Source Job

United States Canada Dominican Republic Unlimited PTO

  • Conduct manual penetration tests against core systems and AI systems, and build AI-assisted tooling to extend testing coverage.
  • Help define how we pentest AI, including LLM applications, agents, and agent-generated code.
  • Triage findings from SAST tools, fix vulnerabilities, and tune rules to reduce false positives.

Application Security Penetration Testing AWS AI/LLM Security Secure Code Review

20 jobs similar to Senior Application Security Engineer

Jobs ranked by similarity.

US

  • Hunt for and close security vulnerabilities across Counterpart Assistant using custom tooling and AI-driven frameworks.
  • Harden systems, services, and endpoints while establishing strong security monitoring and safeguarding PHI.
  • Raise the security bar by reviewing critical pull requests, running training, and mentoring engineers on secure coding practices.

Counterpart Health, a subsidiary of Clover Health, builds an AI-enabled primary care tool called Counterpart Assistant that helps physicians diagnose and manage chronic conditions earlier. The company employs a remote-first culture with a diverse and inclusive team focused on transforming healthcare at scale.

$111,000–$144,400/yr
US

  • Plan and execute application security testing across the software development lifecycle to identify vulnerabilities.
  • Communicate findings and risks to stakeholders and collaborate with teams to drive secure design practices.
  • Lead AI security initiatives including threat modeling and auditing third-party models and APIs.

Clear Capital is a national real estate analytics and valuation technology company that builds confidence in real estate decisions. Established in 2001, the company values integrity, empathy, and excellence in its team.

US

  • Deliver AI red teaming security assessments for enterprise clients, defining scopes and authoring detailed reports.
  • Build and improve frameworks and tooling to scale AI red teaming service delivery and automate repetitive tasks.
  • Develop novel red teaming methodologies for emerging AI modalities and stay ahead of the latest AI security threats.

Check Point protects over 100,000 organizations worldwide from cyber and AI-driven threats using a prevention-first approach. They are recognized by TIME, Newsweek, and Forbes for excellence and workplace culture.

Canada Unlimited PTO

  • Secure cloud infrastructure, applications, APIs, and AI-driven workflows.
  • Partner with engineering to embed security controls into production.
  • Lead vulnerability management and incident response activities.

Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company is a high-growth startup with a remote-first culture, emphasizing transparency, autonomy, and technical craftsmanship.

$109,000–$156,000/yr
US

  • Define and implement secure software development practices including secure coding standards and CI/CD integration.
  • Lead Shift Left security initiatives and threat modeling to embed security early in the development lifecycle.
  • Drive application security for AI and LLM applications through red teaming, guardrails, and risk assessments.

$120,000–$140,000/yr
US Unlimited PTO 20w maternity 12w paternity

  • Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
  • Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
  • Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.

GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.

$199,000–$249,000/yr
US

  • Drive AI security innovation and strategy, ensuring secure AI adoption across the platform and internal productivity initiatives.
  • Implement AI guardrails and defenses against AI-based threats, while leveraging AI for security benefits.
  • Lead security initiatives, architect solutions, and mentor engineers to elevate the overall security posture.

Addepar is a global data and AI platform that empowers investment professionals to turn complex financial information into actionable intelligence. The company serves over 1,400 firms in nearly 60 countries and manages nearly $9 trillion in assets, with offices worldwide.

$174,250–$205,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Lead the security design, implementation, and controls for Jasper’s AI infrastructure and AI-powered internal workflows.
  • Own threat modeling for AI-specific risks and design controls for validating, logging, and auditing AI outputs.
  • Build security tooling and automated checks to let internal teams adopt AI capabilities without slowing down.

Jasper is the marketing agents platform that helps enterprises orchestrate AI agents for marketing execution. Founded in 2021, Jasper has team members across the U.S., Australia, and France, and is trusted by hundreds of enterprises including nearly 20% of the Fortune 500.

$130,100–$187,000/yr
US

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.

Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.

US Unlimited PTO 12w maternity 12w paternity

  • Drive and conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities.
  • Manage and implement security testing tools and frameworks to simulate real-world attacks and validate security controls.
  • Design and implement AI-enabled workflows to scale security testing and threat related operations.

Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. They are a Series C company backed by a16z, managing over $110 billion in loans, with a culture that values security and innovation.

Global

  • Lead Application Security initiatives across HighLevel's products and engineering teams.
  • Conduct architecture reviews, threat modeling, and security assessments for web, mobile, and API applications.
  • Drive DevSecOps practices by automating security in CI/CD pipelines and managing security tooling.

HighLevel is an AI-powered, all-in-one white-label sales and marketing platform that empowers agencies and businesses to grow their digital presence. With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment with a culture rooted in creativity, collaboration, and impact.

US

  • Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
  • Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
  • Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.

Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity, using AI to assess petabytes of enterprise data and remediate critical breaches. We're backed by Greylock, have experienced rapid growth, and our team includes top minds from Stanford, Deepmind, and leading tech companies.

$139,000–$258,000/yr
US Canada Unlimited PTO

  • Design and implement layered AI guardrails and sandboxing to constrain AI behavior and secure enterprise workflows.
  • Partner with users to bake secure-by-default patterns into AI-assisted workflows and maintain an inventory of AI-to-service connections.
  • Continuously test guardrails through red-teaming and evaluate new AI tools to find secure ways to enable adoption.

Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI, developing autonomous transportation technology for commercial trucks and robotaxis. Backed by world leaders in AI and automotive, the company has offices in Toronto, San Francisco, Dallas, and Pittsburgh and is growing quickly with a diverse, innovative team.

US

  • Adversarially test our AI and LLM-backed features.
  • Build and operate production security services.
  • Threat model from product designs.

GoodLeap is a technology company that provides financing and software products for sustainable solutions like solar panels and energy-efficient HVAC. With over $30 billion in financing since 2018, the company supports a collaborative culture and backs the nonprofit GivePower.

$120,000–$145,000/yr
US

  • Design, build, and scale application security capabilities to support secure software development across the enterprise.
  • Develop security patterns and guardrails for AI-assisted development and agentic workflows.
  • Integrate security tools with developer platforms to improve vulnerability management and automate remediation.

NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.

$170,000–$190,000/yr
US Unlimited PTO

  • Own application and product security: threat modeling, secure design review, and secure code review for a member-facing healthcare app.
  • Build and secure the AI-native agentic SDLC with security gates and controls for AI-generated code.
  • Manage security architecture across AWS environment, identity and access management, and third-party vendor integrations.

Oshi Health is on a mission to eliminate the impact of digestive health conditions through innovative GI care, operating a virtual-first platform. As a fully remote, SaaS- and cloud-native healthcare company, they foster a culture that thrives on diversity, with monthly DEIB discussions, and emphasize core values like owning the outcome and doing the right thing.

North America Unlimited PTO

  • Identify and validate realistic attack paths across applications and infrastructure.
  • Develop safe proof-of-concept exploits to demonstrate security risks.
  • Partner with engineering teams to validate fixes and improve security posture.

A fast-growing technology environment focused on product security, protecting products used by millions of consumers. The culture emphasizes collaboration, proactive security practices, and leveraging AI to improve efficiency.

UK 5w PTO

  • Conduct threat modelling sessions using STRIDE with product and engineering teams, focusing on clinical safety, abuse, and business-logic threats.
  • Own and evolve the Secure by Design process, including self-evaluation screening, secure design review, and automated tooling against technical artefacts.
  • Perform automated application and API penetration testing against web, mobile backends, cloud-native services, and AI features, and lead third-party penetration engagements.

Numan is a digital health platform founded in 2018 that integrates diagnostics, medication, supplements, digital programmes, and doctor consultations to empower people to take control of their health. They are a 300+ person team distributed globally, guided by values of patient focus, learning, quality, collaboration, and care.

US Unlimited PTO

  • Own the Application Security product strategy and roadmap, from tooling to governance.
  • Drive delivery of security solutions with engineering and cross-functional teams.
  • Lead tool procurement, risk prioritization, and executive communication.

Zeta Global is an AI-powered marketing cloud that helps marketers acquire and retain customers using advanced AI and consumer data. Founded in 2007, the company is headquartered in New York City with offices worldwide, employing a diverse team focused on innovation and inclusion.

$180,000–$210,000/yr
US Canada Unlimited PTO 12w maternity 12w paternity

  • Threat model new product features and integrations, hardening systems with effective controls.
  • Operate and evolve the application security toolchain, keeping it high-signal for developers.
  • Own day-to-day security operations across the detection stack, triaging and resolving incidents.

Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.