Source Job

UK Unlimited PTO

  • Penetration test web applications, APIs, and mobile applications for clients across various industries.
  • Work with technical and non-technical stakeholders to identify vulnerabilities and recommend remediations.
  • Collaborate closely with developers and teams to strengthen application security and drive continuous improvement.

Penetration Testing Application Security Web Application Security API Security

20 jobs similar to Application Security Engineer

Jobs ranked by similarity.

Nigeria

  • Conduct thorough security assessments and penetration testing to identify vulnerabilities in web and mobile applications.
  • Collaborate with development teams to integrate security best practices and design secure application architectures.
  • Lead incident response and ensure compliance with security standards and regulations.

Moniepoint Inc. is an all-in-one African financial platform serving 20 million businesses with payments, banking, and tools. As Nigeria's largest merchant acquirer, it processes over $250 billion annually and fosters a culture of innovation and teamwork.

Germany

  • Perform penetration tests of IT infrastructures, web applications, and web services.
  • Conduct security assessments in Active Directory, cloud environments (Azure, AWS), and mobile applications.
  • Analyze AI-powered applications and LLM integrations for vulnerabilities and misconfigurations.

SITS Deutschland GmbH is part of the SITS Group, a leading IT security provider offering holistic security solutions. The company has over 700 employees and fosters a culture of appreciation, team spirit, and work-life blending.

US

  • Lead the maturation of Delinea's Offensive Security program, including penetration testing and red teaming operations.
  • Manage a team of penetration test engineers, set performance objectives, and provide mentorship.
  • Collaborate with Product Development, DevOps, IT, and SecOps to test security controls and report findings to technical and executive audiences.

Delinea is a pioneer in securing human and machine identities through intelligent, centralized authorization, empowering organizations to govern interactions across the modern enterprise. The company is a global, passionate team backed by TPG, valuing diversity, innovation, and a culture of respect and fairness.

  • Conduct penetration tests on applications, systems, and networks to validate security controls.
  • Assess security posture, identify risks, and recommend remediation plans.
  • Collaborate with IT and business teams to articulate security requirements in business language.

Philadelphia Company provides customized IT solutions to support organizational success. They are committed to excellence and focus on client needs.

US Unlimited PTO

  • Lead end-to-end penetration testing and red team engagements for customer environments including internal networks, web applications, and cloud infrastructure.
  • Perform in-depth testing with manual techniques to find business-logic flaws and high-impact attack chains that automated tools miss.
  • Deliver high-quality client-ready reports with clear risk ratings, business impact, and practical remediation guidance.

Horizon3 is a fast-growing cybersecurity company whose NodeZero platform delivers autonomous pentests and assessment operations for organizations of all sizes. The team is a fusion of former U.S. Special Operations cyber operators, startup engineers, and cybersecurity practitioners, committed to a culture of respect, collaboration, ownership, and results.

US

  • Hunt for and close security vulnerabilities across Counterpart Assistant using custom tooling and AI-driven frameworks.
  • Harden systems, services, and endpoints while establishing strong security monitoring and safeguarding PHI.
  • Raise the security bar by reviewing critical pull requests, running training, and mentoring engineers on secure coding practices.

Counterpart Health, a subsidiary of Clover Health, builds an AI-enabled primary care tool called Counterpart Assistant that helps physicians diagnose and manage chronic conditions earlier. The company employs a remote-first culture with a diverse and inclusive team focused on transforming healthcare at scale.

US Unlimited PTO

  • Perform application security testing and vulnerability assessments on web applications, APIs, and CI/CD pipelines.
  • Support DevSecOps tool integration and automation, including security scanning and policy enforcement.
  • Develop proof-of-concept secure reference implementations and utility applications to demonstrate best practices.

Ardent supports the federal government's most critical national security and defense priorities. They offer competitive pay, comprehensive benefits, and a culture that values dedication and flexibility.

$120,000–$140,000/yr
US Unlimited PTO 20w maternity 12w paternity

  • Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
  • Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
  • Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.

GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.

Global

  • Serve as a subject matter expert on application and cloud security, representing Escape at industry events, conferences, and webinars.
  • Create and deliver engaging content: blogs, videos, presentations, and technical documentation that educates and inspires.
  • Work directly with customers to understand their challenges, provide best practice guidance, and gather feedback for product improvement.

Escape secures the code-to-cloud attack surface that covers DAST, ASM and AI Pentesting. With a team of 45+ people based across multiple global locations, we are Series A funded and rapidly growing.

Europe

  • Act as an Application Security SME, partnering with Engineering and Product teams to embed security throughout the SDLC.
  • Lead application security reviews, threat modeling, code reviews, and penetration testing to identify and mitigate risks.
  • Design and automate security controls across CI/CD pipelines, including SAST, SCA, and other AppSec tooling.

Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America, backed by leading investors, and places millions of workers.

$160,000–$195,000/yr

  • Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
  • Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
  • Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.

Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.

North America Unlimited PTO

  • Identify and validate realistic attack paths across applications and infrastructure.
  • Develop safe proof-of-concept exploits to demonstrate security risks.
  • Partner with engineering teams to validate fixes and improve security posture.

A fast-growing technology environment focused on product security, protecting products used by millions of consumers. The culture emphasizes collaboration, proactive security practices, and leveraging AI to improve efficiency.

$130,000–$160,000/yr
US

  • Assess and validate web application vulnerabilities across targets, confirming exploitability and scope.
  • Reproduce findings hands-on using tools like Burp Suite and rate severity with CVSS/OWASP.
  • Write clear, accurate customer-facing finding descriptions and remediation guidance.

RunSybil builds Sybil, an AI-driven pentester that automates hacker intuition to discover vulnerabilities before exploitation. Founded in 2023, the company is backed by strong investor support and includes experts from OpenAI, Meta, Mandiant, Palantir, Cruise, Trail of Bits, and Aptiv.

EMEA

  • Drive application security initiatives across the SDLC, partnering with engineering teams to promote secure coding and security-by-design.
  • Integrate security testing tools into CI/CD pipelines and automate security processes using modern AppSec and DevSecOps tools.
  • Perform vulnerability analysis, source code review, and support threat modeling and secure design reviews.

Devoteam Cyber Trust is the cybersecurity arm of the Devoteam Group, offering end-to-end cyber resilience and managed security services. With 800+ experts across EMEA, they are ISO 27001 certified and serve clients in over 20 countries.

$116,920–$175,380/yr
Canada

  • Conduct comprehensive penetration tests across applications, APIs, cloud environments, and infrastructure to identify vulnerabilities.
  • Assess security controls in multi-cloud environments (AWS, GCP) and review Infrastructure as Code configurations.
  • Collaborate with engineering teams to improve security practices and create high-quality technical documentation.

The company develops and secures products in a multi-cloud environment, focusing on cybersecurity. It fosters a collaborative and inclusive culture that encourages innovation and technical excellence.

$130,100–$187,000/yr
US

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.

Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.

$140,000–$140,000/yr
US Unlimited PTO

  • Conduct sophisticated security assessments across client environments, identifying vulnerabilities missed by conventional approaches.
  • Develop targeted attack plans based on bespoke hypotheses and client-specific objectives.
  • Produce actionable, threat-based reports that translate technical discoveries into meaningful security improvements.

Jobgether uses AI-powered matching to connect candidates with roles. It is a platform focused on efficient, objective hiring, with a culture emphasizing technical excellence, radical candor, and collaboration.

US

  • Partner with engineering and product teams to identify application security risks and provide practical mitigation recommendations.
  • Analyze code, configurations, and logs to detect vulnerabilities and improve security workflows.
  • Communicate security risks clearly to technical and non-technical stakeholders and drive scalable solutions.

UK Unlimited PTO

  • Protect applications trusted by millions of users in the Web3 ecosystem.
  • Combine hands-on security engineering with threat modeling, code reviews, and developer enablement.
  • Embed security throughout the software development lifecycle to build resilient products.

This company builds products and infrastructure for the Web3 ecosystem, focusing on digital assets, identities, and blockchain technology. It is a globally distributed, remote-first team with a culture of security, autonomy, and innovation.

$109,000–$156,000/yr
US

  • Define and implement secure software development practices including secure coding standards and CI/CD integration.
  • Lead Shift Left security initiatives and threat modeling to embed security early in the development lifecycle.
  • Drive application security for AI and LLM applications through red teaming, guardrails, and risk assessments.