Source Job

$82,000–$118,000/yr
US

  • Strengthen application security across modern software environments, including AI-enabled applications and services.
  • Embed security throughout the development lifecycle through code reviews, automated testing, and secure design practices.
  • Partner with engineering, product, DevOps, compliance, and incident response teams to identify and reduce risk.

Application Security Code Review CI/CD

20 jobs similar to Application Security Engineer

Jobs ranked by similarity.

$84,000–$132,300/yr
US

  • Assist with source code review and secure coding improvements.
  • Use SAST, DAST, and SCA tools to identify and validate vulnerabilities.
  • Collaborate with teams to integrate security into CI/CD and SDLC processes.

This company is a technology-driven healthcare organization integrating security into software development. It fosters a collaborative remote culture and supports professional growth in cybersecurity.

$111,000–$144,400/yr
US

  • Plan and execute application security testing across the software development lifecycle to identify vulnerabilities.
  • Communicate findings and risks to stakeholders and collaborate with teams to drive secure design practices.
  • Lead AI security initiatives including threat modeling and auditing third-party models and APIs.

Clear Capital is a national real estate analytics and valuation technology company that builds confidence in real estate decisions. Established in 2001, the company values integrity, empathy, and excellence in its team.

$130,000–$190,000/yr
US

  • Own and manage the application vulnerability remediation program, prioritizing findings and guiding developers.
  • Partner with engineering teams to validate fixes and implement long-term security improvements.
  • Define and maintain secure SDLC processes, including security reviews and threat modeling.

The company develops internet-facing financial software, APIs, and cloud-based solutions. It operates with a remote-first culture and emphasizes security and compliance.

$130,100–$187,000/yr
US

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.

Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.

$138,677–$182,296/yr
US

  • Integrate security into the SDLC through automation, testing, and continuous improvement.
  • Identify, investigate, and remediate application and infrastructure vulnerabilities.
  • Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.

Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.

EMEA

  • Drive application security initiatives across the SDLC, partnering with engineering teams to promote secure coding and security-by-design.
  • Integrate security testing tools into CI/CD pipelines and automate security processes using modern AppSec and DevSecOps tools.
  • Perform vulnerability analysis, source code review, and support threat modeling and secure design reviews.

Devoteam Cyber Trust is the cybersecurity arm of the Devoteam Group, offering end-to-end cyber resilience and managed security services. With 800+ experts across EMEA, they are ISO 27001 certified and serve clients in over 20 countries.

US

  • Hunt for and close security vulnerabilities across Counterpart Assistant using custom tooling and AI-driven frameworks.
  • Harden systems, services, and endpoints while establishing strong security monitoring and safeguarding PHI.
  • Raise the security bar by reviewing critical pull requests, running training, and mentoring engineers on secure coding practices.

Counterpart Health, a subsidiary of Clover Health, builds an AI-enabled primary care tool called Counterpart Assistant that helps physicians diagnose and manage chronic conditions earlier. The company employs a remote-first culture with a diverse and inclusive team focused on transforming healthcare at scale.

$160,000–$195,000/yr

  • Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
  • Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
  • Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.

Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.

$120,000–$140,000/yr
US Unlimited PTO 20w maternity 12w paternity

  • Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
  • Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
  • Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.

GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.

$120,000–$145,000/yr
US

  • Design, build, and scale application security capabilities to support secure software development across the enterprise.
  • Develop security patterns and guardrails for AI-assisted development and agentic workflows.
  • Integrate security tools with developer platforms to improve vulnerability management and automate remediation.

NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.

US Unlimited PTO

  • Perform application security testing and vulnerability assessments on web applications, APIs, and CI/CD pipelines.
  • Support DevSecOps tool integration and automation, including security scanning and policy enforcement.
  • Develop proof-of-concept secure reference implementations and utility applications to demonstrate best practices.

Ardent supports the federal government's most critical national security and defense priorities. They offer competitive pay, comprehensive benefits, and a culture that values dedication and flexibility.

$150,000–$196,000/yr
US

  • Strengthen application security across a modern enterprise software platform used worldwide.
  • Embed secure development practices throughout the software development lifecycle.
  • Identify and mitigate vulnerabilities before they reach production.

Our partner is a technology organization providing a modern enterprise software platform used by organizations worldwide. The company fosters a collaborative culture focused on innovation, customer success, and continuous learning, with a remote-first environment.

Nigeria

  • Conduct thorough security assessments and penetration testing to identify vulnerabilities in web and mobile applications.
  • Collaborate with development teams to integrate security best practices and design secure application architectures.
  • Lead incident response and ensure compliance with security standards and regulations.

Moniepoint Inc. is an all-in-one African financial platform serving 20 million businesses with payments, banking, and tools. As Nigeria's largest merchant acquirer, it processes over $250 billion annually and fosters a culture of innovation and teamwork.

Global

  • Lead Application Security initiatives across HighLevel's products and engineering teams.
  • Conduct architecture reviews, threat modeling, and security assessments for web, mobile, and API applications.
  • Drive DevSecOps practices by automating security in CI/CD pipelines and managing security tooling.

HighLevel is an AI-powered, all-in-one white-label sales and marketing platform that empowers agencies and businesses to grow their digital presence. With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment with a culture rooted in creativity, collaboration, and impact.

Europe

  • Act as an Application Security SME, partnering with Engineering and Product teams to embed security throughout the SDLC.
  • Lead application security reviews, threat modeling, code reviews, and penetration testing to identify and mitigate risks.
  • Design and automate security controls across CI/CD pipelines, including SAST, SCA, and other AppSec tooling.

Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America, backed by leading investors, and places millions of workers.

US Unlimited PTO

  • Own the Application Security product strategy and roadmap, from tooling to governance.
  • Drive delivery of security solutions with engineering and cross-functional teams.
  • Lead tool procurement, risk prioritization, and executive communication.

Zeta Global is an AI-powered marketing cloud that helps marketers acquire and retain customers using advanced AI and consumer data. Founded in 2007, the company is headquartered in New York City with offices worldwide, employing a diverse team focused on innovation and inclusion.

US

  • Partner with engineering and product teams to identify application security risks and provide practical mitigation recommendations.
  • Analyze code, configurations, and logs to detect vulnerabilities and improve security workflows.
  • Communicate security risks clearly to technical and non-technical stakeholders and drive scalable solutions.

US

  • Conduct and support static and dynamic application-security testing using tools like Fortify, X-Ray, and OWASP ZAP.
  • Work with software engineers to understand root causes, resolve vulnerabilities, and integrate security testing into CI/CD workflows.
  • Strengthen software supply-chain security and apply secure development practices in environments using GitLab, OpenShift, and Kubernetes.

Rackner builds secure software supporting high-impact Department of Defense planning and decision-support missions. The company has delivered more than $30 million in recent federal awards and fosters a collaborative, mission-focused culture.

$88,800–$125,800/yr
Canada 3w PTO 12w maternity 12w paternity

  • Proactively identify and drive security improvements across the product and platform.
  • Partner with engineering teams to threat model new features and review designs early in development.
  • Build and improve security tooling, libraries, and workflows to make secure development the default path.

Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.

$135,000–$178,000/yr
US

  • Define and lead the enterprise security strategy for AI-powered systems and Azure cloud environments.
  • Establish security controls and threat modeling for agentic AI workflows and cloud workloads.
  • Mentor engineering teams on secure AI adoption and cloud security best practices.

Banner Bank is a community bank with over 135 years of history, serving Washington, Oregon, Idaho, and California with $16 billion in assets and 135 branches. They prioritize core values like teamwork and integrity, and have been Great Place to Work Certified, emphasizing employee volunteerism and community support.