Source Job

US

  • Conduct and support static and dynamic application-security testing using tools like Fortify, X-Ray, and OWASP ZAP.
  • Work with software engineers to understand root causes, resolve vulnerabilities, and integrate security testing into CI/CD workflows.
  • Strengthen software supply-chain security and apply secure development practices in environments using GitLab, OpenShift, and Kubernetes.

SAST GitLab

20 jobs similar to Application Security Engineer — Secure Mission Systems

Jobs ranked by similarity.

$84,000–$132,300/yr
US

  • Assist with source code review and secure coding improvements.
  • Use SAST, DAST, and SCA tools to identify and validate vulnerabilities.
  • Collaborate with teams to integrate security into CI/CD and SDLC processes.

This company is a technology-driven healthcare organization integrating security into software development. It fosters a collaborative remote culture and supports professional growth in cybersecurity.

Europe

  • Define security requirements and design application architectures following a secure-by-default approach.
  • Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
  • Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.

Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.

US

  • Lead implementation and optimization of AppSec tools such as SAST, DAST, and SCA across client environments.
  • Conduct manual application and API security assessments, identifying vulnerabilities and recommending remediation strategies.
  • Advise clients on secure SDLC practices and integrate security tools into CI/CD pipelines.

The company is a cybersecurity consulting firm that helps organizations design and operationalize application security programs. It operates with a remote-first culture and a collaborative, client-facing team.

UK

  • Perform hands-on security testing and code review across web applications and APIs.
  • Conduct threat modeling and embed secure development practices into the SDLC.
  • Build and tune security tooling, including SAST, DAST, and CI/CD automation.

Prolific builds human data infrastructure for AI development, connecting researchers with a global participant pool to collect high-quality, ethically sourced behavioral data. They are a mission-driven company trusted by world-leading research institutions and AI labs, with a remote-first culture.

US 18w maternity 16w paternity

  • Contribute to secure-by-design practices and advance the S-SDLC program.
  • Mentor engineers on secure coding and career growth.
  • Evaluate and recommend AI-assisted security tooling.

Spring Health is a global mental health company eliminating every barrier to mental health. They reach more than 170 million people worldwide and are an AI-native company focused on expanding the reach, quality, and humanity of care.

$120,000–$154,440/yr
US 12w maternity 12w paternity

  • Architect, design, and implement end-to-end security solutions including firewalls, intrusion detection, and cloud security controls.
  • Collaborate with DevOps to integrate security into CI/CD pipelines and automate secure deployments.
  • Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.

Figure is transforming capital markets through blockchain, powering real products used by hundreds of thousands of consumers and institutions. With over 170 partners and $22 billion in home equity loans originated, Figure is the largest non-bank provider of home equity financing in the U.S., recognized as one of Forbes' Most Innovative Fintech Startups in 2025.

US 4w PTO

  • Lead application security reviews, threat modeling, and secure code review for new features and significant product changes.
  • Operate and improve SAST, DAST, and SCA tooling, triage findings, and partner with engineering teams to harden the codebase.
  • Plan and execute internal penetration tests against web applications, APIs, and mobile clients, and own the vulnerability management lifecycle.

ButterflyMX empowers people to automate property access, operations, and security from a single platform, serving over 20,000 properties worldwide. As a distributed, primarily remote workforce, they seek intelligent, passionate, and collaborative individuals driven by a shared commitment to excellence and innovation.

$152,000–$175,000/yr
US Unlimited PTO

  • Lead threat modeling, architecture reviews, and code reviews for web applications, APIs, and microservices.
  • Actively develop and commit code to fix security flaws in Python, Go, or JavaScript/TypeScript codebases.
  • Implement and manage security testing tools within CI/CD pipelines to catch vulnerabilities early in the SDLC.

RunPod is the AI Developer Cloud, providing a platform for developers to experiment, train, fine-tune, deploy, and scale AI. We are a small, remote-first team that has processed over 20 billion inference requests and closed a $100M Series A in June 2026.

$130,000–$190,000/yr
US

  • Own and manage the application vulnerability remediation program, prioritizing findings and guiding developers.
  • Partner with engineering teams to validate fixes and implement long-term security improvements.
  • Define and maintain secure SDLC processes, including security reviews and threat modeling.

The company develops internet-facing financial software, APIs, and cloud-based solutions. It operates with a remote-first culture and emphasizes security and compliance.

India

  • Partner with engineering, product, and DevOps teams to integrate security practices throughout the SDLC, focusing on cloud-native environments and automated pipelines.
  • Design, implement, and maintain security tooling and gates within CI/CD pipelines covering SAST, DAST, SCA, secrets detection, and container scanning.
  • Lead threat modeling, conduct application security assessments including code review and manual penetration testing, and triage bug bounty reports.

Hyland is the pioneer of the Content Innovation Cloud, delivering ubiquitous enterprise intelligence to organizations. With a team of nearly 4,000 employees, the company fosters an employee-centric culture focused on community impact and innovation.

US 5w PTO

  • Own key security domains such as vulnerability management, application security, API security, and supply chain security.
  • Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows.
  • Develop and improve security tooling and automation to reduce manual effort and leverage AI for triage and detection.

NinjaTrader is an industry-leading trading platform and futures broker that empowers traders with award-winning software and brokerage services. Since 2003, the company has grown to over 2 million users and is the number one rated futures brokerage worldwide, fostering a dynamic culture focused on social connection, professional development, and employee recognition.

$180,000–$198,000/yr
US Unlimited PTO 12w maternity 12w paternity

  • Architect and harden security infrastructure, owning PCI and SOC2 programs end-to-end.
  • Integrate security scanning (SAST, DAST, SCA) into CI/CD pipelines and manage identity and access platforms.
  • Run vulnerability scanning, pen testing engagements, and security awareness training programs.

Campminder builds software for summer camps, helping them run great summers by keeping data safe. With over 20 years of experience and 100+ employees, they are stable, profitable, and have been listed on Outside Magazine's 50 Best Places to Work for 8 consecutive years due to their values-led culture and work-life balance.

Global Unlimited PTO

  • Conduct application security reviews including threat modeling, code review, and risk assessment for new features.
  • Perform and improve SAST/DAST operations, triage, validation, and remediation tracking in CI/CD pipelines.
  • Apply and improve AI security review processes for LLM-integrated features and agentic attack surfaces.

Monarch is a powerful, all-in-one personal finance platform designed to simplify money management. They are a fully remote team of do-ers led by experienced entrepreneurs, passionate about building a product people love.

Brazil

  • Identify and remediate vulnerabilities across the product ecosystem using code reviews and automation.
  • Integrate security tools and practices into CI/CD pipelines to ensure secure development.
  • Collaborate with engineering teams to apply threat modeling and secure-by-design principles.

They are a partner company specializing in digital product security. The team size is not specified, but the culture emphasizes trust, collaboration, and remote work.

$147,000–$175,000/yr
US Unlimited PTO

  • Become an expert on the platform and its integration into customer CI/CD pipelines, developer workflows, and AppSec programs.
  • Run technical discovery, diagnose customer issues, and advise on solution design throughout the sales cycle.
  • Own Proof-of-Value engagements end-to-end, from defining success criteria to configuring environments and delivering technical wins.

They build a leading application security platform that helps companies like Snowflake and Dropbox catch and fix code vulnerabilities without slowing down development. The company has grown to roughly 175 employees since 2017 and raised $100M in Series D funding, with a culture combining deep engineering credibility and developer-friendly products.

Europe US Unlimited PTO

  • Triage, validate, and remediate security vulnerabilities across products, infrastructure, and internal systems.
  • Develop, maintain, and contribute to internal and open-source security tooling, writing production-grade code.
  • Improve secure development practices through code reviews, threat modeling, and security design reviews.

Tiger Data provides the fastest PostgreSQL platform for transactional, analytical, and agentic workloads. With over 2,000 customers and 3 million active databases, it is a remote-first team backed by $180 million in funding.

India

  • Remediate platform-level security vulnerabilities using tools like Snyk and SAST/DAST.
  • Manage identity and access management and support security audits.
  • Implement security controls in CI/CD pipelines and manage Adobe Cloud Manager.

Solvative is a technology company that provides digital solutions and software development services. They have a small to medium-sized team with an informal, fun work culture that includes regular team activities and investment in employee growth.

$113,000–$191,000/yr
US Unlimited PTO

  • Engage with customers via Zoom and email as a technical consultant, providing product and best-practice guidance during the post-sales journey.
  • Deliver customer-specific enablement through webinars, hands-on labs, office hours, and on-demand engagements in a pooled support model.
  • Build and maintain specialty competency in DevSecOps tools and GitLab use cases through training, certification, and creating reusable examples.

GitLab provides an intelligent DevSecOps platform that helps organizations increase developer productivity, improve operational efficiency, and accelerate digital transformation. With over 50 million registered users and trust from more than 50% of the Fortune 100, GitLab fosters a high-performance culture driven by values, AI adoption, and continuous knowledge exchange.

$130,000–$170,000/yr
US

  • Partner with product and engineering teams to identify risks early and build security into new features.
  • Lead threat modeling and secure design reviews for new products and architecture changes.
  • Perform security-focused code reviews and maintain application security tooling integrated into CI/CD.

Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up. It is a small startup with a culture that prioritizes security and trust, and security is core to the product.

$175,000–$200,000/yr
United States Dominican Republic Canada

  • Lead application and product security across Forward-built, third-party, and AI-built software.
  • Evolve the pentest program to aggressively test and remediate vulnerabilities in existing and new software.
  • Build and integrate AI solutions within the appsec function.

Forward Financing is a financial technology company that unlocks capital for small businesses across America. Recognized as a Best Place to Work, it invests in employees, technology, and customer experience with a long-term focus.