Source Job

US

  • Hunt for and close security vulnerabilities across Counterpart Assistant using custom tooling and AI-driven frameworks.
  • Harden systems, services, and endpoints while establishing strong security monitoring and safeguarding PHI.
  • Raise the security bar by reviewing critical pull requests, running training, and mentoring engineers on secure coding practices.

Application Security Penetration Testing AI/ML

20 jobs similar to Senior Application Security Engineer

Jobs ranked by similarity.

US

  • Secure AI systems and use AI to scale security, conducting security reviews and threat modeling of AI-integrated product features.
  • Deliver end-to-end application security reviews for high-risk features, working directly with engineering teams to surface and close risk.
  • Advance CI/CD pipeline security by operating and evolving security scanning controls in GitLab pipelines.

Smartsheet empowers teams to manage work and scale solutions by uniting human teams with AI agents. They are a large company with over 20 years of experience, fostering a culture where ideas are heard and contributions have real impact.

Global 4w PTO

  • Take ownership of protecting product, users, and collaborators as a Security Engineer on a fast-growing AI dating platform.
  • Perform weekly code reviews, coordinate security audits, and maintain risk register to ensure safety of AI-generated content.
  • Monitor emerging AI security threats, manage IT access and device security, and run phishing simulations company-wide.

EverAI builds the world's largest AI companionship platform, redefining relationships for millions with a proprietary moderation system, EverGuard. With 50 million users in two years, the team of about 100 is enthusiastic, passionate, and hardworking, led by experienced entrepreneurs.

US 18w maternity 16w paternity

  • Contribute to secure-by-design practices and advance the S-SDLC program.
  • Mentor engineers on secure coding and career growth.
  • Evaluate and recommend AI-assisted security tooling.

Spring Health is a global mental health company eliminating every barrier to mental health. They reach more than 170 million people worldwide and are an AI-native company focused on expanding the reach, quality, and humanity of care.

$131,250–$150,000/yr
United States Canada Dominican Republic Unlimited PTO

  • Lead application and product security across Forward-built, third-party, and AI-built software.
  • Evolve the pentest program and proactively build AI solutions within the appsec function.
  • Own remediation workflows and partner with teams to build controls for external exposure.

Forward Financing is a financial technology company that unlocks capital for small businesses across America. They are a recognized Best Place to Work with a remote-first culture and team members across the US, Canada, and Dominican Republic.

$190,000–$319,000/yr
US

  • Design and ship security workflows combining deterministic analysis with LLM reasoning to find real vulnerabilities across languages and frameworks.
  • Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy for security-critical work.
  • Push on hard problems in automated triage and validation to close the gap between finding and actionable fix.

Semgrep is a code security platform that helps teams catch and fix vulnerabilities before they ship. They are a venture-backed startup with a transparent culture that values respect and honesty.

$111,000–$144,400/yr
US

  • Plan and execute application security testing across the software development lifecycle to identify vulnerabilities.
  • Communicate findings and risks to stakeholders and collaborate with teams to drive secure design practices.
  • Lead AI security initiatives including threat modeling and auditing third-party models and APIs.

Clear Capital is a national real estate analytics and valuation technology company that builds confidence in real estate decisions. Established in 2001, the company values integrity, empathy, and excellence in its team.

$88,800–$125,800/yr
Canada 3w PTO 12w maternity 12w paternity

  • Proactively identify and drive security improvements across the product and platform.
  • Partner with engineering teams to threat model new features and review designs early in development.
  • Build and improve security tooling, libraries, and workflows to make secure development the default path.

Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.

$175,000–$200,000/yr
United States Dominican Republic Canada

  • Lead application and product security across Forward-built, third-party, and AI-built software.
  • Evolve the pentest program to aggressively test and remediate vulnerabilities in existing and new software.
  • Build and integrate AI solutions within the appsec function.

Forward Financing is a financial technology company that unlocks capital for small businesses across America. Recognized as a Best Place to Work, it invests in employees, technology, and customer experience with a long-term focus.

UK

  • Perform hands-on security testing and code review across web applications and APIs.
  • Conduct threat modeling and embed secure development practices into the SDLC.
  • Build and tune security tooling, including SAST, DAST, and CI/CD automation.

Prolific builds human data infrastructure for AI development, connecting researchers with a global participant pool to collect high-quality, ethically sourced behavioral data. They are a mission-driven company trusted by world-leading research institutions and AI labs, with a remote-first culture.

$120,000–$154,440/yr
US 12w maternity 12w paternity

  • Architect, design, and implement end-to-end security solutions including firewalls, intrusion detection, and cloud security controls.
  • Collaborate with DevOps to integrate security into CI/CD pipelines and automate secure deployments.
  • Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.

Figure is transforming capital markets through blockchain, powering real products used by hundreds of thousands of consumers and institutions. With over 170 partners and $22 billion in home equity loans originated, Figure is the largest non-bank provider of home equity financing in the U.S., recognized as one of Forbes' Most Innovative Fintech Startups in 2025.

India

  • Partner with engineering, product, and DevOps teams to integrate security practices throughout the SDLC, focusing on cloud-native environments and automated pipelines.
  • Design, implement, and maintain security tooling and gates within CI/CD pipelines covering SAST, DAST, SCA, secrets detection, and container scanning.
  • Lead threat modeling, conduct application security assessments including code review and manual penetration testing, and triage bug bounty reports.

Hyland is the pioneer of the Content Innovation Cloud, delivering ubiquitous enterprise intelligence to organizations. With a team of nearly 4,000 employees, the company fosters an employee-centric culture focused on community impact and innovation.

US Unlimited PTO

  • Own the Application Security product strategy and roadmap, from tooling to governance.
  • Drive delivery of security solutions with engineering and cross-functional teams.
  • Lead tool procurement, risk prioritization, and executive communication.

Zeta Global is an AI-powered marketing cloud that helps marketers acquire and retain customers using advanced AI and consumer data. Founded in 2007, the company is headquartered in New York City with offices worldwide, employing a diverse team focused on innovation and inclusion.

India

  • Lead security initiatives across infrastructure, applications, cloud, and enterprise deployments to ensure a strong security posture.
  • Conduct penetration testing, vulnerability assessments, and security reviews to proactively identify and mitigate risks.
  • Collaborate with engineering, DevOps, and machine learning teams to embed security best practices into products and processes.

The company develops innovative AI-driven products for highly regulated environments. They operate with a startup culture, emphasizing collaboration, autonomy, and continuous improvement.

US

  • Deliver AI red teaming security assessments for enterprise clients, defining scopes and authoring detailed reports.
  • Build and improve frameworks and tooling to scale AI red teaming service delivery and automate repetitive tasks.
  • Develop novel red teaming methodologies for emerging AI modalities and stay ahead of the latest AI security threats.

Check Point protects over 100,000 organizations worldwide from cyber and AI-driven threats using a prevention-first approach. They are recognized by TIME, Newsweek, and Forbes for excellence and workplace culture.

Global

  • Lead Application Security initiatives across HighLevel's products and engineering teams.
  • Conduct architecture reviews, threat modeling, and security assessments for web, mobile, and API applications.
  • Drive DevSecOps practices by automating security in CI/CD pipelines and managing security tooling.

HighLevel is an AI-powered, all-in-one white-label sales and marketing platform that empowers agencies and businesses to grow their digital presence. With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment with a culture rooted in creativity, collaboration, and impact.

$153,000–$214,000/yr
US Canada

  • Lead end-to-end response to product security incidents, from discovery to disclosure.
  • Own and evolve 1Password's PSIRT function, including severity frameworks and playbooks.
  • Drive coordinated vulnerability disclosure and partner with external security researchers.

1Password is a cybersecurity company providing enterprise password management and Unified Access Management, trusted by over 180,000 businesses. With $400M ARR and a remote-first culture, it values collaboration, transparency, and innovation.

$130,000–$190,000/yr
US

  • Own and manage the application vulnerability remediation program, prioritizing findings and guiding developers.
  • Partner with engineering teams to validate fixes and implement long-term security improvements.
  • Define and maintain secure SDLC processes, including security reviews and threat modeling.

The company develops internet-facing financial software, APIs, and cloud-based solutions. It operates with a remote-first culture and emphasizes security and compliance.

$130,100–$187,000/yr
US

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.

Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.

North America Unlimited PTO

  • Identify and validate realistic attack paths across applications and infrastructure.
  • Develop safe proof-of-concept exploits to demonstrate security risks.
  • Partner with engineering teams to validate fixes and improve security posture.

A fast-growing technology environment focused on product security, protecting products used by millions of consumers. The culture emphasizes collaboration, proactive security practices, and leveraging AI to improve efficiency.

Europe

  • Define security requirements and design application architectures following a secure-by-default approach.
  • Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
  • Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.

Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.