Source Job

US Unlimited PTO 18w maternity 18w paternity

  • Champion secure-by-default culture by embedding defense-in-depth principles into engineering frameworks and development practices.
  • Conduct hands-on source code reviews, threat modeling, and security assessments across microservice architectures.
  • Build automation and frameworks to eliminate repetitive security work and create scalable security capabilities.

Application Security Software Development Microservices Threat Modeling SAST

20 jobs similar to Senior/Staff Engineer, Application & Product Security

Jobs ranked by similarity.

$217,000–$288,000/yr
US Unlimited PTO 18w maternity 18w paternity

  • Champion a secure by default culture, building defense in depth into frameworks and processes.
  • Develop security requirements and work directly with teams to build them into new applications.
  • Run security risk assessments, hands-on penetration testing, and threat modeling.

Grow Therapy is a three-sided marketplace that empowers therapists and patients by providing technology and insurance support. The company has raised over $328M in funding, employs roughly 145 engineers, and values a mission-driven culture.

US

  • Define and implement secure software development practices including secure coding standards and CI/CD integration.
  • Lead Shift Left security initiatives and threat modeling to embed security early in the development lifecycle.
  • Drive application security for AI and LLM applications through red teaming, guardrails, and risk assessments.

$172,000–$240,000/yr
US

  • Lead secure code reviews, threat modeling, and secure design assessments to translate findings into actionable guidance.
  • Design and integrate application security controls across CI/CD platforms and developer workflows.
  • Define secure coding standards, reference architectures, and automated security capabilities scalable to engineering teams.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities, ensuring rapid and fair application reviews. They focus on leveraging technology to streamline hiring processes and are committed to data privacy and professional growth.

$82,000–$118,000/yr
US

  • Strengthen application security across modern software environments, including AI-enabled applications and services.
  • Embed security throughout the development lifecycle through code reviews, automated testing, and secure design practices.
  • Partner with engineering, product, DevOps, compliance, and incident response teams to identify and reduce risk.

Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. It operates as a remote-first organization with a focus on integrity, collaboration, and continuous learning.

$120,000–$140,000/yr
US Unlimited PTO 20w maternity 12w paternity

  • Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
  • Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
  • Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.

GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.

Europe

  • Act as an Application Security SME, partnering with Engineering and Product teams to embed security throughout the SDLC.
  • Lead application security reviews, threat modeling, code reviews, and penetration testing to identify and mitigate risks.
  • Design and automate security controls across CI/CD pipelines, including SAST, SCA, and other AppSec tooling.

Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America, backed by leading investors, and places millions of workers.

US Unlimited PTO

  • Perform application security testing and vulnerability assessments on web applications, APIs, and CI/CD pipelines.
  • Support DevSecOps tool integration and automation, including security scanning and policy enforcement.
  • Develop proof-of-concept secure reference implementations and utility applications to demonstrate best practices.

Ardent supports the federal government's most critical national security and defense priorities. They offer competitive pay, comprehensive benefits, and a culture that values dedication and flexibility.

$138,677–$182,296/yr
US

  • Integrate security into the SDLC through automation, testing, and continuous improvement.
  • Identify, investigate, and remediate application and infrastructure vulnerabilities.
  • Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.

Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.

$130,100–$187,000/yr
US

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.

Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.

$180,000–$210,000/yr
US Canada Unlimited PTO 12w maternity 12w paternity

  • Threat model new product features and integrations, hardening systems with effective controls.
  • Operate and evolve the application security toolchain, keeping it high-signal for developers.
  • Own day-to-day security operations across the detection stack, triaging and resolving incidents.

Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.

US

  • Partner with engineering and product teams to identify application security risks and provide practical mitigation recommendations.
  • Analyze code, configurations, and logs to detect vulnerabilities and improve security workflows.
  • Communicate security risks clearly to technical and non-technical stakeholders and drive scalable solutions.

US

  • Own threat modeling and secure code reviews for new products and features.
  • Maintain and tune AppSec tooling, and run the bug bounty program.
  • Design and evolve the secure SDLC, and partner with engineering teams to implement secure-by-default patterns.

Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. The company operates at the intersection of traditional finance and on-chain systems, with a focus on security and innovation.

UK Unlimited PTO

  • Protect applications trusted by millions of users in the Web3 ecosystem.
  • Combine hands-on security engineering with threat modeling, code reviews, and developer enablement.
  • Embed security throughout the software development lifecycle to build resilient products.

This company builds products and infrastructure for the Web3 ecosystem, focusing on digital assets, identities, and blockchain technology. It is a globally distributed, remote-first team with a culture of security, autonomy, and innovation.

US Unlimited PTO

  • Own the Application Security product strategy and roadmap, from tooling to governance.
  • Drive delivery of security solutions with engineering and cross-functional teams.
  • Lead tool procurement, risk prioritization, and executive communication.

Zeta Global is an AI-powered marketing cloud that helps marketers acquire and retain customers using advanced AI and consumer data. Founded in 2007, the company is headquartered in New York City with offices worldwide, employing a diverse team focused on innovation and inclusion.

$120,000–$145,000/yr
US

  • Design, build, and scale application security capabilities to support secure software development across the enterprise.
  • Develop security patterns and guardrails for AI-assisted development and agentic workflows.
  • Integrate security tools with developer platforms to improve vulnerability management and automate remediation.

NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.

$170,000–$230,000/yr
US

  • Build secure-by-default infrastructure and automation to eliminate entire vulnerability classes across money-moving systems.
  • Own application security, threat modeling, and vulnerability disclosure from design review to production.
  • Partner with engineering to set security standards, make risk-based decisions, and ship fast without compromising safety.

Flex is building the AI-native private bank for business owners, re-architecting the entire financial system for entrepreneurs. Since launching in 2023, Flex has scaled to nine-figure annualized revenue, raised $100M+ in equity and $300M+ in debt, and operates with a high-bar, low-ego culture focused on speed and execution.

EMEA

  • Drive application security initiatives across the SDLC, partnering with engineering teams to promote secure coding and security-by-design.
  • Integrate security testing tools into CI/CD pipelines and automate security processes using modern AppSec and DevSecOps tools.
  • Perform vulnerability analysis, source code review, and support threat modeling and secure design reviews.

Devoteam Cyber Trust is the cybersecurity arm of the Devoteam Group, offering end-to-end cyber resilience and managed security services. With 800+ experts across EMEA, they are ISO 27001 certified and serve clients in over 20 countries.

$111,000–$144,400/yr
US

  • Plan and execute application security testing across the software development lifecycle to identify vulnerabilities.
  • Communicate findings and risks to stakeholders and collaborate with teams to drive secure design practices.
  • Lead AI security initiatives including threat modeling and auditing third-party models and APIs.

Clear Capital is a national real estate analytics and valuation technology company that builds confidence in real estate decisions. Established in 2001, the company values integrity, empathy, and excellence in its team.

$160,000–$195,000/yr

  • Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
  • Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
  • Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.

Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.

$88,800–$125,800/yr
Canada 3w PTO 12w maternity 12w paternity

  • Proactively identify and drive security improvements across the product and platform.
  • Partner with engineering teams to threat model new features and review designs early in development.
  • Build and improve security tooling, libraries, and workflows to make secure development the default path.

Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.