About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role We’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate remediation of vulnerabilities across OpenAI’s infrastructure and applications. You will be the technical owner of this effort, combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at scale. As OpenAI increasingly uses automation throughout the company, we believe our security testing must become increasingly automated as well. Advances in model capabilities create an opportunity to test more of our attack surface than would be possible through human effort alone and a need to ensure that we remain ahead of those same capabilities as they become available to attackers. In this role, you’ll build a portfolio of specialized agents that develop a deep understanding of OpenAI’s infrastructure, applications, processes, and security boundaries. These agents will combine internal context with feedback from running systems to explore our cloud environments, Kubernetes clusters, web applications, endpoints, external attack surface, and other high-value targets. The goal is for agents to not only discover vulnerabilities, but also to validate exploitability, document impact, drive remediation, and verify fixes. Success will be measured through outcomes like vulnerabilities fixed, attack surface covered, and performance on evals
Jobs in United States
Application And Web Security Specialist in United States
2,567 active opportunities · Updated October 2026
Showing
15 jobs
Explore current application and web security specialist jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.
Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Data Scientist What is the opportunity? We are seeking a highly skilled and motivated Data Scientist to join our Cyber Analytics team within the Security Solutions Data Science organization. This role is critical to driving advanced analytics initiatives, improving fraud detection capabilities, and supporting strategic decision-making across cybersecurity and payment fraud domains. What will you do? • Gain subject matter knowledge on web application security, commonly exploited cyber vulnerabilities, and methods of online and payment card fraud including the common points of purchase for compromised cards. • Build, develop, and maintain innovative data-driven analytical solutions, including predictive models and machine learning algorithms, on large volumes of data to support analytics and reporting needs across products, markets, and services. • Competently handle large datasets, sifting for patterns and trends and translating those insights into technical rules and solutions. • Combine cybersecurity and transaction data into new and insightful views of fraud and vulnerability across the Mastercard network. • Collaborate with cross-functional teams including product, engineering, and operations to understand product, usage, and data pipelines as well as delivering scalable solutions. • T
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About Replit Replit is building the world's most ubiquitous AI coding agent. Replit Agent can be used by anybody to bring their ideas to life. Whether it's an app for yourself, the next great startup idea, or a tool to make you more productive at work, Replit Agent can help build it. Replit is also the leader in secure vibe coding. We protect apps, give users features to manage security risks, and help them vibe code more safely. About the role: Replit is changing how people and companies turn ideas into software. Reaching those customers requires engineering that connects acquisition to the product experience and gives teams trustworthy evidence about what works. This role goes beyond operating conventional marketing technology. You will rethink growth systems for a world where agents can observe performance, diagnose problems, take action, and learn from the result. As the founding engineer for Growth Enablement, you will set the technical direction for this area. You will build agentic systems alongside shared foundations for attribution, audiences, lifecycle engagement, referrals, and promotions. The work spans web, mobile, billing, and data. You will work directly with marketing, sales, and partnerships to find the highest-leverage problems and ship the first solutions. Successful projects will become platforms that help these teams move faster and give Replit a clearer view of what drives durable growth. You will: Design agentic growth systems that monitor performance, diagnose failures, run approved experiments, and improve from the results. Explore AI-native approaches to answer engine optimization, campaign operations, audience discovery, and measurement. Build acquisition measurement across web and mobile, in
Java Software Engineer - Developer (Experienced and Senior) Company: The Boeing Company The Boeing Company is currently seeking Java Software Engineers – Developer (Experienced and Senior) to support our Advanced Ground Architecture team located in Herndon, Virginia, Colorado Springs, Colorado, Mesa, Arizona, Seal Beach, California and El Segundo, California. This position will focus on supporting the Boeing Defense, Space & Security (BDS) Software Engineering organization. The Advanced Ground Architecture (AGA) software team is a dynamic group of software engineers creating the future of Ground support with the extensibility and adaptability to be used across ALL Boeing programs. The software team is executing this vision through modern software technologies (Java, ReactJS, python, CI/CD pipelines) and methodologies (Scaled Agile). AGA is looking for self-motivated high performers to execute the large scope of Java development needed for the program's vision. The ideal candidates will provide software engineering functions for the design, development, and maintenance of complex, multi-tiered application software systems used to support the command and control of space vehicles. The software engineers will work day-to-day with system and test engineers in order to implement, test, and document new features and improvements for both web services and applications supporting distributed computing solutions. Position Responsibilities: Designs, develops, tests, and maintains software in an Agile execution that meets industry, customer, safety, and regulation standards throughout the end-to-end lifecycle Reviews, analyzes, and translates customer requirements into initial design and softwa
About the Team The Cybersecurity Products team builds products at the frontier of AI and cybersecurity. Our work includes Codex Security and related cyber products that turn advances in model capability into dependable tools for defenders. We help teams find, validate, and remediate vulnerabilities, continuously improve the security of software, and test AI-powered applications before they reach production. About the Role As a Full Stack Software Engineer, you will build the product experiences and systems that make AI-powered security useful in real engineering environments. You will work across web surfaces, APIs, orchestration, data models, and integrations to help security and engineering teams move from a codebase or application to evidence-backed findings, prioritized remediation, and revalidation. You will collaborate closely with product engineers, security researchers, and customer-facing teams. The work spans fast-moving product development and hard systems problems: long-running workflows, large repositories, sensitive data, reliability, observability, and a high bar for earning user trust. This role is based in San Francisco, CA. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: Build end-to-end workflows for vulnerability discovery, security scanning, red teaming, findings review, remediation, and reruns. Design and operate backend services for long-running security work, including APIs, asynchronous orchestration, durable state, and integrations with developer workflows. Make complex security results actionable through clear product surfaces, strong evidence, thoughtful prioritization, and reliable reporting. Partner with security researchers, product teams, and users to evaluate quality, reduce noise, improve coverage, and ship safely. You might thrive in this role if you: Have experience shipping production full-stack products across modern web frontends and backend s
From $115.2K/yr
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Fullstack Engineer on the Duo Client SDK team at GitLab, you'll build the shared foundation for every GitLab Duo client. Today, the logic that powers Duo in editors lives inside the GitLab Language Server. We're extracting it into a true software development kit (SDK): a set of well-versioned TypeScript packages that editor extensions, our web-based Duo Chat on GitLab.com, and eventually external applications can use. You'll work in TypeScript across frontend and backend systems. You'll design the SDK's Node.js core and public application programming interface (API), and work in the clients that use
Senior Java Software Engineer – Developer Company: The Boeing Company The Boeing Company is looking for a Senior Java Software Engineer – Developer to join the Advanced Ground Architecture team located in Herndon, Virginia, Seal Beach, California, El Segundo, California or Colorado Springs, Colorado . This position will focus on supporting the Boeing Defense, Space & Security (BDS) Software Engineering organization. The Advanced Ground Architecture (AGA) software team is dynamic group of software engineers creating the future of Ground support with the extensibility and adaptability to be used across ALL Boeing programs. The software team is executing this vision through modern software technologies (Java, ReactJS, python, CI/CD pipelines) and methodologies (Scaled Agile). AGA is looking for self-motivated high performers to lead and execute the large scope of Java development needed for the program's vision. The ideal candidates will provide software engineering functions for the design, development, and maintenance of complex, multi-tiered application software systems used to support the command and control of space vehicles. The software engineers will work day-to-day with system and test engineers to implement, test, and document new features and improvements for both web services and applications supporting distributed computing solutions. Position Responsibilities: Develops software in conjunction with agile team leadership including participation at agile events Assists in the execution of DevSecOps processes to deliver software baseline on sprint boundaries. Participates in PI planning as an agile team member Engages with users and other engineers
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role We’re seeking an exceptional Principal-level Offensive Security Engineer focused on deep, hands-on penetration testing of OpenAI’s agent-powered products, infrastructure, and model-integrated application surfaces. You’ll assess complex systems end to end, identify realistic vulnerabilities, validate exploitability and impact, and partner closely with engineering teams to drive durable fixes. This role will be primarily focused on continuously testing our agent-powered products like Codex and Operator. These systems are uniquely valuable targets because they’re rapidly evolving, can perform sensitive actions on behalf of users, and have large, diverse attack surfaces. You will play a crucial role in securing our agents by finding vulnerabilities that emerge from the interactions between the applications, infrastructure, tools, and models that power them. You’ll have the chance to not only find vulnerabilities, but actively drive their resolution, build reusable testing approaches, automate offensive security workflows with cutting-edge technologies, and use your attacker perspective to improve the security of OpenAI’s products. In this role you will: Conduct deep penetration tests of OpenAI’s agent-powered products, including web applications, APIs, cloud services, identity and authorization flows, CI/CD systems, and model-integrated product surfaces. Continuously hunt for exploitable vulnerabilities in the interactions between the appli
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires strong technical ability to reproduce vulnerabilities , deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly. What You’ll Do Vulnerability Intake, Triage & Validation Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. Independently validate, reproduce, severity-score, and document findings. Identify duplicates and maintain a clean vulnerability records pipeline. Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC). Remediation Coordination & SLA Management Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation. Provide detailed reproduction steps, proof-of-concepts, and technical analyses. Track SLAs, remediation progress, regression testing, and systemic improvements. Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance. Bug Bounty & Vulnerability Disclosure Program Management Design and evolve the bug bounty program, including scope, rules, and reward structures. Man
£225K – £325K/yr
Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! As a Manager of Security Engineering, your key responsibilities include: Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues Execute the long-term vision for the Security team in alignment with Cohere’s product and business goals. Collaborate closely with leadership to prioritize high-impact initiatives and strategic customer engagements. Vulnerability Management: Develop and implement enterprise-wide vulnerability management processes and tooling, including identification, prioritization, remediation tracking, and reporting, including customer artifacts Static Application Security Testing (SAST): Establish SAST programs, integrate tools into CI/CD pipelines, and analyze results to identify and remediate security flaws in source code Dynamic Application Security Testing (DAST): Implement DAST methodologies, configure scanning tools, and conduct regular assessments of running applications Penetration Testing: Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform inclu
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Team Product Platform builds and owns the shared foundations the rest of Replit is built on, spanning the full stack so every other team can ship features safely and quickly. Identity & Authorization defines how people, agents, sandboxes, and services prove who they are and what they can do. These systems protect critical product and service interactions across Replit's web product, Agent, enterprise controls, and internal services. Our work is high-leverage and horizontal: when identity and policy are clear, reliable, and easy to adopt, every other team can move faster without rebuilding security controls. We are a small, collaborative team that values curiosity and clear thinking over pedigree, and we work in the open by bringing each other the problem rather than just the request. We care more about how you reason and build than the route you took to get here. About the Role As a Software Engineer , you will design, build, and operate the identity and authorization systems that protect critical interactions on Replit, including Agent acting on behalf of a user or holding their own identity. The work is guided by a few simple questions: Can every protected request prove which workload made it, which principal it represents, and who is acting on that principal's behalf? Can product teams express policy once and trust the same decision across web, mobile, Agent, and internal services? Can enterprise administrators control who can access each workspace, app, connector, and Agent capability without navigating a permission maze as well as having a legible ledger of decisions? Can Agent act for a user across long-running and durable work without receiving broad or long-lived credentials? Are identity and auth
Linux System Administrator Alexandria, VA Secret clearance or higher The Test and Training Enabling Architecture (TENA) program at Leidos is looking to add a Linux System Administrator . Our mission is to develop tools for the United States Department of Defense test and training communities, to increase the speed of the development cycle, to get capabilities to the warfighter more rapidly. The Linux System Administrator will work within a team engineers, developers and system administrators, adding new capabilities to our enclaves, as well as ensuring the existing systems are secure and performing as intended. This position is required to work on-site in our Alexandria, VA office. Primary Responsibilities: Provide support for installing and maintaining Linux servers. Provide technical leadership for migrating on premise infrastructure to hybrid cloud solution. Provide support for troubleshooting from OS to application-level issues. Manage networking equipment including switches, routers and firewalls. Manage configuration and maintenance of core enclave infrastructure services including DCHP, DNS, e-mail, Apache Web Servers, Tomcat application servers, Atlassian applications, MariaDB database servers. Configure and monitor security tools required for DoD networks. Participate and contribute to design discussions related to improving the capabilities, performance and security posture of new and existing services. Basic Qualifications: US Citizen with at least an active Secret clearance. Bachelor’s degree with 4+ years of experience or a Master’s degree with 2+ years of experience. Additional experience may be considered in lieu of a degree. 4+ years of experience providing System Administration to DoD IT systems. DoD 8570 IAT level I
$123.1K – $150.4K/yr
Software Product Security Engineer Description - This role supports the development and maintenance of secure software products under the guidance of senior engineers. The position focuses on learning software engineering and security best practices while contributing to the design, implementation, testing, and maintenance of desktop, web, and cloud-based applications and services. Key Responsibilities Assist in developing, testing, and maintaining software applications and security solutions. Participate in software development activities including coding, debugging, testing, and integration. Support the development and maintenance of Windows desktop applications and services. Assist in developing and maintaining web applications, APIs, and cloud-connected services. Troubleshoot software issues with guidance from senior team members. Write clean, maintainable, and well-documented code. Create and execute unit tests to verify software functionality and reliability. Participate in code reviews and learn software development best practices. Contribute to Agile ceremonies, sprint planning, and team activities. Learn and apply secure coding and software security principles. Support the deployment, monitoring, and maintenance of cloud-based applications and services. Collaborate with cross-functional teams to deliver end-to-end software solutions. Support product release and maintenance activities. Education & Experience Bachelor's or Master's Degree in Computer Science, Software Engineering, or a related discipline. 0-2 years of software development experience. <li
$174.5K – $236.1K/yr
Drata is building the trust layer between great companies - automating compliance, managing risk, and helping organizations prove trust continuously as they scale. We're Dratanauts: a global crew of 600+ professionals united by a culture that rewards integrity, ownership, and raising the bar, no matter where in the world we're working from. Why Join the Drata Team? At Drata, you're not maintaining legacy compliance software - you're building the agentic AI platform defining what trust looks like for the next generation of companies. Here's what makes the work itself worth showing up for: Problems without a playbook: You'll work at the edge of AI and security, building agentic governance, continuous compliance, and real-time trust verification to solve problems that don't have an established answer yet. You're writing it as you go. Real ownership, not just process: Our values center on owning outcomes and raising the bar, not checking boxes. You're expected to have opinions and back them. A seat at the table: Your perspective is unique and valued. Open debate and diverse viewpoints are built into how decisions actually get made here, at every level. Growth at rocketship speed: Drata is scaling fast, which means scope grows fast too. High performers get more ownership, visibility, and experience. A crew, not just coworkers: Dratanauts consistently describe a "come as you are" culture with sharp, curious people—the kind of team that makes hard problems genuinely fun to solve. See what they say here and follow us on LinkedIn for company news, employee stories, and career updates. Job Summary: The Senior Software Engineer II helps lead the platform development by making architecture decisions to ensure we're building clean, maintainable, and beautiful applications. This person is responsible for maintaining, expanding, and scaling our APIs that power our web applications. They develop specifications for moderately complex software programming applications and modify/main
About the Team Full Stack engineers within the Fleet Scheduling team are dedicated to building intuitive and scalable interfaces that empower researchers to efficiently manage AI workloads across some of the largest supercomputers in the world. Our focus is on developing robust, high-performance systems that provide real-time insights, resource tracking, and seamless interaction with complex infrastructure. We aim to optimize resource allocation, minimize operational overhead, and create user-friendly tools that enhance researcher productivity and system transparency. About the Role You will design, develop, and operate web-based systems that provide a powerful and intuitive interface to OpenAI’s supercomputing clusters. You will collaborate closely with researcher, product and infrastructure teams to deliver scalable solutions that enable seamless monitoring, job scheduling, and resource management. This is an opportunity to work at the cutting edge of AI infrastructure, designing tools that scale to exascale workloads while maintaining usability and performance. This role is based in San Francisco, CA. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: Design and develop full-stack web applications to track, monitor, and manage large-scale AI workloads in real time. Collaborate with researchers and infrastructure teams to translate complex operational needs into intuitive UIs and scalable backends. Build data visualization tools (e.g., Gantt charts, dashboards) to provide insights into job scheduling and resource allocation. Optimize backend services to handle massive data throughput while ensuring low-latency performance and high availability. Implement frontend components that provide seamless interactions with scheduling, storage, and compute systems. Ensure system security, reliability, and scalability across globally distributed supercomputing infrastructure. You might thrive i
Other cities to consider
More places hiring for this role
Get new application and web security specialist jobs in United States by email
Daily job updates · Unsubscribe anytime