About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments. We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization. The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: Perform Security Assessments : Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software. Develop and Implement Security Tools : Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats. Collaborate with Development Teams : Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines. Threat Modeling and Risk Assessment : Conduct threat modeling and risk
Jobiba hiring network
Application Security Engineer Jobs
4,781 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current application security engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments. We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization. The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: Perform Security Assessments : Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software. Develop and Implement Security Tools : Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats. Collaborate with Development Teams : Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines. Threat Modeling and Risk Assessment : Conduct threat modeling and risk
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments. We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization. The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: Perform Security Assessments : Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software. Develop and Implement Security Tools : Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats. Collaborate with Development Teams : Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines. Threat Modeling and Risk Assessment : Conduct threat modeling and risk
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Director of Engineering for the Application, Cloud and Offensive security teams in the Security Engineering organization. Snowflake is the AI Data Cloud powering enterprises worldwide to store, process, and build intelligent applications on their most sensitive data. As AI has become more deeply embedded in what Snowflake and its customers do, the threat landscape has evolved at the same pace. This Director role was created directly in response to that convergence: a wide mandate with real influence across three security pillars and the visibility to shape how one of the most consequential technology platforms in the world stays ahead of emerging threats. AS A DIRECTOR OF ENGINEERING AT SNOWFLAKE, YOU WILL: Define and execute the security strategy across three core pillars: application security, cloud security assurance, and offensive security (including the red team program), setting direction and driving measurable outcomes across all three pillars. Build and develop a high-performing security engineering organization, hiring top talent and creating a culture of rigor, ownership, and continuous improvement Drive the offensive security program including red team operations, adversarial simulations, and proactive threat modeling to stay ahead of emerging att
About Backblaze Backblaze provides reliable, high-availability cloud storage trusted by consumers, SMBs, enterprises, and developers in over 150 countries. Backblaze B2 Cloud Storage supports data-intensive workloads including backup, media, analytics, and modern AI pipelines. Our teams focus on building secure, durable, scalable systems with a strong emphasis on application security from day one and protecting customers to keep them safe. But while there is a lot to celebrate in our past, there is almost as much opportunity ahead of us. About the Role We are seeking an Application Security Engineer to improve application security across the software used to enable Backblaze B2 Cloud Storage and Computer Backup. The primary role is to build security into how the product is used, how data is stored and how customers can use it. This role will require development skills and application security knowledge to build security into the product and new features. Leveraging AI is key. This is a hands-on role that requires application development knowledge. This role is expected to know and use the latest AI to help with both development and security. The primary requirements include; development in common web languages, application security and AI tool usage. Leverage AI tools and software for Building new and maintaining existing software security features Meeting evolving software security needs in existing software Developing new components as needed Perform security assessments and code reviews on internal and external customer-facing applications Work closely with engineers to remediate security vulnerabilities using AI tools Develop security automation and tooling to improve security Support bug bounty program and vulnerability handling Investigate newly reported vulnerabilities Determine ways to remediate them Provide guidance to engineering based on known vulnerabilities found in existing applications Understanding cryptography and secure authentication Knowled
Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase . As an Offensive Security Engineer on the Application Security team within Security, you'll pioneer how Coinbase uses frontier AI models to scale vulnerability discovery, red team AI systems, and automate security workflows. This role bridges traditional penetration testing with next-generation AI-augmented offensive security, directly accelerating our ability to protect products and customers. You'll own the development of AI-driven security tooling and collaborate across Vulnerability Management, Offensive Security, and Incident Response to fundamentally shift how we operate. What you'll do: Build, deploy, and maintain custom security scanners that leverage frontier models to detect vulnerabilities at scale across Coinbase's product surface. Lead red teaming efforts against internal AI systems, including jailbreak testing, prompt injection analysis, and tool abuse simulation. Develop AI-driven automation for vulnerability triage, validation, and remediation workflows to accelerate the bug bounty and vulnerability response pipelines. Partner with engineering teams to prioritize, remediate, and verify fixes for critical vulnerabilities discovered through AI-augmented and manual testing. Mentor junior security engineers on integrating AI into offensive security workflows to scale team capabilities. Required Skills and Experience: 3+ years of experience in application s
CLEAR is building THE secure identity company of the future. Our mission is to make experiences safer and easier—physically and digitally. With more than 43 million Members and a growing network of partners across the world, CLEAR's secure identity platform is transforming the way people live, work, and travel. Whether it’s at the airport, stadium, or throughout your everyday life, CLEAR unlocks the magic of frictionless experiences. We are seeking a Senior Product Security Engineer to serve as a technical leader and strategic contributor within our Product Security team. This role goes beyond execution — you will drive the evolution of CLEAR’s application security posture by influencing architecture, shaping security engineering processes, and mentoring team members in security and engineering. You’ll lead security initiatives across the organization and help embed security into every stage of our software development lifecycle. What you'll do: Drive security strategy and implementation across all CLEAR products and engineering teams, ensuring consistent protection of customer and business-critical assets. Partner with engineering leadership to align application security initiatives with company-wide technology and product roadmaps, balancing innovation with risk mitigation. Provide technical leadership across CLEAR’s application security initiatives, guiding architecture, design, and development to meet high security standards. Serve as a trusted advisor to cross-functional teams — including Engineering, DevOps, Product, GRC, and IT — enabling secure-by-design practices across the organization. Design and drive implementation of scalable automated security controls and testing frameworks integrated into CLEAR’s CI/CD pipelines. Lead complex threat modeling, architecture reviews, and risk assessments across high-value systems and platforms, driving meaningful security outcomes. Engage with CLEAR's customers to provide insight and support their fraud and ident
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem. What You'll Do Core Responsibilities Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure. Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals. Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture. Software Supply Chain Security: Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security. Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws. Tooling Integration: Configure and tune automated security te
About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in. Job Title - Product Security Engineer Available Location - Bengaluru, India Role Summary As a Product Security Engineer, you will support security assessments and vulnerability operations for Cloudflare’s core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SL
About Forma.ai: Forma.ai is a Series B startup that's revolutionizing how sales compensation is designed, managed and optimized. We handle billions in annual managed commissions for market leaders like Edmentum, Stryker, and Autodesk. Our growth has been fuelled by our passion for fundamentally changing and shaping how companies use sales intelligence to drive business strategy. We’re welcoming equally driven individuals who are excited about creating something big! The Opportunity As a Staff Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems, and incident-response practices. Security today is shared across Engineering and DevOps. You'll work closely with both teams and have real room to shape how Forma approaches security as we grow. Depending on your interests and the needs of the business, the role could develop into a deeper individual-contributor position or help build a dedicated security team. You'll work directly with Engineering, DevOps, IT, Product, Legal, and Privacy to identify risks, design practical controls, automate security processes, and help teams ship secure and reliable software. What you'll do Cloud and infrastructure security Design and implement security controls across Forma's AWS environments, with a focus on IAM, least-privilege access, service identities, and account boundaries. Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management. Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services. Application, data, and AI security Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations
About the Role We’re looking for a Product Security Engineer to join our team and help strengthen how security is built into Supabase’s products, platform, and engineering workflows as we continue to scale. You’ll work closely with software engineers, infrastructure teams, and technical leadership , helping us proactively reduce risk earlier in the development lifecycle and ship securely by default. This role is ideal for someone who thrives in async, fast-paced environments and is excited about building developer tools that scale to millions. Success in this role means improving the security posture of the product without becoming a blocker to speed, autonomy, or builder velocity. What You’ll Own In this role, you’ll: Identify and close gaps across application security, secure design review, and vulnerability management. Conduct threat modeling, secure design reviews, and code reviews to identify practical remediation paths. Partner closely with engineering teams to provide product-focused security expertise and shape a modern security program. Mature how we think about security in a developer-first environment, balancing pragmatism with strong technical judgment. Distinguish between theoretical risk and material business risk to prioritize security efforts effectively. Improve security posture through scalable mechanisms like tooling, automation, secure defaults, and developer-friendly guardrails. Support security incident response by helping triage, investigate, and coordinate remediation for product and platform security issues. Participate in security on-call rotations, helping respond to urgent security events with clear judgment and calm execution. Help manage and mature our bug bounty and vulnerability disclosure processes, including triage, validation, prioritization, and coordination with engineering teams. You Might Be a Good Fit If You Have strong experience in product security, application security, or security engineering. Are comfortable working with
About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in. Available Locations: Austin, TX Role Summary As a Product Security Engineer, you will support security assessments and vulnerability operations for Cloudflare’s core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SLAs. On any given day, you might conduc
As a Platform Security Engineer you will partner with different stakeholders across the organization to secure our infrastructure and application components of the Datadog platform. As part of the Platform Security organization we secure the building blocks of Datadog’s applications and infrastructure. We do this by building solutions solving systemic risks making the secure path easier and the insecure path harder. At Datadog, we place value in our office culture - the relationships that it builds, the creativity it brings to the table, and the collaboration of being together. We operate as a hybrid workplace to ensure our employees can create a work-life harmony that best fits them. What You’ll Do: Solve our most challenging cloud infrastructure security & application security problems starting with our core building blocks and golden paths. Enable our engineers to build and ship secure solutions quickly. Build and extend Datadog’s Platform Security solutions. Leverage and influence the direction of Datadog’s products to secure our infrastructure, and provide internal feedback that enables our teams to improve the products for ourselves and our customers. Who You Are: You have a BS/MS/PhD in a Computer Science, Engineering or related scientific field or equivalent professional experience. You don’t want to just provide security recommendations, you want to help implement solutions to solve systemic issues. Passionate about advocating for and implementing solutions to complex security problems, at-scale, in a large multi-cloud self-managed Kubernetes environment. Proven experience in securing enterprise SaaS applications including securing the underlying authentication flows, authorization patterns, and input validation at API boundaries. Demonstrated experience in securing the deployment & management mechanisms for software and infrastructure changes. Familiarity with common security frameworks such as OWASP, MITRE ATT&CK, PAST
Your wellbeing, our mission. Join a company shaping a healthier world. GET TO KNOW US At Wellhub we're revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company. We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally. Join us in redefining the future of wellbeing! THE OPPORTUNITY We are hiring a Senior Security Engineer| AppSec to our Information Security team in Brazil ! This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil. The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery. YOUR IMPACT Own core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability manage
Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! As a Senior Security Engineer you will: Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues Lead security operation functions – including vulnerability management, SAST, DAST, detection engineering, and incident response – in CI/CD and cloud-native production environments Integrate security into our applications throughout the software development lifecycle Collaborate with product and development teams, driving the success of larger projects to ensure that software is built and deployed securely without compromising agility and speed Driving and supporting bug bounty program, application security reviews and threat modeling, including code review and dynamic testing Assess and integrate security tools to automate and scale security processes, i.e: evaluate open-source vs vendor solutions Gather and analyze security metrics to address security issues with cross-team dependencies Be a problem solver who is empathetic to developer concerns and will employ constructive and flexible approach to building innovative solutions You may be a good fit if: 5
Get new application security engineer jobs by email
Daily job updates · Unsubscribe anytime