Source Job

$130,100–$187,000/yr
US

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.

Python Go Java JavaScript Application Security

20 jobs similar to Application Security Engineer II

Jobs ranked by similarity.

India

  • Partner with engineering, product, and DevOps teams to integrate security practices throughout the SDLC, focusing on cloud-native environments and automated pipelines.
  • Design, implement, and maintain security tooling and gates within CI/CD pipelines covering SAST, DAST, SCA, secrets detection, and container scanning.
  • Lead threat modeling, conduct application security assessments including code review and manual penetration testing, and triage bug bounty reports.

Hyland is the pioneer of the Content Innovation Cloud, delivering ubiquitous enterprise intelligence to organizations. With a team of nearly 4,000 employees, the company fosters an employee-centric culture focused on community impact and innovation.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

US

  • Secure AI systems and use AI to scale security, conducting security reviews and threat modeling of AI-integrated product features.
  • Deliver end-to-end application security reviews for high-risk features, working directly with engineering teams to surface and close risk.
  • Advance CI/CD pipeline security by operating and evolving security scanning controls in GitLab pipelines.

Smartsheet empowers teams to manage work and scale solutions by uniting human teams with AI agents. They are a large company with over 20 years of experience, fostering a culture where ideas are heard and contributions have real impact.

$134,000–$184,000/yr
Canada

  • Lead secure design reviews, threat modeling, and risk assessments for AI-driven products and APIs.
  • Embed security practices throughout the software and AI development lifecycle.
  • Architect and enforce security controls for AI/ML systems and cloud-native infrastructure.

AlphaSense provides AI-driven market intelligence and search platform trusted by over 6,000 enterprise customers. Founded in 2011, the company has more than 2,000 employees globally with offices in multiple countries.

UK

  • Perform hands-on security testing and code review across web applications and APIs.
  • Conduct threat modeling and embed secure development practices into the SDLC.
  • Build and tune security tooling, including SAST, DAST, and CI/CD automation.

Prolific builds human data infrastructure for AI development, connecting researchers with a global participant pool to collect high-quality, ethically sourced behavioral data. They are a mission-driven company trusted by world-leading research institutions and AI labs, with a remote-first culture.

$120,000–$154,440/yr
US 12w maternity 12w paternity

  • Architect, design, and implement end-to-end security solutions including firewalls, intrusion detection, and cloud security controls.
  • Collaborate with DevOps to integrate security into CI/CD pipelines and automate secure deployments.
  • Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.

Figure is transforming capital markets through blockchain, powering real products used by hundreds of thousands of consumers and institutions. With over 170 partners and $22 billion in home equity loans originated, Figure is the largest non-bank provider of home equity financing in the U.S., recognized as one of Forbes' Most Innovative Fintech Startups in 2025.

$152,000–$175,000/yr
US Unlimited PTO

  • Lead threat modeling, architecture reviews, and code reviews for web applications, APIs, and microservices.
  • Actively develop and commit code to fix security flaws in Python, Go, or JavaScript/TypeScript codebases.
  • Implement and manage security testing tools within CI/CD pipelines to catch vulnerabilities early in the SDLC.

RunPod is the AI Developer Cloud, providing a platform for developers to experiment, train, fine-tune, deploy, and scale AI. We are a small, remote-first team that has processed over 20 billion inference requests and closed a $100M Series A in June 2026.

EMEA

  • Drive application security initiatives across the SDLC, partnering with engineering teams to promote secure coding and security-by-design.
  • Integrate security testing tools into CI/CD pipelines and automate security processes using modern AppSec and DevSecOps tools.
  • Perform vulnerability analysis, source code review, and support threat modeling and secure design reviews.

Devoteam Cyber Trust is the cybersecurity arm of the Devoteam Group, offering end-to-end cyber resilience and managed security services. With 800+ experts across EMEA, they are ISO 27001 certified and serve clients in over 20 countries.

US 18w maternity 16w paternity

  • Contribute to secure-by-design practices and advance the S-SDLC program.
  • Mentor engineers on secure coding and career growth.
  • Evaluate and recommend AI-assisted security tooling.

Spring Health is a global mental health company eliminating every barrier to mental health. They reach more than 170 million people worldwide and are an AI-native company focused on expanding the reach, quality, and humanity of care.

Europe

  • Define security requirements and design application architectures following a secure-by-default approach.
  • Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
  • Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.

Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.

$111,000–$144,400/yr
US

  • Plan and execute application security testing across the software development lifecycle to identify vulnerabilities.
  • Communicate findings and risks to stakeholders and collaborate with teams to drive secure design practices.
  • Lead AI security initiatives including threat modeling and auditing third-party models and APIs.

Clear Capital is a national real estate analytics and valuation technology company that builds confidence in real estate decisions. Established in 2001, the company values integrity, empathy, and excellence in its team.

Australia 14w maternity 6w paternity

  • Design and implement security controls across Mable's platform, applications, and infrastructure
  • Embed security into the software development lifecycle through design reviews, threat modeling, and code reviews
  • Lead vulnerability assessments and coordinate remediation efforts across engineering teams

Mable is one of Australia's leading healthtech platforms connecting people with disability and older Australians with independent support workers. With over 25 million hours of support facilitated since 2014, they have been recognized on AFR's Top 100 and Deloitte Tech Fast 50, fostering a purpose-driven and dynamic team environment.

Canada Unlimited PTO

  • Own cloud and platform security end to end across AWS and Azure, including architecture, detection, and response.
  • Build self-serve security tooling and guardrails to replace manual processes and reduce risk.
  • Partner with engineering teams to embed security into CI/CD pipelines and product development.

Ada is an AI customer service platform that enables enterprise companies to deliver instant, proactive, and personalized customer experiences. Established in 2016, the Canadian company has powered over 5.5 billion interactions for brands like Square and YETI, backed by over $250M in funding from top-tier investors.

Global

  • Lead Application Security initiatives across HighLevel's products and engineering teams.
  • Conduct architecture reviews, threat modeling, and security assessments for web, mobile, and API applications.
  • Drive DevSecOps practices by automating security in CI/CD pipelines and managing security tooling.

HighLevel is an AI-powered, all-in-one white-label sales and marketing platform that empowers agencies and businesses to grow their digital presence. With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment with a culture rooted in creativity, collaboration, and impact.

Asia

  • Build production-grade security applications and services using Python.
  • Develop internal security platforms and tooling from scratch.
  • Design and enforce secure cloud architectures (AWS) and implement policy enforcement for IAM least-privilege models.

Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. They are trusted by 300+ million people in 100+ countries and have a diverse workforce.

Canada

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
  • Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
  • Contribute to security architecture reviews and support bug bounty programs and incident response.

Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.

$88,800–$125,800/yr
Canada 3w PTO 12w maternity 12w paternity

  • Proactively identify and drive security improvements across the product and platform.
  • Partner with engineering teams to threat model new features and review designs early in development.
  • Build and improve security tooling, libraries, and workflows to make secure development the default path.

Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.

$145,000–$175,000/yr
United States

  • Strengthen company-wide security posture through hands-on engineering, collaboration, and pragmatic standards, focusing on application security, cloud and infrastructure security, and secure development practices.
  • Define and implement scalable security standards supporting SOC 2 readiness through practical, automated, and auditable solutions, partnering with Engineering, Infrastructure, IT, Product, Legal, and other teams.
  • Build and maintain internal security tools, automation, and services that support secure development, compliance workflows, vulnerability management, and operational visibility.

Later is the world’s most intelligent influencer marketing company, built to give brands the confidence to create unforgettable campaigns by combining real creator relationships, trusted intelligence, and expert guidance. Trusted by leading enterprise brands including Nike, Wayfair, Unilever, and Southwest Airlines, Later bridges creativity and performance so campaigns deliver results.

$130,000–$170,000/yr
US

  • Partner with product and engineering teams to identify risks early and build security into new features.
  • Lead threat modeling and secure design reviews for new products and architecture changes.
  • Perform security-focused code reviews and maintain application security tooling integrated into CI/CD.

Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up. It is a small startup with a culture that prioritizes security and trust, and security is core to the product.

Asia

  • Design and implement secure application architectures considering authentication, authorization, data protection, and vulnerability management.
  • Develop and maintain secure coding guidelines, conduct security reviews, and implement security controls.
  • Communicate security risks to stakeholders and provide guidance on secure coding practices.

Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange. With over 300 million users in 100+ countries, it offers a diverse, fast-paced, and innovative work environment.