44 appsec engineer jobs at 37 companies in California
2mo
Save
Mark Applied
Hide
2mo
AppSec Engineer
Austin or Chicago or Denver or Los Angeles or San Diego or San Francisco or United States or Australia or New Zealand or Canada or United Kingdom or Philippines
$131k-$169k/yrHybridFull Time
Karbon: Practice management software for accounting firms.
4+ YOE4+ years security/development experience embedding AppSec in SDLC, cloud (Azure/AWS/GCP), SAST/SCA/DAST configuration, CI/CD security, code review, Python/PowerShell/Bash, and strong communication skills.
LENS: AI-powered technology for real-time traffic accident prevention.
Design, implement, and operate end-to-end security for cloud-native platforms; lead FedRAMP/GovRAMP compliance; perform threat modeling, appsec, and incident response; partner with engineering teams.
Boston or New York City or Los Angeles or San Francisco
$275k-$395k/yrOnsiteFull Time
Suno: AI platform for creating full songs from text prompts.
10+ YOE10+ years security engineering experience with deep expertise in AppSec, cloud/infrastructure security, or incident response; experience building security capabilities, mentoring teams, and participating in on-call incident response.
Boston or Chicago or Los Angeles or New York or San Francisco or Toronto or Vancouver or Vancouver
$145k-$175k/yrRemoteFull Time
Later: Provides software for social media scheduling and influencer marketing.
5+ YOE5+ years security engineering experience; strong application, cloud, and infrastructure security; SOC 2 and compliance experience; vulnerability management, IaC and CI/CD security; strong communication and software engineering skills.
OWASP, NIST, CIS Controls, SOC 2, ISO 27001, AWS Security Hub, Azure Security Center, GCP Security Command Center, SIEM, SOAR, Terraform, CloudFormation, C#, CI/CD
Merge: Unified API platform for connecting B2B software integrations.
3+ YOE3+ years security engineering with product/application focus; familiarity with OWASP, threat modeling, secure code review, SAST/DAST/SCA and CI/CD integration; able to read/write code; SaaS/API experience.
San Francisco or Toronto or United States or Canada
$180k-$260k/yrHybridFull Time
EvenUp: AI-powered document generation and analysis for personal injury law.
5+ YOE5+ years in security-focused engineering with hands-on architecture, SAST/DAST and CI/CD integration, cloud and application security, experience securing AI systems, strong scripting (Python) and relevant cybersecurity certification.
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
10+ YOE10+ years product security engineering experience; expertise in auth/authz, OWASP top 10, secure microservices, code reviews; hands-on in at least one OO language (Java or Golang); technical leadership and stakeholder management skills.
Corridor: Secures software codebases using AI-powered autonomous vulnerability detection.
5+ YOE5+ years in sales engineering or pre-sales, experience selling to security/AppSec or developer-tools buyers; strong technical demo/POV, and travel up to ~30%.
Git, CI/CD, IDEs, Code Review, Cursor, Claude Code, GitHub Copilot
BDNYSE: BDX: Manufactures medical devices, surgical instruments, and pharmacy automation systems.
3+ YOEBachelor's in cybersecurity/computer science or related; 3+ years in product security/product or software development or QA; experience with static code analysis and vulnerability scanning; foundational cryptography and PKI; knowledge of threat modeling and medical-device security.
Black Duck, Coverity, Veracode, Nessus, Snyk, Metasploit, SBOM, TLS, mTLS, HL7, FHIR, Bluetooth LE, STRIDE, PASTA, NIST, OWASP, PKI
Senior Principal Engineer Software - Cyber Security (San Diego CA)
San Diego, California, United States
$142k-$213k/yrOnsiteFull Time
Northrop GrummanNYSE: NOC: Designs and manufactures advanced aerospace and defense systems.
4+ YOEActive Top Secret/SCI clearance required. STEM degree with 4–8+ years engineering experience, DoD 8140/8570 or equivalent IAM certifications, RMF/NIST experience, vulnerability management, Windows/UNIX/RedHat and container familiarity, and use of compliance tools (Nessus, Nexpose, ACAS).
Security Technical Implementation Guides (STIG), Security Requirements Guides (SRGs), Center for Internet Security (CIS) Benchmark, Common Vulnerabilities and Exposures (CVE), Common Weakness Enumeration (CWE), OWASP, RMF, NIST SP 800-53, NIST SP 800-37, CNSSI, Windows, UNIX, RedHat, hypervisor, containerized environments, Nessus, Nexpose, SCAP, ACAS, Nmap, SAST, DAST
Apollo Research: Developing technical evaluations to detect and mitigate AI scheming risks.
5+ YOE5+ years hands-on security experience; threat modeling, red‑teaming, and attack design for software/AI systems; application/cloud/product security; able to read code, evaluate infra and controls, and produce clear security artifacts.
United States or Canada or San Francisco or New York City or Seattle
$190k-$273k/yrRemoteFull Time
Apollo.io: AI-powered platform for B2B sales intelligence and outreach automation.
5+ YOE5+ years software engineering or application security experience; strong coding skills (Ruby, Python), Linux and GCP familiarity, deep AppSec/vulnerability management, pen-testing and SAST experience, AI security, and strong communication.
TikTok: Global short-form video hosting and social media platform.
Hands-on offensive security/red teaming experience, strong appsec and privacy engineering knowledge, ability to threat-model privacy concepts and lead end-to-end technical assessments, strong communication skills.
New York City or Atlanta or Los Angeles or Jersey City or United States or Canada or United Kingdom or Ireland or Portugal or Romania or Australia or Puerto Rico
$134k-$168k/yrHybridFull Time
FanDuelNYSE: FLUT: Offers online sports betting and daily fantasy sports services.
Hands-on security engineering experience across the SDLC; coding in Python or Go; AI/LLM security and AI Agent experience; familiarity with cloud (AWS/GCP/Azure) and frameworks (OWASP, MITRE ATT&CK, NIST); code review and risk analysis skills.
Los Angeles or Palo Alto or Bellevue or Santa Monica
$178k-$313k/yrOnsiteFull Time
SnapNYSE: SNAP: Develops social media applications and augmented reality technology.
6+ YOE6+ years security experience post-Bachelor's, expertise in infrastructure/enterprise/access/appsec/detection or abuse domains; experience with cloud, Kubernetes, IAM, CSPM, AI tools, threat modeling, and securing distributed systems.
Eagan or Frisco or New York City or Richmond or San Francisco or Los Angeles or Irvine or McLean or Washington
$198k-$368k/yrHybridFull Time
Thomson ReutersNASDAQ: TRI: Provides professional software, data, and news services globally.
12+ YOE12+ years of cybersecurity engineering experience at Principal, Staff, or Distinguished Engineer level, with AI threat defense, production AI systems, mature SOC/CIRT, enterprise security architecture, and technical influence expertise.
Kai Cyber: Agentic AI platform for autonomous enterprise cybersecurity operations.
7+ YOE7+ years enterprise security pre-sales experience, hands-on AppSec and integration skills, deep vulnerability management knowledge, Bay Area coverage, ability to run POVs and travel ~50%.
Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, CrowdStrike, Microsoft Defender, Splunk, Microsoft Sentinel, ServiceNow, CVSS, EPSS, KEV, SCA, SAST, CI/CD, MEDDICC, MEDDPICC, Force Management, Challenger
AmaWaterways: Provides luxury river cruise vacations on international waterways.
8+ YOEBA/BS in CS or related (or equivalent experience); 8+ years software engineering with full-stack expertise (Next.js/React/TypeScript and .NET/C# or Node.js); experience with APIs, cloud (Azure), CI/CD, identity (Auth0/OIDC), security, observability, and mentoring/technical leadership.
Next.js, React, TypeScript, .NET, C#, Node.js, GraphQL, REST, SQL Server, PostgreSQL, Redis, Builder.io, Contentful, Sanity, Microsoft Azure, Azure DevOps, GitHub Actions, Auth0, OIDC, OAuth2, JWT, OWASP, SAST, DAST, Dash0, Datadog, New Relic, Git, GitHub, Microsoft Office Suite
St. Louis or Brentwood or Alaska or Arizona or Arkansas or California or Connecticut or Delaware or Hawaii or Idaho or Louisiana or Maine or Massachusetts or Michigan or Mississippi or Montana or Nebraska or Nevada or New Mexico or New York or North Carolina or North Dakota or Oregon or Rhode Island or South Carolina or South Dakota or Texas or Utah or Vermont or Washington or West Virginia or Wyoming or United States
HybridFull Time
Navitus Health Solutions: Transparent pharmacy benefit management and specialty pharmacy provider.
8+ YOEBachelor's in CS or related; 8+ years software engineering experience (5+ years with C#, .NET, React); experience with cloud-native, APIs, microservices, CI/CD, Git, Azure; technical leadership and mentoring experience.
C#, .NET, ASP.NET Core, React, TypeScript, JavaScript, REST APIs, GraphQL, Webhooks, API Management, Microsoft Azure App Services, Microsoft Azure Functions, Microsoft Azure Container Apps, Microsoft Azure Kubernetes Service (AKS), Microsoft Azure Storage, Microsoft Azure Databricks, Microsoft Azure Data Lake Storage Gen2, Microsoft Azure Synapse Analytics, Microsoft SQL Server, PostgreSQL, Microsoft Azure DevOps, GitHub Actions, CI/CD, Infrastructure as Code, Retrieval-Augmented Generation (RAG), Microsoft Azure OpenAI, Microsoft Azure AI Services, Intelligent Automation, Agent-Based Solutions, OWASP, OAuth2, OpenID Connect, DevSecOps, Git, Azure Repos, GitHub, TFS, Jira, Unix/Linux shell scripting