2mo
Save
Mark Applied
Hide
AppSec Engineer
New York City, New York, United States
$220k-$250k/yr OnsiteFull Time
Digital Asset US Corp
Digital Asset US Corp: Builds privacy-enabled, interoperable blockchain infrastructure for institutional finance.
3+ YOE3-7 years IT/application security experience; vulnerability assessments, cloud security (Google Cloud/AWS/Azure), scripting, Kubernetes/GKE, AppSec tooling; Bachelor’s in relevant field required.
Daml, Canton, Google Cloud, AWS, Azure, Python, GoLang, Bash, GKE, Cloud Armor, KMS, HSMs, SAST, DAST, SCA
2mo
Save
Mark Applied
Hide
AppSec Engineer
United States or Canada
RemoteFull Time
Theori
Theori: Private cybersecurity firm providing offensive security consulting, AI-powered security testing, AI red teaming, and training to organizations.
Experience in security engineering, vulnerability research or penetration testing; CTF or bug bounty experience preferred; proficiency auditing code; ability to triage AI-generated static analysis reports and write proof-of-concept exploits.
2mo
Save
Mark Applied
Hide
AppSec Engineer
Austin or Chicago or Denver or Los Angeles or San Diego or San Francisco or United States or Australia or New Zealand or Canada or United Kingdom or Philippines
$131k-$169k/yr HybridFull Time
Karbon
Karbon: Cloud practice-management software that helps accounting firms manage workflows, clients, communications, and billing.
4+ YOE4+ years security/development experience embedding AppSec in SDLC, cloud (Azure/AWS/GCP), SAST/SCA/DAST configuration, CI/CD security, code review, Python/PowerShell/Bash, and strong communication skills.
Microsoft .NET/C#, JavaScript, React, EmberJS, Python, Azure, AWS, GCP, PowerShell, Bash, Claude Code, GitHub Co-Pilot, Portswigger Burp, SAST, SCA, DAST, GitHub Actions, Azure Devops, EDR, MDM
5d
Save
Mark Applied
Hide
Staff AppSec Engineer
United States
$156k-$215k/yr RemoteFull Time
SentinelOne
SentinelOneNYSE: S: AI-native cybersecurity platform for autonomous threat protection.
7+ YOERequires 7+ years in application or product security, expert proficiency in at least two of Go, Java, and C#, SAST rule authoring, threat modeling, secure SDLC, Git, CI/CD, and executive communication.
Go, Java, C#, OWASP Top 10, CWE Top 25, SAML, OAuth, OIDC, JWT, ASVS, Python, Django, Flask, Node.js, Express, IDA Pro, Binary Ninja, Ghidra, dnspy, ilspy, JAD, CFR, Git, CI/CD, SAST
1mo
Save
Mark Applied
Hide
AppSec Sales Engineer - East
Tampa or Atlanta
RemoteFull Time
Harness
Harness: Private software providing AI software delivery and DevOps automation to engineering teams.
Pre-sales experience supporting DevSecOps or cybersecurity SaaS, hands-on knowledge of application/API/AI security practices and tools, strong presentation and communication skills, willingness to travel occasionally.
SCA, SAST, DAST, API Security, AI Security, Zoom
3w
Save
Mark Applied
Hide
Senior AI AppSec Engineer
United States
$130k-$160k/yr RemoteFull Time
Fabric Health
Fabric Health: Public-benefit helping busy families access healthcare and public benefits through community-based services.
5+ YOE5+ years in application security, including penetration testing and secure code review; AI security expertise; programming proficiency; SAST/DAST, CI/CD, OWASP, AWS, and regulated healthcare security experience.
Ruby on Rails, Python, React, Node.js, SAST, DAST, CI/CD, AWS, OWASP Top 10, FHIR, HL7, Epic, Cerner, Google Meet, Zoom, Skype, WhatsApp, LinkedIn, Google Forms
1w
Save
Mark Applied
Hide
Security Engineer, AWS AppSec
Herndon or Seattle
$136k-$184k/yr OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Multinational technology focused on e-commerce and cloud computing.
Bachelor's degree in engineering, computer science, or related field; security engineering experience; web security knowledge; coding or scripting ability; and experience with application security, testing, or incident response.
AWS, Java, C++, Python
2w
Save
Mark Applied
Hide
Senior Associate - AI AppSec Engineer
New York City, New York, United States
$124k-$177k/yr HybridFull Time
New York Life Insurance
New York Life Insurance: Mutual life insurance providing insurance and investment solutions.
5+ YOEBachelor's degree or equivalent and 5+ years in application or cloud security. Requires Python, AI platform security, CI/CD, infrastructure-as-code, cloud IAM, secure API design, and AI threat-model knowledge.
Google Cloud Vertex AI, Amazon SageMaker, Azure Machine Learning, Python, LangChain, LangGraph, Vertex AI Agent Builder, ADK, CrewAI, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI RMF, Google Secure AI Framework (SAIF), OPA/Rego, Cloud Custodian, Sentinel, Lakera, Protect AI, NeMo Guardrails, Llama Guard, Vertex AI Safety Filters, CI/CD, SLSA, SBOMs
2w
Save
Mark Applied
Hide
Senior Associate - AI AppSec Engineer
New York City, New York, United States
$124k-$177k/yr HybridFull Time
New York Life Insurance
New York Life Insurance: Mutual life insurance providing insurance and investment solutions.
5+ YOEBachelor's degree or equivalent practical experience, 5+ years in application or cloud security, production AI platform security, CI/CD and infrastructure-as-code controls, cloud IAM, application security, and Python automation.
Google Cloud Vertex AI, Amazon SageMaker, Azure Machine Learning, Python, LangChain, LangGraph, Vertex AI Agent Builder, ADK, CrewAI, MITRE ATLAS, NIST AI RMF, OPA/Rego, Cloud Custodian, Sentinel, Lakera, Protect AI, NeMo Guardrails, Llama Guard, Vertex AI Safety Filters, CI/CD, SLSA, SBOMs, IAM
1mo
Save
Mark Applied
Hide
Security Engineer
Los Angeles, California, United States
OnsiteFull Time
LENS
LENS: AI traffic-safety serving public-safety agencies and transportation departments with real-time highway hazard detection.
Design, implement, and operate end-to-end security for cloud-native platforms; lead FedRAMP/GovRAMP compliance; perform threat modeling, appsec, and incident response; partner with engineering teams.
GCP, AWS, Azure, KMS, OWASP ZAP, OX suites, SIEM, Splunk, GSO
2mo
Save
Mark Applied
Hide
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions
Essnova Solutions: Minority-owned Alabama small-business government contractor delivering IT, professional, geospatial, healthcare, and environmental services to public and commercial clients.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
1mo
Save
Mark Applied
Hide
Senior Security Engineer
Burlington, Vermont, United States
HybridFull Time
Mach7 Technologies, Inc.
Mach7 Technologies, Inc.: A provider of enterprise imaging solutions that consolidates medical images and supports secure, accessible patient care.
5+ YOE5+ years security engineering with strong AppSec focus; threat modeling, secure code review, SAST/DAST/SCA, SBOM and supply-chain experience; ability to read code and communicate risk to engineers and executives.
Semgrep, Snyk, Burp Suite, OWASP ZAP, SAST, DAST, SCA, SBOM, CycloneDX, SPDX, GitHub Actions, Jenkins, Python, Go, TypeScript, C/C++, OpenSSF Scorecards, SLSA, NIST SSDF, SOC 2, ISO 27001, DICOM, HL7
3w
Save
Mark Applied
Hide
Lead Security Engineer
Boston or New York City or Los Angeles or San Francisco
$275k-$395k/yr OnsiteFull Time
Suno
Suno: Private AI music platform that helps people create complete songs from text prompts.
10+ YOE10+ years security engineering experience with deep expertise in AppSec, cloud/infrastructure security, or incident response; experience building security capabilities, mentoring teams, and participating in on-call incident response.
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
Ann Arbor or United States or Canada
$172k-$233k/yr RemoteFull Time
Censys
Censys: Internet intelligence and cybersecurity software providing threat hunting and attack-surface management to governments and enterprises.
10+ YOE10+ years in security engineering/DevSecOps/SRE; expertise securing Kubernetes, cloud (GCP), IaC, CI/CD AppSec tooling, scripting (Python/Bash), threat frameworks, and on-call participation.
Kubernetes, Google Cloud Platform (GCP), Helm, Crossplane, GitHub Actions, ArgoCD, Terraform, Python, Bash, Orca Security, Aikido Security, TensorFlow, PyTorch, Prometheus, Grafana, OpenTelemetry, MITRE ATT&CK
2mo
Save
Mark Applied
Hide
Application Security Engineer
Miami, Florida, United States
HybridFull Time
Opendoor
OpendoorNasdaq: OPEN: Public U.S. real estate technology that buys and sells homes for residential sellers and buyers.
5+ YOE5+ years application security or software engineering experience; hands-on with Python/Go/TypeScript/Ruby, AppSec toolchain (GitHub Advanced Security, Semgrep, secret scanning), cloud and Kubernetes security, threat modeling, and AI/automation for vulnerability triage.
Go, Python, TypeScript, Ruby, Terraform, AWS, GCP, Azure, Kubernetes, Apollo GraphQL, GitHub Advanced Security, CodeQL, Dependabot, secret scanning, Semgrep, HackerOne, Burp Suite, Cloudflare WAF, Claude, OpenAI, MCP
2mo
Save
Mark Applied
Hide
Security Engineer
United States or India
RemoteFull Time
Outmarket AI
Outmarket AI: AI software platform for insurance brokerages, MGAs, wholesalers, and carriers, automating commercial insurance workflows.
4+ YOE4+ years security engineering experience, strong application security depth, hands-on cloud-native and multi-tenant security, knowledge of OWASP risks, practical partnership with engineers.
GCP IAM, OWASP, SOC 2 Type II
1mo
Save
Mark Applied
Hide
Senior Application Security Engineer
New York, New York, United States
$220k-$235k/yr HybridFull Time
Savvy Wealth
Savvy Wealth: Technology-enabled wealth management platform serving independent financial advisors with software, operations, compliance, and marketing support.
5+ YOE5+ years hands-on security engineering with application/product security, strong coding skills, AppSec toolchain experience (secrets, SCA, SAST), cloud (AWS/GCP) and Cloudflare experience, OAuth/SaaS hardening, GitHub/CICD security, and strong communication.
AWS, GCP, Cloudflare, Google Workspace, GitHub, Rippling, Slack, Claude
3w
Save
Mark Applied
Hide
Lead Information Security Engineer
Charlotte or Irving or Chandler or Minneapolis or United States
$119k-$206k/yr HybridFull Time
Wells Fargo
Wells FargoNYSE: WFC: Multinational financial services providing banking and investment products.
5+ YOERequires 5+ years of information security engineering experience, AppSec expertise, tooling integration, CI/CD knowledge, leadership, regulated-environment experience, and strong written, verbal, and presentation skills.
SAST, DAST, SCA, Infrastructure as Code (IaC), GitHub, Jira, ServiceNow, Jenkins, Harness, CI/CD, OWASP, MITRE CVE/CWE, Cursor, GitHub Copilot, Checkmarx, Black Duck, Prisma Cloud, TruffleHog, GitHub Advanced Security (GHAS), Snyk, Socket, Invicti, Qualys
1mo
Save
Mark Applied
Hide
Senior Security Engineer
Boston or Chicago or Los Angeles or New York or San Francisco or Toronto or Vancouver or Vancouver
$145k-$175k/yr RemoteFull Time
Later
Later: Private influencer marketing and social media management serving brands, agencies, and creators.
5+ YOE5+ years security engineering experience; strong application, cloud, and infrastructure security; SOC 2 and compliance experience; vulnerability management, IaC and CI/CD security; strong communication and software engineering skills.
OWASP, NIST, CIS Controls, SOC 2, ISO 27001, AWS Security Hub, Azure Security Center, GCP Security Command Center, SIEM, SOAR, Terraform, CloudFormation, C#, CI/CD
2mo
Save
Mark Applied
Hide
Security Engineer
New York City or San Francisco
$165k-$200k/yr OnsiteFull Time
Merge
Merge: B2B software integration platform serving SaaS companies, Fortune 500 organizations, and AI agents.
3+ YOE3+ years security engineering with product/application focus; familiarity with OWASP, threat modeling, secure code review, SAST/DAST/SCA and CI/CD integration; able to read/write code; SaaS/API experience.
OWASP, SAST, DAST, SCA, CI/CD