Source Job

$55,000–$77,000/yr
EMEA APAC

  • Expand the application security landscape at Coupa
  • Lead and execute Security Architecture Reviews, Threat Modeling, and Design Reviews
  • Be a champion of Coupa’s Secure Software Development Lifecycle ( SSDLC ) methodologies

Java .Net Python OWASP

20 jobs similar to Lead Application Security Engineer

Jobs ranked by similarity.

$135,000–$200,000/yr
US Unlimited PTO

  • Perform security reviews of our current and future product and service portfolio.
  • Be the security subject matter expert for product architects and engineers for threat modeling.
  • Find new and novel ways to identify and resolve security vulnerabilities in our products.

Palantir builds software for data-driven decisions and operations, empowering partners to develop lifesaving drugs, forecast supply chain disruptions, and locate missing children. They value excellence and encourage employees to work from their offices to foster connectivity and innovation.

$106,500–$202,500/yr
US

  • Implementing and maintaining Application Security Testing (AST) tools to identify code and dependency vulnerabilities during the software development lifecycle.
  • Implementing and maintaining Application Security Posture Management (ASPM) tools to centralize findings from multiple solutions and integrate into software development processes.
  • Acting as the first line of support for users by helping resolve false positives, providing guidance on finding remediation, and evaluating security exception requests.

AbbVie discovers and delivers innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. They strive to have a remarkable impact on people's lives across several key therapeutic areas and products and services in their Allergan Aesthetics portfolio.

$215,000–$230,000/yr
US

  • Lead application security reviews and threat modeling.
  • Develop automated testing and mature our Secure SDLC.
  • Own and perform application security vulnerability management.

TRM Labs provides blockchain analytics and AI solutions to help law enforcement, national security agencies, financial institutions, and cryptocurrency businesses detect and disrupt crypto-related fraud and financial crime. They are a Series C company with $220M in funding and operate as a distributed-first company.

Canada

  • Help scale NerdWallet’s application security program through automation, tooling, and developer enablement.
  • Partner with engineering and product teams to identify and remediate security gaps across multiple systems while balancing business priorities.
  • Build tools, processes, and automation that improve security posture visibility for engineers and leadership.

NerdWallet aims to bring clarity to life's financial decisions with a team of exceptional Nerds. They foster an inclusive, flexible, and candid culture where employees are empowered to grow and take risks, supporting well-being and development whether working remotely or in-office.

US

  • Assist with the delivery of Application Security services.
  • Contribute to Application Security research projects.
  • Maintain a  strong desire to learn, adapt, and improve along with a rapidly-growing company

GuidePoint Security provides trusted cybersecurity expertise, solutions, and services that help organizations make better decisions and minimize risk. Since its inception in 2011, GuidePoint has grown to over 1,200 employees and established strategic partnerships with leading security vendors.

Europe 5w PTO

  • Conduct regular security assessments, vulnerability scanning, and penetration testing of Veeam products and services
  • Work with development teams to integrate secure development practices into the software development lifecycle
  • Collaborate on the design and implementation of security within Veeam products

Veeam specializes in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. They are headquartered in Seattle with offices in more than 30 countries, protecting over 550,000 customers worldwide.

India

  • Conduct security assessments, code reviews, and penetration testing to identify vulnerabilities.
  • Plan and execute security testing for LLM-enabled applications, including prompt injection testing.
  • Design, develop, and implement security tools and automation to prevent and detect vulnerabilities.

Granicus provides technology that transforms the Govtech industry by connecting governments and constituents. They are a remote-first company with a globally distributed workforce across the United States, Canada, United Kingdom, India, Armenia, Australia, and New Zealand.

$160,000–$200,000/yr
US Unlimited PTO

  • Lead threat modeling and security architecture reviews for distributed, event-driven systems.
  • Integrate security code reviews, SAST/DAST, Software Composition Analysis (SCA), and container scanning into CI/CD and AI/ML pipelines.
  • Evangelize secure coding and AI security through training, brown bag sessions, and workshops.

Zeta Global is an AI-Powered Marketing Cloud that helps marketers acquire, grow, and retain customers more efficiently. They unify identity, intelligence, and omnichannel activation into a single platform. Zeta Global is headquartered in New York City with offices around the world.

$140,000–$150,000/yr
US Global

  • Partner with engineering teams to conduct threat modeling.
  • Build and maintain automated scanning, penetration testing frameworks, and monitoring tools within our AWS CI/CD pipelines.
  • Champion a "security-first" mindset and host workshops that empower developers to write secure code.

Panopto is a customer-centric learning technology company and the leader in visual and audio-based learning. They empower organizations to share knowledge effortlessly. Panopto has been adopted by more than 1,600 companies and universities worldwide with over 11 million end users.

US Unlimited PTO

  • Focus on automation, integrating security within the CI/CD pipeline, and DevOps toolchain.
  • Strong working knowledge of security fundamentals including OWASP Top10.
  • Experience with public cloud infrastructure (AWS or Azure) and cloud security fundamentals.

GuidePoint Security provides cybersecurity expertise, solutions, and services to help organizations make better decisions and minimize risk. They have grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serve as a trusted advisor to more than 6,200 customers.

US

  • Run client SAST/DAST/SCA tools, review outputs and provide recommendations
  • Work with development teams to identify and remediate security vulnerabilities
  • Provide security guidance during the software development lifecycle (SDLC)

GuidePoint Security provides cybersecurity expertise and solutions to help organizations make better decisions and minimize risk. Since 2011, they've grown to over 1,200 employees and serve as a trusted advisor to more than 6,200 customers, fostering a collaborative and enjoyable workplace.

$101,405–$140,400/yr
US Unlimited PTO

  • Analyze security vulnerabilities and drive remediations.
  • Integrate security at every stage of the SDLC.
  • Deploy and manage security tooling.

Modern Health is a mental health benefits platform for employers, offering access to various resources for emotional, professional, social, financial, and physical well-being. They are the fastest entirely female-founded company in the U.S. to reach Unicorn status, with a unique culture centered around high empathy and accountability.

Europe

  • Drive adoption of a Secure Software Development Lifecycle (SSDLC) across engineering teams.
  • Implement and integrate application security tooling into CI/CD pipelines, improving vulnerability detection and remediation.
  • Establish consistent threat modelling and secure design practices across new features and products.

Neko Health's mission is to deliver proactive healthcare for all, empowering members to take control of their health via technology and compassionate care. They have nearly 100 full-time engineers working across Berlin, Chamonix, Hamburg, Lisbon, Marseille, Vilnius, and Stockholm and they support a flexible workplace that prioritizes work-life balance.

US

  • Design, develop, and maintain application components using Java, JavaScript, and SQL.
  • Provide technical leadership and code guidance to the development team.
  • Participate in system design discussions and architecture reviews.

North Stone supports development and sustainment of defense applications. They value technical leadership and collaboration.

India

  • Design and implement security controls for mobile applications, backend services, and web platforms.
  • Conduct threat modelling and risk assessments for new and existing systems.
  • Embed secure coding practices across engineering teams, aligned with OWASP standards.

Smart Working connects skilled professionals with outstanding global teams and products for full-time, long-term roles, breaking down geographic barriers. It is a highly-rated workplace on Glassdoor, focused on community, growth, and well-being in a remote-first environment.

$110,000–$120,000/yr
US Unlimited PTO 11w maternity 6w paternity

  • Design, implement, and manage application and cloud security tooling across AWS.
  • Lead the deployment and configuration of Wiz CSPM, collaborating with infrastructure and DevOps teams.
  • Manage secure code scanning processes, integrating SAST and DAST to identify and remediate vulnerabilities early in the SDLC.

Twin Health aims to empower people to improve and prevent chronic metabolic diseases with AI Digital Twin technology. It is recognized for innovation and culture, with recent funding to scale rapidly across the U.S. and globally.

US Unlimited PTO

  • Lead security architecture and design reviews across applications, infrastructure, and integrations.
  • Conduct and coordinate penetration testing, threat modeling, and security reviews.
  • Design and implement security automation within CI/CD pipelines.

Assured modernizes insurance by providing software solutions to large insurers that help them win in a technology-driven world. Their products include self-service claim-filing software to backend fraud detection and are dynamic, collaborative, and rewarding.

$125,000–$175,000/yr
US

  • Lead architecture interviews with stakeholders.
  • Develop architecture briefing documents.
  • Support Continuous Monitoring activities.

Smartsheet helps people and teams achieve their goals with work management and scalable solutions. They empower teams to automate tasks, uncover insights, and scale smarter, with a focus on creating space for innovation and meaningful work.

$135,000–$185,000/yr
Canada

  • Design, implement, and maintain systems that secure Yelp’s AWS and Google Cloud Platform environments.
  • Develop and enforce data security controls to support privacy initiatives.
  • Manage system-level access controls and tiered access for internal digital assets.

Yelp's engineering culture values individual authenticity and encourages creative solutions. They focus on helping users, growing as engineers, and having fun in a collaborative environment.

6w PTO 26w maternity 26w paternity

  • Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues
  • Lead security operation functions – including vulnerability management, SAST, DAST, detection engineering, and incident response – in CI/CD and cloud-native production environments
  • Integrate security into our applications throughout the software development lifecycle

They are scaling intelligence to serve humanity by training and deploying frontier models for developers and enterprises, building AI systems to power magical experiences. Cohere is composed of researchers, engineers, and designers who are passionate about their craft, and believes that a diverse range of perspectives is a requirement for building great products.