Source Job

$182,800–$215,000/yr
US

  • Own the configuration, tuning, and management of our SIEM solution to diagnose unusual threats.
  • Perform architecture reviews, code reviews, and penetration testing on web and mobile apps.
  • Build and maintain vulnerability management CI/CD pipeline and collaborate with engineering teams.

Ruby Java Python Docker Kubernetes

20 jobs similar to Staff Application Security Engineer

Jobs ranked by similarity.

$182,800–$215,000/yr
US

  • Own and improve the organization's SIEM, including threat detection, alert tuning, and incident response.
  • Conduct security architecture reviews, code reviews, and infrastructure assessments to identify and remediate risks.
  • Build scalable security processes and integrate security practices into development workflows across cloud and container environments.

This company is a fast-moving technology organization focused on building secure and scalable software systems. It fosters a high-ownership, remote-first culture where experienced professionals collaborate with high-caliber engineering teams.

$175,000–$200,000/yr
US Canada Unlimited PTO

  • Partner with engineering teams on architecture reviews, threat modeling, and secure design to translate risks into practical recommendations.
  • Improve security tooling, strengthen SDLC and CI/CD controls, and serve as a GCP security subject matter expert.
  • Drive vulnerability management, coordinate penetration testing, and enable engineers through documentation and mentorship.

Doppel builds an AI-native platform for social engineering defense, protecting executives, employees, customers, and brands from phishing, impersonation, and fraud across digital channels. Backed by Andreessen Horowitz and Bessemer Venture Partners, it is a rapidly growing Series C startup with a team focused on cybersecurity expertise and startup velocity.

$98,000–$116,000/yr
US

  • Integrate AppSec tools into CI/CD pipelines and manage application security vulnerabilities.
  • Monitor and respond to security incidents, tuning WAF policies and security rulesets.
  • Collaborate with IT partners to perform security reviews and remediate findings across cloud platforms.

EMCOR Group, Inc. is a Fortune 500 leader in mechanical and electrical construction, industrial and energy infrastructure, and building services. As a large company with a diverse portfolio, it emphasizes a culture of security and collaboration.

US

  • Get hands-on with our Go codebase, AWS and Kubernetes environment, SIEM, and security services, contributing security feedback to design docs and shipping your first fix or detection.
  • Own a security domain end to end, such as cloud hardening or detection engineering, and ship reusable Go security middleware adopted by service teams.
  • Drive multi-quarter initiatives like default-deny networking, expand Kubernetes security, and automate compliance evidence for audits.

Bastion provides regulated infrastructure for businesses to hold, move, and issue stablecoins, combining custodial wallets, payment orchestration, and issuance. As a 40-person startup, we operate through our own regulated entities with built-in compliance and risk controls.

$175,000–$220,000/yr

  • Own identity and endpoint security, including access management, device standards, and risk assessments.
  • Administer SSO, enforce MFA, manage MDM/EDR, and automate security workflows.
  • Act as a first responder for incidents, conduct vendor reviews, and build scalable security processes.

Squads is a financial technology company building products and APIs for the stablecoin economy. More than 450 teams use Squads Multisig to secure over $10 billion in value.

Global

  • Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
  • Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
  • Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.

Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.

EMEA

  • Lead the Application Security program across all products, embedding security throughout the SDLC.
  • Integrate AppSec findings into centralized vulnerability workflows, correlating them with asset and exploit intelligence.
  • Automate security testing pipelines and mentor engineers on secure coding and threat modeling.

ServiceNow is the AI control tower for business reinvention, helping 85% of the Fortune 500 work smarter with its AI platform. The company is building an AI-native culture where technology and talent are unstoppable together.

Global

  • Monitor security systems, logs, and alerts to detect and respond to threats.
  • Run vulnerability scans and coordinate remediation with IT and engineering.
  • Maintain compliance with SOC 2 and support security awareness programs.

Power Digital is an AI-native growth firm combining talent and proprietary technology to help brands drive measurable business outcomes. With a people-first culture, the company values diversity and collaboration, using its AI operating system Omega to amplify capacity for strategy, creativity, and analysis.

Global

  • Work with engineering teams to run security assessments and threat models for cloud-native and SaaS products.
  • Review cloud application architectures, build automation for security controls, and participate in incident response.
  • Communicate security risks to technical and non-technical audiences and champion improvements to security processes.

Atlassian provides collaboration software solutions designed to help teams work better together. The company has a global, inclusive culture where the unique contributions of all employees create success.

$120,000–$150,000/yr
US

  • Fix vulnerabilities across the stack by writing pull requests in application repositories and Terraform.
  • Build and tune SIEM detections, mapping coverage to MITRE ATT&CK and reducing false positives.
  • Lead incident response, harden AWS estate, and automate security workflows with code.

Cloudbeds is a hospitality management platform powering hotels across 150 countries, processing billions in bookings annually. The company is a remote-first team of 650+ across 40+ countries, recognized for innovation and an inclusive culture.

Europe

  • Architect and oversee advanced security monitoring and threat detection frameworks across diverse systems and log sources.
  • Lead the integration of security into the software development lifecycle, including Security-as-Code and automated SAST, DAST, and SCA capabilities within CI/CD pipelines.
  • Own the end-to-end vulnerability management strategy across infrastructure and applications, prioritizing remediation according to business risk.

The partner company operates a large-scale digital platform and a globally distributed technology ecosystem connected to gaming and esports communities. They maintain a flexible, distributed, and inclusive work environment focused on equal opportunity and technical ownership.

$157,675–$238,500/yr
US

  • Build, deploy, and continuously improve MITRE ATT&CK–aligned detections across cloud, endpoint, identity, email, and application telemetry with clear false-positive thresholds.
  • Own the full detection lifecycle from hypothesis and data validation through deployment, tuning, and retirement.
  • Advance the detection-as-code platform with version control, peer review, automated testing, CI/CD, and improved pipeline reliability and observability.

Samsara is the pioneer of the Connected Operations™ Cloud, helping organizations that depend on physical operations to harness IoT data for actionable insights. They are a recently public company with a high-caliber team, embracing a flexible working model that supports remote and hybrid work.

India

  • Own security architecture across Azure and AWS, covering tenant design, network segmentation, and workload isolation.
  • Raise the engineering bar with hardened infrastructure-as-code modules, secure defaults, and policy-as-code signals at commit time.
  • Own vulnerability and exposure management end to end, delivering findings as pull requests, not tickets.

One Identity enables organizations to secure, manage, monitor, protect, and analyze information and infrastructure to drive innovation. With a globally distributed team, we build enterprise products at scale and foster a collaborative, improvement-driven culture.

$90,000–$100,000/yr
US

  • Monitor, triage, and respond to security alerts and incidents across the security stack.
  • Engineer, implement, and maintain information security technologies such as SIEM, detection rules, and automation.
  • Collaborate with teams to promote information security culture and advise on cyber risk across the organization.

VEIC is a sustainable energy organization working toward a healthy planet, thriving people, and energy justice. The company values an inclusive culture and supports flexible work arrangements, welcoming candidates of all backgrounds.

US

  • Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
  • Build automation, policy-as-code, and security tooling that enables development teams to 'shift left' and integrate end-to-end security into their workflows.
  • Drive vulnerability management and remediation efforts, prioritizing issues, implementing mitigations, and designing strategic preventative controls in software supply chains from development through production.

Wiz is redefining security for the AI era, enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. As one of the fastest-growing startups ever, we are trusted by over 65% of the Fortune 100 and scan over 230 billion files daily, with a culture that values world-class talent and is now powered by Google.

US Unlimited PTO

  • Design, harden, and defend containerized application infrastructure across edge and cloud environments.
  • Lead threat modeling, vulnerability management, and security reviews to support mission-critical systems.
  • Own provisioning, secrets management, and security controls for systems operating in denied or disconnected environments.

CX2 is a next-generation defense technology company building AI-enabled hardware and software platforms to detect, disrupt, and defend the electromagnetic spectrum. Backed by leading defense investors and led by founders from Meta, SpaceX, Epirus, and the DoD, the company values high responsibility and autonomy.

Colombia

  • Safeguard customer digital assets, sensitive data, and critical systems against cyber threats as part of the MXDR team.
  • Leverage expertise in vulnerability identification, robust security implementation, and incident response to enhance security posture.
  • Collaborate with cross-functional teams to assess risks, formulate security strategies, and ensure adherence to industry standards.

Check Point Software Technologies is a leading vendor of cybersecurity solutions, protecting against sophisticated threats and attacks. The company has been honored by Time Magazine as one of the World’s Best Companies for 2024 and recognized as one of the World’s Top Female-Friendly Places to Work.

Europe

  • Design and strengthen security features across Pigment's product and infrastructure, threat modeling new services and making architectural decisions.
  • Lead security investigations and incident response, manage vulnerability detection and remediation, and build detection engineering capabilities.
  • Drive the security roadmap end-to-end, working hands-on with code and infrastructure to balance risk and business benefit.

Pigment is an AI-powered business planning and performance management platform. Founded in 2019, the company has over 600 employees and has raised nearly $400M, recognized as a Gartner Visionary.

$120,000–$150,000/yr
US

  • Protect cloud infrastructure, applications, and customer data across a modern technology environment.
  • Identify and remediate vulnerabilities directly in application repositories and infrastructure code.
  • Build and tune SIEM detections, strengthen AWS security controls, and lead incident response.

Cloudbeds is a hospitality technology company providing cloud-based management solutions for lodging businesses. It operates as a remote-first organization with a globally distributed team across 40+ countries and a small, senior security team.

EU

  • Build and maintain secure CI/CD pipelines, embedding security testing and controls into software development and deployment.
  • Strengthen application and cloud-native security across Kubernetes and containerized environments, identifying risks and implementing practical controls.
  • Manage CVE and vulnerability lifecycles, supporting prioritization and working with application teams on mitigation and remediation.

Redcare Pharmacy is Europe's leading online pharmacy, driven by dedicated teams and cutting-edge innovation. The company fosters an enjoyable and collaborative working environment where every employee feels comfortable and motivated to contribute to the vision: 'Until every human has their health.'