Source Job

$110,000–$120,000/yr
US Unlimited PTO 11w maternity 6w paternity

  • Design, implement, and manage application and cloud security tooling across AWS.
  • Lead the deployment and configuration of Wiz CSPM, collaborating with infrastructure and DevOps teams.
  • Manage secure code scanning processes, integrating SAST and DAST to identify and remediate vulnerabilities early in the SDLC.

AWS SAST DAST Python

20 jobs similar to Application Security Engineer

Jobs ranked by similarity.

US Unlimited PTO

  • Architect and implement secure AWS configurations (IAM roles/policies, encryption keys, VPC segmentation)
  • Embed security into CI/CD pipelines and repos using policy-as-code tools (pre-commit hooks, SAST/SCA, IDE tool integrations)
  • Conduct threat modeling sessions and risk‑driven design reviews early in development

OnePay is a consumer fintech company trusted by millions of Americans to make money better by providing an all-in-one financial services platform. They are backed by Walmart and Ribbit Capital, allowing them rare scale and distribution to build something truly category-defining.

$130,000–$186,000/yr
US

  • Create, manage, and maintain the application security strategy and roadmap.
  • Develop, execute, and track the performance of security measures to protect Alma’s data, applications, and systems.
  • Build and provide high-quality application security documentation and training to engineers.

Alma simplifies access to high-quality, affordable mental health care by making it easy and financially rewarding for therapists to accept insurance. Alma has over 20,000 therapists in their growing network and was named one of Inc’s Best Workplaces in 2022 and 2023.

$181,125–$258,750/yr
US Unlimited PTO

  • Drive security of systems at scale and influence security strategy.
  • Integrate security into our SDLC with a shift-left approach.
  • Build a culture where security empowers developers through best practices.

Boulevard provides a client experience platform for appointment-based, self-care businesses, empowering customers to enhance client experiences. They are a team that values diverse backgrounds and believes in equal opportunity, fostering an inclusive culture where employees can excel.

$101,405–$140,400/yr
US Unlimited PTO

  • Analyze security vulnerabilities and drive remediations.
  • Integrate security at every stage of the SDLC.
  • Deploy and manage security tooling.

Modern Health is a mental health benefits platform for employers, offering access to various resources for emotional, professional, social, financial, and physical well-being. They are the fastest entirely female-founded company in the U.S. to reach Unicorn status, with a unique culture centered around high empathy and accountability.

US Unlimited PTO

  • Conducting a comprehensive threat model of our application and infrastructure layers.
  • Hardening our AWS infrastructure while keeping developer workflows frictionless.
  • Integrating security tooling into our CI/CD pipeline.

Loancrate simplifies home-buying for lenders and borrowers by building AI-native tooling to automate mortgage workflows. Since 2020, their remote team has enabled customers to power >$85 billion in new home loans and they value collaboration and open communication.

Global

  • Lead Application Security testing projects and drive remediation of identified vulnerabilities.
  • Design and run adversarial testing campaigns across the full Buildkite environment.
  • Build automation for both AppSec and adversarial testing workflows.

Buildkite's mission is to unblock every developer on the planet with their CI/CD platform. They are a remote-first company since 2013 with a small team, high standards, and real ownership distributed across 60+ cities, built around async communication and genuine autonomy.

Europe

  • Drive adoption of a Secure Software Development Lifecycle (SSDLC) across engineering teams.
  • Implement and integrate application security tooling into CI/CD pipelines, improving vulnerability detection and remediation.
  • Establish consistent threat modelling and secure design practices across new features and products.

Neko Health's mission is to deliver proactive healthcare for all, empowering members to take control of their health via technology and compassionate care. They have nearly 100 full-time engineers working across Berlin, Chamonix, Hamburg, Lisbon, Marseille, Vilnius, and Stockholm and they support a flexible workplace that prioritizes work-life balance.

South America

  • Collaborate with engineering teams to design and build cloud-native applications and infrastructure that are secure by default.
  • Use CSPM tools (like Wiz) to discover cloud security findings and provide clear, practical guidance to teams on how to remediate those risks.
  • Create new security alerts and dashboards within our infosec stack and perform threat hunting across log feeds to identify emerging risks.

KnowBe4 is a cybersecurity company that puts security first. Their AI-driven Human Risk Management platform empowers over 70,000 organizations worldwide to strengthen their security culture.

US Canada Ireland UK Mexico Argentina

  • Perform infrastructure security reviews across cloud services, network design, IAM, and platform components.
  • Design and build internal security services, APIs, and tools that automate infrastructure vulnerability detection, triage, reporting, and remediation.
  • Develop security automation that integrates with CI/CD, cloud control planes, and developer workflows to shift detection and remediation earlier in the lifecycle.

Webflow is building the world’s leading AI-native Digital Experience Platform as a remote-first company. They empower teams to design, launch, and optimize for the web without barriers, from entrepreneurs to global enterprises, and believe the future of the web, and work, is more open, more creative, and more equitable.

US

  • Run client SAST/DAST/SCA tools, review outputs and provide recommendations
  • Work with development teams to identify and remediate security vulnerabilities
  • Provide security guidance during the software development lifecycle (SDLC)

GuidePoint Security provides cybersecurity expertise and solutions to help organizations make better decisions and minimize risk. Since 2011, they've grown to over 1,200 employees and serve as a trusted advisor to more than 6,200 customers, fostering a collaborative and enjoyable workplace.

Global Unlimited PTO

  • Architect, implement, and maintain cloud security controls across AWS and GCP.
  • Take full ownership of security projects, driving them from initial concept through deployment.
  • Continuously assess cloud environments using Cloud Security Posture Management (CSPM) platforms.

Xapo Bank is a fully distributed team of over 130 Xapiens that work remotely from 30+ countries around the world. They aim to provide economic freedom and wealth protection, searching the world for the best people and inspiring each other to learn and grow.

US

  • Design and implement cloud security guardrails across AWS and GCP
  • Embed policy enforcement and compliance checks directly into Terraform modules
  • Conduct architecture reviews and continuously harden multi-cloud environments

Beast Industries is a multifaceted media and entertainment company founded by Jimmy Donaldson, popularly known as MrBeast. We are known for revolutionizing digital content creation, encompassing ventures that extend far beyond YouTube.

$239,000–$275,000/yr
Unlimited PTO

  • Own the technical design and review process for security-critical systems.
  • Maintain mastery of technical security domains to solve complex business challenges.
  • Create and implement advanced tools and automation to increase security monitoring.

Garner Health aims to transform the healthcare economy, delivering high-quality and affordable care for all. They partner with employers to redesign healthcare benefits using clear incentives and data-driven insights. Garner Health is one of the fastest-growing healthcare technology companies.

6w PTO 26w maternity 26w paternity

  • Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues
  • Lead security operation functions – including vulnerability management, SAST, DAST, detection engineering, and incident response – in CI/CD and cloud-native production environments
  • Integrate security into our applications throughout the software development lifecycle

They are scaling intelligence to serve humanity by training and deploying frontier models for developers and enterprises, building AI systems to power magical experiences. Cohere is composed of researchers, engineers, and designers who are passionate about their craft, and believes that a diverse range of perspectives is a requirement for building great products.

$250,000–$320,000/yr
US

  • Actively partner on the Cloud Security strategy and implementation.
  • Evolve and expand our current Cloud Security posture across multiple platforms.
  • Recommend and validate Security controls and improvements across our infrastructure stack

Circle is a global financial technology firm building the foundation for a more open financial system through digital assets, payment applications, and blockchain infrastructure. They value their employees and foster a culture of collaboration and excellence, with a flexible work enviornment.

Global

  • Design and implement security controls across cloud infrastructure, applications, and data systems.
  • Identify, assess, and mitigate security risks through threat modeling, reviews, and testing.
  • Build and maintain monitoring, alerting, and incident response capabilities.

BlockchainUnmasked aims to streamline cryptocurrency forensic investigations through advanced automation combined with cutting-edge solutions. They work with investigative partners to dramatically accelerate investigation times and boost success rates in interdiction, recovery, and deterrence.

Europe

  • Conduct security assessments and build a prioritized remediation roadmap across infrastructure and services
  • Harden AWS and Kubernetes environments: IAM, network policies, workload isolation, secrets management
  • Secure AI-specific attack surfaces: prompt injection defenses, PII handling in LLM pipelines, model interaction data leakage

Kiefer Tech leverages over 20 years of engineering heritage from the Green Energy sector to deliver cutting-edge AI, robotics, and enterprise solutions across Greece and the EU. They build sovereign AI infrastructure that keeps data within EU borders, respect privacy, and delivers tangible business impact.

Global

  • Develop and maintain automated security tools and processes to identify vulnerabilities and conduct security testing.
  • Design and implement secure cloud infrastructure, network architecture, and deployment processes.
  • Implement security monitoring tools and processes to proactively identify and respond to security events and anomalies.

Deel is an all-in-one payroll and HR platform for global teams, aiming to unlock global opportunity for every person, team, and business. They are among the largest globally distributed companies with a team of 7,000 spanning more than 100 countries, fostering a connected and dynamic culture.

Global

  • Lead and grow a high-performing security engineering team.
  • Own cloud security architecture for AWS.
  • Embed security into the SDLC: threat modeling, secure coding guidance, code scanning, dependency controls, build-time checks, and release gates.

Keyrock is a leading change-maker in the digital asset space, known for partnerships and innovation. They have over 180 team members around the world from 42 nationalities, with backgrounds ranging from DeFi natives to PhDs, with hubs in London, Brussels, Singapore and Paris.

Global

  • Partner with engineering teams throughout the SDLC to embed security by design in our products.
  • Lead and evolve our AppSec tooling and workflows by implementing, tuning, and integrating SAST, DAST, SCA, and container/image scanning into CI/CD pipelines.
  • Drive vulnerability management for our applications and supply chain, including triaging and prioritizing issues, coordinating with teams on fix/mitigate/accept decisions.

Camunda is the leader in enterprise agentic automation, orchestrating complex business processes across agents, people, and systems. They were named a Visionary in the inaugural 2025 Gartner Magic Quadrant for Business Orchestration and Automation Technologies (BOAT).