Source Job

$150,000–$230,000/yr
US Canada

  • Contribute production-quality code to the application (Node.js and Python), shipping security fixes end-to-end.
  • Build AI-powered automation and manage a bug bounty program, evaluating and reproducing submissions.
  • Define secure-by-design patterns and drive security standards across the architecture, including AI-integrated features.

Node.js Python Terraform AWS

20 jobs similar to Senior Application Security Engineer

Jobs ranked by similarity.

$104,300–$193,700/yr
US

  • Collaborate with DevOps and engineering teams to embed security throughout the software development lifecycle.
  • Implement automated security testing, including SAST, DAST, SCA, and container security, and strengthen cloud-native security controls.
  • Support compliance with PCI-DSS, GDPR, CCPA, and SOC 2, and evaluate secure adoption of AI-assisted coding tools.

Our partner is a technology company in the travel and hospitality industry. They have a collaborative remote culture and value employee development and diversity.

$120,000–$150,000/yr
US

  • Protect cloud infrastructure, applications, and customer data across a modern technology environment.
  • Identify and remediate vulnerabilities directly in application repositories and infrastructure code.
  • Build and tune SIEM detections, strengthen AWS security controls, and lead incident response.

Cloudbeds is a hospitality technology company providing cloud-based management solutions for lodging businesses. It operates as a remote-first organization with a globally distributed team across 40+ countries and a small, senior security team.

US 4w PTO 12w maternity 4w paternity

  • Act as the bridge between architectural intent and operational reality, mediating conflicts between security requirements and feasible implementation.
  • Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code.
  • Define and enforce security requirements for AI-powered features, including model access controls, prompt-injection mitigations, and output validation.

Rithum is the world's most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. More than 40,000 companies trust Rithum to grow their business across hundreds of channels, representing over $50 billion in annual GMV.

$229,000–$270,000/yr
Global Unlimited PTO

  • Lead technical vision for NodeZero's defensive agents, setting direction alongside AI researchers.
  • Write production code weekly, mentor engineers, and drive design and code reviews.
  • Own the technical strategy for autonomous remediation, from architecture to shipped features.

Horizon3 is a remote cybersecurity company focused on autonomous pentesting and attack path remediation. The team is a fusion of former Special Operations cyber operators, startup engineers, and security practitioners, with a culture of collaboration, ownership, and results.

Global

  • Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects.
  • Triage and validate bug bounty reports, assess severity, and coordinate remediation with engineering.
  • Build and operate security automation including AI-assisted code review, scanning, and findings-triage pipelines.

RootstockLabs builds Bitcoin-secured DeFi infrastructure enabling companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale. They operate at the intersection of crypto and institutional finance with a global, diverse team.

$124,750–$178,215/yr
US

  • Design, build, and maintain automation pipelines for workload packaging, validation, testing, deployment, and monitoring across AWS environments.
  • Collaborate with data engineers to operationalize workloads within a data lakehouse ecosystem and develop reusable infrastructure-as-code constructs using Terraform, AWS CDK, or CloudFormation.
  • Ensure pipelines meet enterprise security, compliance, and scalability standards while mentoring junior engineers and contributing to DevSecOps practices.

Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company uses AI to review applications and ensure fair, objective candidate evaluation, and operates in a distributed, fully remote environment.

$135,000–$155,000/yr
US

  • Design and enforce cloud security controls and IAM policies across multi-account AWS environments.
  • Embed automated security tools into CI/CD pipelines to catch vulnerabilities pre-deployment.
  • Develop automated detection and remediation workflows using Python, Bash, or Go and IaC tools.

The Tripadvisor Group connects people to experiences worth sharing, aiming to be the world's most trusted source for travel and experiences. It is a publicly traded company with a global portfolio of travel brands, fostering a culture of collaboration, agility, and traveler-first mindset.

Canada US

  • Lead complex, high-severity security incident responses as incident commander.
  • Design and build AI-assisted automation for security operations.
  • Own readiness programs, threat hunting, and insider risk capabilities.

1Password is a cybersecurity company that provides enterprise password management and unified access management, trusted by over 180,000 businesses. They are a remote-first company with a fast-paced, collaborative culture, and have surpassed $400M in ARR.

US Unlimited PTO

  • Support, configure, and extend workflow applications for federal customers.
  • Strengthen platform security guardrails, CI/CD, and infrastructure automation.
  • Deploy applications to on-premises and classified environments with Linux hardening.

The company supports workflow applications for federal and commercial customers, focusing on secure and AI-assisted development. The culture emphasizes mission impact, continuous improvement, and security-conscious engineering.

US Unlimited PTO

  • Build and tune the application security scanning program (SAST, DAST, SCA, container and IaC) to surface real risk.
  • Triage scan, penetration test, and bug bounty findings, prioritizing by risk and tracking remediation to closure.
  • Partner with engineering on threat modeling, secure-coding standards, and hands-on fixes.

Turquoise Health is a Series C price transparency platform building a more open, efficient healthcare marketplace for finance leaders. They're a remote-first US team backed by top investors, powering transparency for 300+ enterprise organizations.

Europe

  • Architect and oversee advanced security monitoring and threat detection frameworks across diverse systems and log sources.
  • Lead the integration of security into the software development lifecycle, including Security-as-Code and automated SAST, DAST, and SCA capabilities within CI/CD pipelines.
  • Own the end-to-end vulnerability management strategy across infrastructure and applications, prioritizing remediation according to business risk.

The partner company operates a large-scale digital platform and a globally distributed technology ecosystem connected to gaming and esports communities. They maintain a flexible, distributed, and inclusive work environment focused on equal opportunity and technical ownership.

$150,000–$155,000/yr
US

  • Conduct application and cloud security assessments to identify risks and vulnerabilities.
  • Collaborate with development teams to integrate security best practices into the SDLC.
  • Support vulnerability management, incident response, and security awareness education.

Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.

Global 4w PTO

  • Perform weekly code reviews to catch security vulnerabilities before they ship.
  • Coordinate external security audits and penetration tests, and track remediation.
  • Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.

EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.

US Unlimited PTO

  • Lead the technical vision for platform hardening across AWS and GCP, including tier-0 access and secrets services.
  • Own the hardening roadmap for critical cloud infrastructure and drive operational excellence with rigorous on-call practices.
  • Mentor a global team of engineers and partner cross-functionally to build secure-by-default controls.

DoorDash is a technology and logistics company building the most reliable delivery network for consumers, merchants, and dashers. The company is growing rapidly and fosters a culture of learning, customer obsession, and inclusive leadership.

$170,000–$235,000/yr
US

  • Design and implement backend services for licensing, entitlements, feature access, and usage limits across NodeZero's product and APIs.
  • Build and evolve provisioning, admin experience, MSP/MSSP capabilities, and audit logging for a multi-tenant SaaS platform.
  • Operate production services with monitoring, incident response, and a high bar for design quality and test coverage.

Horizon3 is a fast-growing, remote cybersecurity company that helps organizations proactively find, fix, and verify exploitable attack vectors through its NodeZero autonomous pentesting platform. The team is a fusion of former special operations cyber operators and startup engineers, fostering a culture of respect, collaboration, ownership, and results.

$190,000–$250,000/yr
Global

  • Lead and mentor diverse software engineering teams across the Americas and EMEA, fostering innovation, collaboration, and continuous improvement.
  • Drive software delivery transformation through agentic development, AI-assisted engineering tools, and modern delivery models.
  • Oversee architecture and hands-on technical leadership for platform and AI services across Python, TypeScript, AWS, and LLM frameworks.

This partner company builds financial technology products, platform services, and AI-driven solutions for global businesses. It operates as a remote-first organization with a high-trust culture and a focus on engineering innovation and collaboration across EMEA and APAC.

US

  • Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
  • Build automation, policy-as-code, and security tooling that enables development teams to 'shift left' and integrate end-to-end security into their workflows.
  • Drive vulnerability management and remediation efforts, prioritizing issues, implementing mitigations, and designing strategic preventative controls in software supply chains from development through production.

Wiz is redefining security for the AI era, enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. As one of the fastest-growing startups ever, we are trusted by over 65% of the Fortune 100 and scan over 230 billion files daily, with a culture that values world-class talent and is now powered by Google.

$120,000–$150,000/yr
US

  • Fix vulnerabilities across the stack by writing pull requests in application repositories and Terraform.
  • Build and tune SIEM detections, mapping coverage to MITRE ATT&CK and reducing false positives.
  • Lead incident response, harden AWS estate, and automate security workflows with code.

Cloudbeds is a hospitality management platform powering hotels across 150 countries, processing billions in bookings annually. The company is a remote-first team of 650+ across 40+ countries, recognized for innovation and an inclusive culture.

US

  • Design, build, and maintain CI/CD pipelines for application and infrastructure delivery.
  • Automate infrastructure provisioning and configuration using Terraform and Ansible.
  • Integrate security scanning, vulnerability detection, and automated testing into software delivery pipelines.

This company delivers secure, reliable technology for critical federal acquisition systems. They offer a remote work environment and support mission-critical government technology initiatives.

$98,000–$116,000/yr
US

  • Integrate AppSec tools into CI/CD pipelines and manage application security vulnerabilities.
  • Monitor and respond to security incidents, tuning WAF policies and security rulesets.
  • Collaborate with IT partners to perform security reviews and remediate findings across cloud platforms.

EMCOR Group, Inc. is a Fortune 500 leader in mechanical and electrical construction, industrial and energy infrastructure, and building services. As a large company with a diverse portfolio, it emphasizes a culture of security and collaboration.