Source Job

Europe

  • Bridge Security and Development, empowering engineering teams to deliver secure code.
  • Integrate security into the Software Development Life Cycle (SDLC) for AI-driven applications.
  • Conduct penetration tests and monitor application resilience.

Application Security Penetration Testing Cloud AI Security

20 jobs similar to Senior Application Security Specialist

Jobs ranked by similarity.

Global

  • Build AI agents that handle vulnerability triage, automated security reviews of PRs, and initial incident forensics at scale.
  • Build systems that automatically detect and remediate security gaps across AWS, GCP, and Azure -- configuration drift, IAM misconfigurations, vulnerable dependencies, exposed secrets.
  • Lead threat modeling, security reviews, and risk assessments across web applications, APIs, and services.

Atlan is building the missing context layer for data and AI, helping enterprises close the AI value chasm. They connect to every part of the modern data and AI stack to unify this context into a single, shared layer that both humans and AI agents can rely on.

$160,000–$200,000/yr
US Unlimited PTO

  • Lead threat modeling and security architecture reviews for distributed, event-driven systems.
  • Integrate security code reviews, SAST/DAST, Software Composition Analysis (SCA), and container scanning into CI/CD and AI/ML pipelines.
  • Evangelize secure coding and AI security through training, brown bag sessions, and workshops.

Zeta Global is an AI-Powered Marketing Cloud that helps marketers acquire, grow, and retain customers more efficiently. They unify identity, intelligence, and omnichannel activation into a single platform. Zeta Global is headquartered in New York City with offices around the world.

$165,000–$185,000/yr
Global Unlimited PTO

  • Own and lead Limble’s application security program, partnering with the Head of Information Security and key stakeholders to define strategy and roadmap.
  • Perform hands-on security work including threat modeling and secure design reviews, using engagements as opportunities to educate and influence engineering decisions.
  • Partner with engineering teams to triage, prioritize, and remediate vulnerabilities across the platform.

Limble empowers the unsung heroes who support the world by revolutionizing how businesses manage their maintenance operations. They provide a comprehensive suite of software solutions to optimize asset performance and drive operational excellence; their CMMS platform features streamline operations and enhance productivity.

$180,000–$190,000/yr
US

  • Embed security into the SDLC by partnering with Engineering to implement secure design patterns, conduct threat modeling, and deliver developer-focused AppSec training.
  • Lead and perform application security assessments including SAST, DAST, SCA, and manual code review across web, mobile, and API surfaces.
  • Own and mature the vulnerability management program, including prioritization frameworks, SLA tracking, and cross-functional remediation coordination.

Branch is on a mission to empower workers with financial freedom by helping companies accelerate payments and providing working Americans with accessible, free financial services. They are committed to building inclusive and transparent financial products while valuing diversity of opinions and working styles, fostering innovation, and promoting teamwork.

Global

  • Integrate security activities across all SDLC phases.
  • Partner closely with engineering teams to ensure secure development practices.
  • Review security controls for new features, services, and architectural changes.

Infiterra simplifies subscription service delivery, enabling IT distributors, Managed Service Providers (MSPs), and telcos to succeed in the subscription economy. They are recognized as a global leader in subscription commerce, combining innovation, performance excellence, and trusted expertise to help partners transform and grow.

India

  • Own and evolve vulnerability management end-to-end.
  • Embed secure design principles across mobile applications, APIs, and microservices.
  • Partner closely with engineering teams to remediate security issues.

Smart Working connects skilled professionals with global teams for full-time, long-term roles. They help you discover meaningful work with teams that invest in your success, where you’re empowered to grow personally and professionally.

$160,000–$188,000/yr
US Unlimited PTO

  • Own and drive the company’s security strategy, roadmap, and overall posture
  • Lead threat modeling, secure code reviews, and architecture reviews
  • Build and maintain security tooling, automation, and infrastructure as code

Seesaw's mission is to provide every elementary student with joyful and connected learning experiences that lay the foundation for success in life. Trusted and loved by 25 million educators, students, and families worldwide, Seesaw is the only elementary learning experience platform.

Global

  • Responsible for designing, engineering, and operationalizing AI security across J.S. Held’s enterprise.
  • Serves as the central Cyber Security owner for all AI Security.
  • Balances hands‑on engineering, solution design, and architectural leadership.

J.S. Held is a global consulting firm that combines technical, scientific, financial, and strategic expertise to advise clients seeking to realize value and mitigate risk. They provide a comprehensive suite of services, products, and data that enables clients to navigate complex, contentious, and often catastrophic situations.

Europe

  • Participate in threat modeling exercises with engineering team members
  • Triage SCA/SAST/DAST/CSPM findings by eliminating false positives and providing well-vetted vulnerabilities to engineering teams
  • Support vulnerability management efforts for networks and infrastructure

They offer a SaaS-based Global Employment Platform that enables clients to expand into over 180 countries. Their diverse, remote-first teams are essential to their success, fostering innovation and valuing every contribution.

$140,000–$160,000/yr
US

  • Design and maintain secure architectures across AWS, Azure, and GCP environments.
  • Collaborate with DevOps and Engineering to integrate security into CI/CD pipelines.
  • Monitor alerts, investigate incidents, and coordinate responses with the SOC.

Reveleer provides a cloud-based healthcare SaaS platform. They are an equal opportunity employer that values diversity and does not discriminate based on race, religion, or other protected characteristics.

US Unlimited PTO 16w maternity

  • Lead and grow a team of the best security engineers.
  • Define the strategy for Vanta’s application security program.
  • Work with Engineering and Product Development to assess and mitigate risk.

Vanta helps businesses earn and prove trust by providing continuous security monitoring and verification. They aim to empower companies to practice better security with their automation and orchestration tools. Vanta has a kind and talented team, embracing individuals with and without prior security experience.

US Unlimited PTO

  • Lead security architecture and design reviews across applications, infrastructure, and integrations.
  • Conduct and coordinate penetration testing, threat modeling, and security reviews.
  • Design and implement security automation within CI/CD pipelines.

Assured modernizes insurance by providing software solutions to large insurers that help them win in a technology-driven world. Their products include self-service claim-filing software to backend fraud detection and are dynamic, collaborative, and rewarding.

India

  • Design and implement security controls for mobile applications, backend services, and web platforms.
  • Conduct threat modelling and risk assessments for new and existing systems.
  • Embed secure coding practices across engineering teams, aligned with OWASP standards.

Smart Working connects skilled professionals with outstanding global teams and products for full-time, long-term roles, breaking down geographic barriers. It is a highly-rated workplace on Glassdoor, focused on community, growth, and well-being in a remote-first environment.

$147,900–$203,000/yr
US 4w PTO

  • Conduct regular vulnerability assessments, threat modeling, and security architecture and design reviews.
  • Partner with engineering teams to identify, prioritize, and mitigate identified risks
  • Design and implement proactive security solutions to systematically eliminate vulnerability classes rather than endlessly chase individual vulnerabilities

Oura's mission is to empower every person to own their inner potential. Its award-winning products help its global community gain a deeper knowledge of their readiness, activity, and sleep quality by using their Oura Ring and its connected app. The company is quickly growing and focused on helping people live healthier and happier lives, and ensures that its team members have what they need to do their best work — both in and out of the office.

$170,000–$180,000/yr
US Unlimited PTO

  • Design and build scalable platform services, web and mobile applications, and AI-powered workflows.
  • Leverage AI-accelerated developer tooling to improve delivery speed and code quality.
  • Participate in greenfield architectural decisions, including technology selection, service design, and infrastructure strategy.

Zócalo Health is a tech-enabled, community-oriented primary care organization serving people who have historically been underserved by healthcare. Founded in 2021, Zócalo Health is backed by leading healthcare investors and is scaling rapidly across states and populations.

  • Developing high-level and detailed design solutions for Azure-based applications.
  • Developing Azure DevOps pipelines.
  • Configuring Azure Virtual networks, including hybrid network architecture and cloud-native web ingress patterns.

The Department of Industry, Science and Resources helps the government build a better future for all Australians through enabling a productive, resilient and sustainable economy, enriched by science and technology. The Chief Information Officer Division (CIOD) provides a range of enabling services and operations delivery to the department and to Australian businesses.

Canada

  • Help scale NerdWallet’s application security program through automation, tooling, and developer enablement.
  • Partner with engineering and product teams to identify and remediate security gaps across multiple systems while balancing business priorities.
  • Build tools, processes, and automation that improve security posture visibility for engineers and leadership.

NerdWallet aims to bring clarity to life's financial decisions with a team of exceptional Nerds. They foster an inclusive, flexible, and candid culture where employees are empowered to grow and take risks, supporting well-being and development whether working remotely or in-office.

Global Unlimited PTO

  • Own and enforce DevSecOps practices across CI/CD pipelines.
  • Drive vulnerability identification, triage, and remediation across infrastructure and applications.
  • Act as the primary security SME for the engineering organization.

Teramind is pioneering a predictive, AI-driven approach to safeguarding organizations' people, data, and operations. As a global leader in user behavior analytics, insider risk management, and workforce intelligence, we empower businesses to transform data into a strategic asset.

US

  • Design, deploy, and manage security solutions within Cloud environments( Azure experience preferred).
  • Assist other security engineering and consulting needs as they arise.
  • Implement cloud security controls and monitor compliance frameworks (Azure Security Center, Azure Policy, etc.).

UChicago Medicine is a world-class academic healthcare system. We provide superior healthcare with compassion, always mindful that each patient is a person, an individual.

US Unlimited PTO

  • Support the design and implementation of secure application architectures under guidance from senior engineers.
  • Apply secure coding practices and assist in threat modeling and vulnerability assessments.
  • Conduct and support application security testing (SAST, DAST, SCA, and manual reviews).

Edgesource Corporation is an innovative technology service provider for the Department of Defense (DOD), Department of Homeland Security (DHS), Department of State (DOS), the U.S. Intelligence Community, Law Enforcement, and other federal, state, and commercial clients locally, nationally, and abroad. They are an ISO 9001:2015 certified and CMMI Level 3 appraised small business specializing in providing a variety of technical solutions.