Source Job

US Unlimited PTO

  • Build and tune the application security scanning program (SAST, DAST, SCA, container and IaC) to surface real risk.
  • Triage scan, penetration test, and bug bounty findings, prioritizing by risk and tracking remediation to closure.
  • Partner with engineering on threat modeling, secure-coding standards, and hands-on fixes.

Application Security OWASP Top 10 AWS

20 jobs similar to Senior Application Security Engineer

Jobs ranked by similarity.

$150,000–$155,000/yr
US

  • Conduct application and cloud security assessments to identify risks and vulnerabilities.
  • Collaborate with development teams to integrate security best practices into the SDLC.
  • Support vulnerability management, incident response, and security awareness education.

Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.

$160,000–$180,000/yr
US Unlimited PTO

  • Own and mature Cleo's SSDLC, including threat modeling, design reviews, and automated security scanning.
  • Run risk-based triage for product vulnerabilities, penetration testing, and the CVE lifecycle.
  • Own product security posture, customer-facing advisories, and secure-by-default configurations.

Cleo provides secure data integration and managed file transfer solutions for enterprise businesses. With over 4,000 clients and a 99% retention rate, the company promotes a supportive, life-work balanced culture.

$104,300–$193,700/yr
US

  • Collaborate with DevOps and engineering teams to embed security throughout the software development lifecycle.
  • Implement automated security testing, including SAST, DAST, SCA, and container security, and strengthen cloud-native security controls.
  • Support compliance with PCI-DSS, GDPR, CCPA, and SOC 2, and evaluate secure adoption of AI-assisted coding tools.

Our partner is a technology company in the travel and hospitality industry. They have a collaborative remote culture and value employee development and diversity.

$150,000–$160,000/yr
US Unlimited PTO

  • Implement and maintain AWS security configurations across development, staging, and production environments.
  • Operate SAST, DAST, and SCA tools integrated into CI/CD pipelines to remediate vulnerabilities.
  • Support compliance efforts such as SOC 2 Type II and ISO 27001 audits and improve security processes.

Pacvue is a leading software suite for eCommerce advertising, sales, and intelligence, helping brands grow on Amazon, Walmart, Instacart, and other marketplaces. The team is energetic, passionate, and focused on innovation, with a mission to help brands and sellers succeed.

US Unlimited PTO

  • Deliver Application Security services including assessments, threat modeling, and source code reviews for web, mobile, AI, and thick client applications.
  • Perform AI/LLM and agentic security assessments, including prompt injection, model bypass, and tool-calling exploitation, mapped to OWASP Top 10 for LLM and Agentic Applications.
  • Build and extend AI-driven tooling and automation harnesses to improve testing coverage, consistency, and efficiency.

GuidePoint Security provides trusted cybersecurity expertise, solutions, and services to help organizations make better decisions and minimize risk. With over 1,300 employees, it is a rapidly growing, profitable, privately-held value added reseller focused exclusively on information security.

$98,000–$116,000/yr
US

  • Integrate AppSec tools into CI/CD pipelines and manage application security vulnerabilities.
  • Monitor and respond to security incidents, tuning WAF policies and security rulesets.
  • Collaborate with IT partners to perform security reviews and remediate findings across cloud platforms.

EMCOR Group, Inc. is a Fortune 500 leader in mechanical and electrical construction, industrial and energy infrastructure, and building services. As a large company with a diverse portfolio, it emphasizes a culture of security and collaboration.

$120,000–$150,000/yr
US

  • Protect cloud infrastructure, applications, and customer data across a modern technology environment.
  • Identify and remediate vulnerabilities directly in application repositories and infrastructure code.
  • Build and tune SIEM detections, strengthen AWS security controls, and lead incident response.

Cloudbeds is a hospitality technology company providing cloud-based management solutions for lodging businesses. It operates as a remote-first organization with a globally distributed team across 40+ countries and a small, senior security team.

EMEA

  • Lead the Application Security program across all products, embedding security throughout the SDLC.
  • Integrate AppSec findings into centralized vulnerability workflows, correlating them with asset and exploit intelligence.
  • Automate security testing pipelines and mentor engineers on secure coding and threat modeling.

ServiceNow is the AI control tower for business reinvention, helping 85% of the Fortune 500 work smarter with its AI platform. The company is building an AI-native culture where technology and talent are unstoppable together.

US 4w PTO 16w maternity 16w paternity

  • Perform security design reviews and threat modeling for new products and features, including AI-enabled services.
  • Conduct manual penetration testing of web, API, mobile, and cloud-native applications, and validate third-party findings.
  • Drive adoption of secure coding practices and improve security automation in CI/CD pipelines.

Iru is an AI-powered security & IT platform that unifies identity and access, endpoint security, and compliance automation for fast-growing companies. Backed by top investors and valued at $850 million, it serves customers like Cursor and Vercel, and is recognized for employee engagement.

North America Unlimited PTO

  • Lead the design and implementation of secure enterprise solutions for Professional Services clients across AMER.
  • Assess complex security architectures and guide migrations to GitLab security capabilities, including CI/CD and compliance frameworks.
  • Provide technical leadership throughout the engagement lifecycle, from pre-sales scoping to delivery and enablement.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security risk. With more than 50 million registered users and 50% of the Fortune 100 as customers, GitLab fosters a high-performance, all-remote culture driven by values and continuous learning.

$150,000–$230,000/yr
US Canada

  • Contribute production-quality code to the application (Node.js and Python), shipping security fixes end-to-end.
  • Build AI-powered automation and manage a bug bounty program, evaluating and reproducing submissions.
  • Define secure-by-design patterns and drive security standards across the architecture, including AI-integrated features.

Fast-growing B2B SaaS company serving the life sciences and pharma space. A small, high-impact security team with an engineering-first mindset, building AI-native features.

$125,000–$135,000/yr
US

  • Conduct code and container vulnerability assessments using DoD scanning tools, DISA STIGs, and SRGs.
  • Apply SAST and DAST methodologies and integrate security controls into CI/CD pipelines.
  • Serve as GitLab security reviewer and coordinate remediation of security findings across teams.

This partner company supports cybersecurity and secure software delivery within U.S. Department of Defense and Navy environments. The organization offers a fully remote, mission-focused culture with opportunities to collaborate across engineering and program teams.

$116,019–$145,024/yr
US 4w PTO 4w maternity 4w paternity

  • Design, deploy, and manage cloud security solutions to protect AWS and Azure environments.
  • Perform security assessments, vulnerability remediation, and lead key security programs.
  • Automate security processes and integrate DevSec practices into the software development lifecycle.

Navitus is a pharmacy benefit manager (PBM) alternative that aims to make medications more affordable by removing cost from the drug supply chain. The company fosters a diverse, creative, and growth-oriented culture.

Europe

  • Own cloud and product security across AWS and GCP, setting baselines for IAM, networking, data protection, and workload configuration.
  • Partner with platform, SRE, and product teams to embed practical security controls into developer workflows and automate guardrails in delivery pipelines.
  • Perform security architecture reviews, threat modeling, and incident response, and drive systemic improvements with meaningful security metrics.

We create intelligent software development tools used by more than 15 million users and 300,000 companies, including 88 of the Fortune Global Top 100. Our mission is to make development teams more productive and AI adoptable at scale, and we foster an open and inclusive workplace.

US

  • Develop playbooks and address security-related tasks in AWS serverless environments.
  • Drive improvements in security posture, including application, endpoint, and access management.
  • Collaborate with product engineering teams to raise the bar for security in CI/CD, dependency management, and secure design reviews.

Stedi is building a new healthcare clearinghouse and RCM engine, accessible via API. With $142 million in funding and a lean, passionate team, they ship products weekly and prioritize automation and eliminating toil.

$120,000–$155,000/yr
US Unlimited PTO

  • Deploy and automate CI/CD pipelines and establish IaC using modern DevSecOps techniques including serverless and Zero Trust patterns.
  • Own the POAM process end to end, develop plans of action with target dates, track progress, and close findings proactively.
  • Conduct Security Impact Analyses (SIAs) to achieve and maintain ATO, and maintain a live dashboard for all security findings.

Oddball brings quality software to the federal space, aiming to improve the daily lives of millions. It is a small company that values learning, growth, and making a big impact.

Global

  • Work with engineering teams to run security assessments and threat models for cloud-native and SaaS products.
  • Review cloud application architectures, build automation for security controls, and participate in incident response.
  • Communicate security risks to technical and non-technical audiences and champion improvements to security processes.

Atlassian provides collaboration software solutions designed to help teams work better together. The company has a global, inclusive culture where the unique contributions of all employees create success.

$115,000–$140,000/yr
US

  • Perform systems administration, patching, vulnerability scanning, and remediation for AWS and GCP cloud workloads.
  • Configure and maintain security tools for endpoint protection, log collection, vulnerability scanning, and compliance monitoring.
  • Support 24x7 on-call rotation and collaborate with security analysts to deliver secure solutions for FedRAMP and FISMA customers.

Quantum Sky is a technology company that engineers solutions for cyber, networks, software, and quantum for mission-driven clients. They foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role.

Global 4w PTO

  • Perform weekly code reviews to catch security vulnerabilities before they ship.
  • Coordinate external security audits and penetration tests, and track remediation.
  • Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.

EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.

US Unlimited PTO

  • Lead the technical vision for platform hardening across AWS and GCP, including tier-0 access and secrets services.
  • Own the hardening roadmap for critical cloud infrastructure and drive operational excellence with rigorous on-call practices.
  • Mentor a global team of engineers and partner cross-functionally to build secure-by-default controls.

DoorDash is a technology and logistics company building the most reliable delivery network for consumers, merchants, and dashers. The company is growing rapidly and fosters a culture of learning, customer obsession, and inclusive leadership.