Source Job

$160,000–$200,000/yr
US Unlimited PTO

  • Lead threat modeling and security architecture reviews for distributed, event-driven systems.
  • Integrate security code reviews, SAST/DAST, Software Composition Analysis (SCA), and container scanning into CI/CD and AI/ML pipelines.
  • Evangelize secure coding and AI security through training, brown bag sessions, and workshops.

OWASP React Node.js

20 jobs similar to Staff Application Security Engineer

Jobs ranked by similarity.

US Unlimited PTO

  • Lead security architecture and design reviews across applications, infrastructure, and integrations.
  • Conduct and coordinate penetration testing, threat modeling, and security reviews.
  • Design and implement security automation within CI/CD pipelines.

Assured modernizes insurance by providing software solutions to large insurers that help them win in a technology-driven world. Their products include self-service claim-filing software to backend fraud detection and are dynamic, collaborative, and rewarding.

US Unlimited PTO

  • In collaboration, develop and maintain the Security Architecture roadmap that preserves a strong security posture and aligns with corporate objectives.
  • Lead the development and implementation of automation for established and new security processes to increase operational efficiency and reduce manual intervention.
  • Develop the architectural framework for the secure deployment of AI, designing foundational layers for Model Security, Data Privacy, and Autonomous Agent orchestration.

Bestow is a leading vertical technology platform serving some of the largest and most innovative life insurers. Their platform unifies the fragmented, legacy value chain, enabling carriers to launch products in weeks instead of years.

Europe

  • Drive adoption of a Secure Software Development Lifecycle (SSDLC) across engineering teams.
  • Implement and integrate application security tooling into CI/CD pipelines, improving vulnerability detection and remediation.
  • Establish consistent threat modelling and secure design practices across new features and products.

Neko Health's mission is to deliver proactive healthcare for all, empowering members to take control of their health via technology and compassionate care. They have nearly 100 full-time engineers working across Berlin, Chamonix, Hamburg, Lisbon, Marseille, Vilnius, and Stockholm and they support a flexible workplace that prioritizes work-life balance.

$190,000–$210,000/yr
US Unlimited PTO

  • Drive the architectural vision for our platform and lead AI strategy within engineering.
  • Own greenfield architectural decisions and provide leadership across application, network, and infrastructure security.
  • Drive team SDLC processes and lead the recruiting process for engineers.

Zócalo Health is a tech-enabled, community-oriented primary care organization serving people who have historically been underserved by the healthcare system. Founded in 2021, Zócalo Health is backed by leading healthcare and mission-aligned investors and is scaling rapidly across states and populations.

$140,000–$150,000/yr
US Global

  • Partner with engineering teams to conduct threat modeling.
  • Build and maintain automated scanning, penetration testing frameworks, and monitoring tools within our AWS CI/CD pipelines.
  • Champion a "security-first" mindset and host workshops that empower developers to write secure code.

Panopto is a customer-centric learning technology company and the leader in visual and audio-based learning. They empower organizations to share knowledge effortlessly. Panopto has been adopted by more than 1,600 companies and universities worldwide with over 11 million end users.

Europe

  • Conduct security assessments and build a prioritized remediation roadmap across infrastructure and services
  • Harden AWS and Kubernetes environments: IAM, network policies, workload isolation, secrets management
  • Secure AI-specific attack surfaces: prompt injection defenses, PII handling in LLM pipelines, model interaction data leakage

Kiefer Tech leverages over 20 years of engineering heritage from the Green Energy sector to deliver cutting-edge AI, robotics, and enterprise solutions across Greece and the EU. They build sovereign AI infrastructure that keeps data within EU borders, respect privacy, and delivers tangible business impact.

6w PTO 26w maternity 26w paternity

  • Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues
  • Lead security operation functions – including vulnerability management, SAST, DAST, detection engineering, and incident response – in CI/CD and cloud-native production environments
  • Integrate security into our applications throughout the software development lifecycle

They are scaling intelligence to serve humanity by training and deploying frontier models for developers and enterprises, building AI systems to power magical experiences. Cohere is composed of researchers, engineers, and designers who are passionate about their craft, and believes that a diverse range of perspectives is a requirement for building great products.

US Canada

  • Define and execute our security strategy from the ground up.
  • Build security into AI agent systems as a first-class product feature.
  • Develop and potentially commercialize security products.

Human Agency partners with organizations of all sizes to explore, design, and implement AI strategies that are secure, scalable, and human-centered. They are scaling rapidly and have a growing pipeline of opportunities that demand exceptional talent across disciplines.

US Unlimited PTO

  • Focus on automation, integrating security within the CI/CD pipeline, and DevOps toolchain.
  • Strong working knowledge of security fundamentals including OWASP Top10.
  • Experience with public cloud infrastructure (AWS or Azure) and cloud security fundamentals.

GuidePoint Security provides cybersecurity expertise, solutions, and services to help organizations make better decisions and minimize risk. They have grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serve as a trusted advisor to more than 6,200 customers.

Global

  • Design and implement security controls across cloud infrastructure, applications, and data systems.
  • Identify, assess, and mitigate security risks through threat modeling, reviews, and testing.
  • Build and maintain monitoring, alerting, and incident response capabilities.

BlockchainUnmasked aims to streamline cryptocurrency forensic investigations through advanced automation combined with cutting-edge solutions. They work with investigative partners to dramatically accelerate investigation times and boost success rates in interdiction, recovery, and deterrence.

Global

  • Partner with engineering teams throughout the SDLC to embed security by design in our products.
  • Lead and evolve our AppSec tooling and workflows by implementing, tuning, and integrating SAST, DAST, SCA, and container/image scanning into CI/CD pipelines.
  • Drive vulnerability management for our applications and supply chain, including triaging and prioritizing issues, coordinating with teams on fix/mitigate/accept decisions.

Camunda is the leader in enterprise agentic automation, orchestrating complex business processes across agents, people, and systems. They were named a Visionary in the inaugural 2025 Gartner Magic Quadrant for Business Orchestration and Automation Technologies (BOAT).

$178,500–$203,500/yr
US

  • Own the strategy and execution for the Cloudflare ecosystem to secure the network edge.
  • Lead the design of security controls within Google Cloud Platform, specifically for Vertex AI, BigQuery, VPC Service Controls, IAM, and Security Command Center.
  • Embed security into CI/CD pipelines (Cloud Build, GitHub Actions) using Infrastructure as Code (Terraform).

Kareo and PatientPop joined forces to become Tebra, the digital backbone for practice well-being, helping independent practices bring modernized care to patients everywhere. Well over 100,000 providers trust them to elevate their patient experience and grow their practice.

Europe

  • Design, build, implement and train AI‑based tools (e.g., ChatBots, automated document processing, knowledge assistants)
  • Improve efficiency across security architecture services to enable utilization organizational wide
  • Optimize workflows and reduce manual workload through automation

Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group and was Hungary’s most attractive employer in 2025. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees, serving hundreds of large customers in Germany and other European countries.

India

  • Conduct security assessments, code reviews, and penetration testing to identify vulnerabilities.
  • Plan and execute security testing for LLM-enabled applications, including prompt injection testing.
  • Design, develop, and implement security tools and automation to prevent and detect vulnerabilities.

Granicus provides technology that transforms the Govtech industry by connecting governments and constituents. They are a remote-first company with a globally distributed workforce across the United States, Canada, United Kingdom, India, Armenia, Australia, and New Zealand.

$246,000–$369,000/yr
US Canada

  • Define the technical direction for AI-powered security capabilities.
  • Set the architecture, technical standards, and operating model for AI use.
  • Design production-grade systems that operate under enterprise scrutiny.

1Password is building the foundation for a safe, productive digital future. As one of the most loved brands in cybersecurity, they take a human-centric approach in everything from product strategy to user experience; it has over 180,000 businesses who trust 1Password.

$110,000–$120,000/yr
US Unlimited PTO 11w maternity 6w paternity

  • Design, implement, and manage application and cloud security tooling across AWS.
  • Lead the deployment and configuration of Wiz CSPM, collaborating with infrastructure and DevOps teams.
  • Manage secure code scanning processes, integrating SAST and DAST to identify and remediate vulnerabilities early in the SDLC.

Twin Health aims to empower people to improve and prevent chronic metabolic diseases with AI Digital Twin technology. It is recognized for innovation and culture, with recent funding to scale rapidly across the U.S. and globally.

ANZ

  • Play a pivotal role in shaping the architecture, strategic direction and maturity of Canva’s Detection and Response capabilities.
  • Deliver innovative and scalable security solutions yourself as an individual, and also as a mentor of other security builders.
  • Evangelise and lead the adoption and integration of GenAI Workflows to raise the efficiency and scalability of the Detection and Response team’s operations.

Canva is a design platform redefining how the world experiences design. They have campuses in Sydney and Melbourne, and co-working spaces in Brisbane, Perth and Adelaide, with a flexible and fun culture that incorporates empathy, humility, and generosity.

$165,000–$200,000/yr
US Unlimited PTO

  • Lead security architecture/design review and threat modeling sessions with product and engineering teams.
  • Conduct hands-on penetration testing and security assessments across our full product stack.
  • Drive PSIRT Operations by triaging incoming vulnerability reports, leading technical investigations, coordinating remediation with engineering, scoring severity.

Greenlight is a family fintech company with a mission to help parents raise financially smart kids through their award-winning banking app. They serve over 6 million parents and kids, offering tools to automate allowance, manage chores, set spend controls, and invest.

US Canada Ireland UK Mexico Argentina

  • Perform infrastructure security reviews across cloud services, network design, IAM, and platform components.
  • Design and build internal security services, APIs, and tools that automate infrastructure vulnerability detection, triage, reporting, and remediation.
  • Develop security automation that integrates with CI/CD, cloud control planes, and developer workflows to shift detection and remediation earlier in the lifecycle.

Webflow is building the world’s leading AI-native Digital Experience Platform as a remote-first company. They empower teams to design, launch, and optimize for the web without barriers, from entrepreneurs to global enterprises, and believe the future of the web, and work, is more open, more creative, and more equitable.

South America

  • Plan, develop, implement, and update the company’s information security strategy for infrastructure and software development.
  • Develop, execute and track the performance of security measures to protect information and network infrastructure and computer systems.
  • Identify, define and document system security requirements and recommend solutions to management.

Stensul is the Governed Creation™ Platform for enterprise marketing teams that need to create campaigns quickly, safely, and at scale. We bring creation, collaboration, and control together in one connected platform. They are a people-first team that values inclusive collaboration, ownership, and continuous learning.