Source Job

US 18w maternity 16w paternity

  • Contribute to secure-by-design practices and maturing SAST, SCA, and DAST programs.
  • Develop Secure AI Development Lifecycle and AI-assisted threat modeling framework.
  • Mentor engineers on secure coding and foster cross-functional collaboration.

Application Security Cloud Security AI/ML Security

20 jobs similar to Senior Application Security Engineer II

Jobs ranked by similarity.

US Unlimited PTO

  • Build and tune the application security scanning program (SAST, DAST, SCA, container and IaC) to surface real risk.
  • Triage scan, penetration test, and bug bounty findings, prioritizing by risk and tracking remediation to closure.
  • Partner with engineering on threat modeling, secure-coding standards, and hands-on fixes.

Turquoise Health is a Series C price transparency platform building a more open, efficient healthcare marketplace for finance leaders. They're a remote-first US team backed by top investors, powering transparency for 300+ enterprise organizations.

$157,675–$238,500/yr
US

  • Deliver accurate security assessments of software, code, and firmware, evaluating resilience against AI-driven attacks.
  • Build and pressure-test novel AI-enabled security tooling and workflows, then drive adoption across the security org.
  • Partner cross-functionally to define and drive Samsara's medium- and long-term AI security strategy.

Samsara provides a Connected Operations Cloud platform that helps organizations improve safety, efficiency, and sustainability of physical operations. As a publicly traded company, they foster a culture of rapid career development and hyper growth, with a high-caliber team.

US Unlimited PTO

  • Lead security assessments of AI/ML models, data pipelines, and AI-enabled applications, identifying vulnerabilities such as prompt injection, model inversion, data poisoning, and adversarial inputs.
  • Partner with Data & Analytics and Engineering to embed security requirements and threat modeling into the AI development lifecycle, from data collection through model deployment.
  • Build and maintain guardrails, monitoring, and detection controls for AI systems in production, flagging anomalous model behavior and unauthorized data access.

Interra Health is a healthcare technology company that helps providers and patients navigate the prescription journey. It is a fast-growing, mission-driven team of about 100 employees, formed through the merger of DoseSpot, Arrive Health, and pVerify, and focused on reducing friction and improving access to medications.

$140,000–$160,000/yr
US

  • Design and maintain secure architectures across AWS, Azure, and GCP with infrastructure-as-code and policy-as-code enforcement.
  • Secure AI/ML pipelines and LLM applications, addressing OWASP Top 10 for LLMs and implementing guardrails and content-filtering controls.
  • Drive security operations, including SIEM monitoring, incident response, and supporting HIPAA/HITRUST/SOC 2 compliance.

Reveleer delivers a unified platform for risk adjustment, quality improvement, clinical intelligence, and member management for health plans and provider organizations in value-based care. Trusted by 80+ customer organizations nationwide, the company fosters a collaborative, compliance-focused culture with transparent, human-in-the-loop AI at its core.

US Unlimited PTO

  • Deliver Application Security services including assessments, threat modeling, and source code reviews for web, mobile, AI, and thick client applications.
  • Perform AI/LLM and agentic security assessments, including prompt injection, model bypass, and tool-calling exploitation, mapped to OWASP Top 10 for LLM and Agentic Applications.
  • Build and extend AI-driven tooling and automation harnesses to improve testing coverage, consistency, and efficiency.

GuidePoint Security provides trusted cybersecurity expertise, solutions, and services to help organizations make better decisions and minimize risk. With over 1,300 employees, it is a rapidly growing, profitable, privately-held value added reseller focused exclusively on information security.

US 4w PTO 16w maternity 16w paternity

  • Perform security design reviews and threat modeling for new products and features, including AI-enabled services.
  • Conduct manual penetration testing of web, API, mobile, and cloud-native applications, and validate third-party findings.
  • Drive adoption of secure coding practices and improve security automation in CI/CD pipelines.

Iru is an AI-powered security & IT platform that unifies identity and access, endpoint security, and compliance automation for fast-growing companies. Backed by top investors and valued at $850 million, it serves customers like Cursor and Vercel, and is recognized for employee engagement.

US 4w PTO 12w maternity 4w paternity

  • Act as the bridge between architectural intent and operational reality, mediating conflicts between security requirements and feasible implementation.
  • Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code.
  • Define and enforce security requirements for AI-powered features, including model access controls, prompt-injection mitigations, and output validation.

Rithum is the world's most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. More than 40,000 companies trust Rithum to grow their business across hundreds of channels, representing over $50 billion in annual GMV.

Global

  • Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
  • Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
  • Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.

Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.

EMEA

  • Lead the Application Security program across all products, embedding security throughout the SDLC.
  • Integrate AppSec findings into centralized vulnerability workflows, correlating them with asset and exploit intelligence.
  • Automate security testing pipelines and mentor engineers on secure coding and threat modeling.

ServiceNow is the AI control tower for business reinvention, helping 85% of the Fortune 500 work smarter with its AI platform. The company is building an AI-native culture where technology and talent are unstoppable together.

$139,200–$189,000/yr
North America Unlimited PTO

  • Own risk identification, analysis, and prioritization across third-party risk and security risk assessments using established frameworks.
  • Translate technical vulnerabilities and risk findings into clear, quantified risk statements for non-security stakeholders and leadership.
  • Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal.

GitLab is an intelligent orchestration platform for DevSecOps, helping organizations increase developer productivity and improve security. With over 50 million users, GitLab is trusted by more than 50% of the Fortune 100 and fosters a high-performance culture driven by values and continuous knowledge exchange.

Global 4w PTO

  • Perform weekly code reviews to catch security vulnerabilities before they ship.
  • Coordinate external security audits and penetration tests, and track remediation.
  • Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.

EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.

$150,000–$230,000/yr
US Canada

  • Contribute production-quality code to the application (Node.js and Python), shipping security fixes end-to-end.
  • Build AI-powered automation and manage a bug bounty program, evaluating and reproducing submissions.
  • Define secure-by-design patterns and drive security standards across the architecture, including AI-integrated features.

Fast-growing B2B SaaS company serving the life sciences and pharma space. A small, high-impact security team with an engineering-first mindset, building AI-native features.

North America Unlimited PTO

  • Lead the design and implementation of secure enterprise solutions for Professional Services clients across AMER.
  • Assess complex security architectures and guide migrations to GitLab security capabilities, including CI/CD and compliance frameworks.
  • Provide technical leadership throughout the engagement lifecycle, from pre-sales scoping to delivery and enablement.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security risk. With more than 50 million registered users and 50% of the Fortune 100 as customers, GitLab fosters a high-performance, all-remote culture driven by values and continuous learning.

$175,000–$200,000/yr
US Canada Unlimited PTO

  • Partner with engineering teams on architecture reviews, threat modeling, and secure design to translate risks into practical recommendations.
  • Improve security tooling, strengthen SDLC and CI/CD controls, and serve as a GCP security subject matter expert.
  • Drive vulnerability management, coordinate penetration testing, and enable engineers through documentation and mentorship.

Doppel builds an AI-native platform for social engineering defense, protecting executives, employees, customers, and brands from phishing, impersonation, and fraud across digital channels. Backed by Andreessen Horowitz and Bessemer Venture Partners, it is a rapidly growing Series C startup with a team focused on cybersecurity expertise and startup velocity.

$160,000–$180,000/yr
US Unlimited PTO

  • Own and mature Cleo's SSDLC, including threat modeling, design reviews, and automated security scanning.
  • Run risk-based triage for product vulnerabilities, penetration testing, and the CVE lifecycle.
  • Own product security posture, customer-facing advisories, and secure-by-default configurations.

Cleo provides secure data integration and managed file transfer solutions for enterprise businesses. With over 4,000 clients and a 99% retention rate, the company promotes a supportive, life-work balanced culture.

$150,000–$155,000/yr
US

  • Conduct application and cloud security assessments to identify risks and vulnerabilities.
  • Collaborate with development teams to integrate security best practices into the SDLC.
  • Support vulnerability management, incident response, and security awareness education.

Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.

$235,000–$305,000/yr
US 4w PTO 12w maternity 12w paternity

  • Lead threat modeling and security architecture for AI-enabled systems, including LLM applications and cloud-native platforms.
  • Define and implement secure engineering patterns and guardrails across AWS infrastructure, CI/CD pipelines, and third-party integrations.
  • Partner with engineering and security teams to embed security throughout the AI product lifecycle and drive cross-functional security initiatives.

Quanata is an insurance technology innovation company that engineers advanced risk prediction and prevention solutions for State Farm and HiRoad. We are a wholly owned subsidiary of State Farm with a remote-first culture that values inclusion and positive team dynamics.

$204,000–$290,000/yr
US Unlimited PTO

  • Lead Affirm's enterprise AI security review process, evaluating architecture, data flows, and design of AI tools and agentic systems.
  • Threat model AI/LLM systems for risks like prompt injection, insecure output handling, and data poisoning, and drive remediation.
  • Build security guardrails, tooling, and policy-as-code to automate AI security and support cross-functional initiatives.

Affirm is a financial technology company that offers clear, predictable point-of-sale installment loans with no hidden fees. The company is remote-first and values transparency, care, and flexibility, with a focus on building a diverse and inclusive team.

Global

  • Work with engineering teams to run security assessments and threat models for cloud-native and SaaS products.
  • Review cloud application architectures, build automation for security controls, and participate in incident response.
  • Communicate security risks to technical and non-technical audiences and champion improvements to security processes.

Atlassian provides collaboration software solutions designed to help teams work better together. The company has a global, inclusive culture where the unique contributions of all employees create success.

Global 6w PTO 26w maternity 26w paternity

  • Lead security reviews of architecture, code, and security-sensitive changes.
  • Secure AI-powered products against prompt injection, unsafe tool use, and tenant isolation risks.
  • Threat model new capabilities and build scalable guardrails that reduce recurring risks.

Cohere is a security-first enterprise AI company building foundation models and products for business. It is a global team of researchers, engineers, and designers headquartered in Toronto with offices worldwide.