Jobiba hiring network

Application Security Head Jobs

4,781 active opportunities · Updated for October 2026

Fresh results

15 shown

Explore current application security head jobs. Use filters to narrow by work mode, employment type, experience and date posted.

SA
Snorkel AI
📍 San Francisco• Full-time• From $252K/yr
14 days ago

About Snorkel At Snorkel, we believe meaningful AI doesn’t start with the model, it starts with the data. We’re on a mission to help enterprises transform expert knowledge into specialized AI at scale. The AI landscape has gone through incredible changes since 2015, when Snorkel started as a research project in the Stanford AI Lab, to the generative AI breakthroughs of today. But one thing has remained constant: the data you use to build AI is the key to achieving differentiation, high performance, and production-ready systems. We work with some of the world’s largest organizations to empower scientists, engineers, financial experts, product creators, journalists, and more to build custom AI with their data faster than ever before. Excited to help us redefine how AI is built? Apply to be the newest Snorkeler! About Snorkel Snorkel AI is the frontier AI data lab, helping teams build the data and environments behind high-performing frontier and agentic AI. We combine technology with research-driven AI data development to create datasets, benchmarks, evals, and custom solutions for real-world AI systems. Founded out of the Stanford AI Lab in 2019, Snorkel works with leading AI labs and enterprises to move from better data to better outcomes. Excited to help us redefine how AI is built? Apply to be the newest Snorkeler! About The Role Snorkel is hiring a Head of Security to build and lead our security function end-to-end — infrastructure security, application security, and governance, risk & compliance (GRC). You'll own the security function end-to-end — strategy, team, and execution — and operate as the primary security voice with customers, auditors, and the exec team. You'll report to the CTO. This is a builder's role: you'll take security from its current state to a mature, right-sized function as Snorkel scales, hiring and developing the team as needs grow. Key Responsibilities Security Leadership & Team Building Define Snorkel's overall security strategy,

awsci/cdai
View job →
S
1mo ago

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and teams across Europe and the US. As AI continues to shape the way we live and work, Synthesia develops products to enhance visual communication and enterprise skill development, helping people work better and stay at the center of successful organizations. Following our recent Series E funding round, where we raised $200 million, our valuation stands at $4 billion. Our total funding exceeds $530 million from premier investors including Accel, NVentures (Nvidia's VC arm), Kleiner Perkins, GV, and Evantic Capital, alongside the founders and operators of Stripe, Datadog, Miro, and Webflow. Location: Europe remote or London hybrid About the role: As our engineering and research organisation grows, so does the complexity of securing it. Our Application Security team is at the forefront of that challenge — building AI-native security tooling, embedding security into the development lifecycle at scale, and finding ways to make a small, highly capable team punch well above its weight. We're looking for an Engineering Manager to lead and grow the AppSec team. This is not a coordination role. You'll be leading a team of exceptionally senior and staff-level engineers who are deeply self-directed and technically excellent. To earn their trust and enable their best work, you'll need to be genuinely close to the craft — able to engage at depth on threat modelling, agentic security tooling, SDLC design, and application risk. You'll also own AppSec strategy and be accountable for how the function scales alongside a product organisation that is growing fast and leaning heavily into AI-assisted development. Important note: Anyone working as a manager within the Infosec team will need to follow the Infosec Team Management Tenets . Key Responsibilities: Lead, support, enable and grow the AppSec team — owning hirin

javascriptpythonjava
View job →
W
Wellhub
📍 Brazil• Full-time• Remote
14 days ago

Your wellbeing, our mission. Join a company shaping a healthier world. GET TO KNOW US At Wellhub we're revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company. We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally. Join us in redefining the future of wellbeing! THE OPPORTUNITY We are hiring a Senior Security Engineer| AppSec to our Information Security team in Brazil ! This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil. The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery. YOUR IMPACT Own core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability manage

REMOTEawsgcpgit
View job →
C
Cohere
📍 Toronto• Full-time
1mo ago

Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! As a Senior Security Engineer you will: Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues Lead security operation functions – including vulnerability management, SAST, DAST, detection engineering, and incident response – in CI/CD and cloud-native production environments Integrate security into our applications throughout the software development lifecycle Collaborate with product and development teams, driving the success of larger projects to ensure that software is built and deployed securely without compromising agility and speed Driving and supporting bug bounty program, application security reviews and threat modeling, including code review and dynamic testing Assess and integrate security tools to automate and scale security processes, i.e: evaluate open-source vs vendor solutions Gather and analyze security metrics to address security issues with cross-team dependencies Be a problem solver who is empathetic to developer concerns and will employ constructive and flexible approach to building innovative solutions You may be a good fit if: 5

ci/cdgitrest
View job →
C
Coinbase
📍 - USA• Full-time• Remote• From $201.4K/yr
1mo ago

Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase . Coinbase is looking for a Senior Manager, Security Audit to lead the Internal Audit team's global coverage of information security, cybersecurity, and infrastructure/application security. Reporting to the Global Head of Internal Audit, you'll own the security audit portfolio, spanning identity and access management, threat detection, incident response, cloud security, application security, and crypto-native controls (wallets, cold storage, key management), while managing a small team and carrying your own book of complex audits. What you'll do: Own and lead Coinbase's global security audit portfolio covering IAM, threat detection, incident response, security architecture, cryptography/key management, vulnerability management, application security, and crypto-native security (wallets, cold storage), third-party/outsourced security oversight Partner with Security Engineering, Detection & Response, and AppSec teams as the cybersecurity subject matter expert, providing independent audit perspective and advisory value while maintaining third-line objectivity. Manage and develop a team of security auditors while personally leading high-complexity, high-risk security engagements across multiple jurisdictions. Synthesize complex technical security findings into clear, risk-prioritized reports for executive leadership, the Audit Committee, and the Board. Drive proactive i

REMOTEawsgcpai
View job →
P
1mo ago

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. The Product Security team is responsible for managing the security processes, policies and controls to secure Plaid’s developer and consumer facing products.The product security team is focused on areas like Application Security, Vulnerability Management, Secure Development Lifecycle, Penetration Testing and Cloud Security. We build the services and components that protect Plaid’s products. We move security "left" by engineering common libraries, modules, and workflows that make the secure path the easiest path for all Plaid engineers. Plaid is looking for a Product Security Engineer who is a builder to join our Product Security team. Unlike traditional Product security roles, this position is for a Senior software engineer who wants to solve security challenges at scale by designing and building production-grade services, libraries, and frameworks. Our goal is to make the "secure path" the only path for Plaid developers. The Role You will lead, design and develop security capabilities to manage vulnerabilities lifecycle and automate workflows to reduce KTLO toil. You will own, maintain, and build Plaid’s VM Orchestration service and build solutions to eliminate the entire vulnerability classes. You

awskubernetesci/cd
View job →
C
Cohere
📍 San Francisco• Full-time• £225K – £325K/yr
1mo ago

Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! As a Manager of Security Engineering, your key responsibilities include: Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues Execute the long-term vision for the Security team in alignment with Cohere’s product and business goals. Collaborate closely with leadership to prioritize high-impact initiatives and strategic customer engagements. Vulnerability Management: Develop and implement enterprise-wide vulnerability management processes and tooling, including identification, prioritization, remediation tracking, and reporting, including customer artifacts Static Application Security Testing (SAST): Establish SAST programs, integrate tools into CI/CD pipelines, and analyze results to identify and remediate security flaws in source code Dynamic Application Security Testing (DAST): Implement DAST methodologies, configure scanning tools, and conduct regular assessments of running applications Penetration Testing: Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform inclu

pythonawsazure
View job →
W
10 days ago

WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: The Business Intelligence Developer drives the design, development, and maintenance of Power BI dashboards and reports used across AUNZ Finance and Operations. This role bridges data and stakeholders - translating requirements into intuitive, actionable dashboards, providing first-level support to end users, and delivering ad hoc analysis in partnership with the Head of Data & Analytics. What you'll be doing: KRA 1 Dashboard Design & Development Translate business requirements into intuitive, visually compelling Power BI dashboards and reports. Create wireframes and proof-of-concepts aligned with requirements, adhering to design standards. Develop custom visuals where native Power BI functionality does not meet business needs. Maintain quality control standards across own projects prior to release. KRA 2 Data Modelling & Security Design and refine data models underpinning dashboards, building on curated datasets. Implement and maintain row-level and application-layer security to ensure appropriate data access. Manage and monitor scheduled data refreshes, proactively resol

sqlPower BIfinance
View job →
A
Anyscale
📍 Remote• Full-time• Remote
1mo ago

Senior Cloud Security Engineer At Anyscale , we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We’re commercializing Ray , a popular open-source project that's creating an ecosystem of libraries for scalable machine learning. Companies like OpenAI , Uber , Spotify , Instacart , Cruise , and many more, have Ray in their tech stacks to accelerate the progress of AI applications out into the real world. With Anyscale, we’re building the best place to run Ray, so that any developer or data scientist can scale an ML application from their laptop to the cluster without needing to be a distributed systems expert. Proud to be backed by Andreessen Horowitz, NEA, and Addition with $250+ million raised to date. About the Role Anyscale's security needs are growing as we operate more production and cloud infrastructure for larger and more demanding customers. We're looking for a Senior Cloud Security Engineer to own the security of that infrastructure. This is a hands-on, high-ownership role: you will own how our production and cloud environments are hardened, isolated, and monitored. You will set and drive the direction for infrastructure and production security, reporting to the Head of Security and partnering closely with the wider engineering organization. This role is based in the San Francisco, Bay Area. In your first year, success looks like hardened and well-segmented production environments, strong runtime security coverage across our container footprint, and a clear, defensible story for how we secure the infrastructure our customers rely on. What You'll Do Own the security posture of Anyscale's production and cloud infrastructure across AWS and Azure, including hardening, network segmentation, and tenant isolation. Own runtime security coverage across our Kubernetes environments, from deployment through detection of anomalous activity. Partner with engineering on secure infrastructure architectur

REMOTEawsazurekubernetes
View job →
A
1mo ago

At Anyscale , we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We’re commercializing Ray , a popular open-source project that's creating an ecosystem of libraries for scalable machine learning. Companies like OpenAI , Uber , Spotify , Instacart , Cruise , and many more, have Ray in their tech stacks to accelerate the progress of AI applications out into the real world. With Anyscale, we’re building the best place to run Ray, so that any developer or data scientist can scale an ML application from their laptop to the cluster without needing to be a distributed systems expert. Proud to be backed by Andreessen Horowitz, NEA, and Addition with $250+ million raised to date. About the Role Anyscale's product security needs are growing as we ship to larger and more demanding customers. We're looking for a Senior Product Security Engineer to own our secure software development lifecycle and to be engineering's partner on building security into the product. Reporting to the Head of Security, you will work in close partnership with engineering. This is a senior, high-ownership role. You will own and operate a scalable SSDL, partner with engineering on security features and secure design, review the security of existing systems and new initiatives, and own how we find, track, drive to resolution and report on vulnerabilities in what we ship. This role is based in India. In your first year, success looks like an SSDL that scales with engineering rather than gating it, security review embedded in how new initiatives ship, and accurate, on-demand vulnerability reporting backed by a working path to resolution. What You'll Do Own and operate a scalable secure software development lifecycle: threat modeling, security requirements, secure design practices, and scanning that engineering can readily adopt. Partner with engineering on security features and secure-by-design architecture, from early design through i

machine learningaisupply chain
View job →
R
Replit
📍 Foster City• Full-time
1mo ago

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit is building the security GRC function that will scale with an AI-native product. As the Risk & Compliance lead, you'll own our certification and audit program end to end: SOC 2, ISO 27001, and eventually ISO 42001 (AI management systems), while also owning the company's master security risk register and continuous compliance monitoring. You'll report to the Head of Security GRC, who retains overall accountability for the risk program, and work closely with Engineering to make sure controls hold up in practice, not just on paper. What You'll Do Own the end-to-end certification roadmap (SOC 2 Type II, ISO 27001, and future frameworks like ISO 42001) including scoping, gap assessments, remediation, and audit execution Manage relationships with external auditors and drive the annual audit calendar so certifications renew without last-minute scrambles Own and maintain the company's master security risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting Build and maintain continuous compliance monitoring so control status reflects real-time state rather than point-in-time snapshots Own the core audit artifacts that back every certification including ISMS documentation, Statements of Applicability, risk assessments, and potentially FedRAMP System Security Plans (SSPs) Run regular audits and readiness assessments, and track remediation of findings and control gaps to closure Support GDPR and broader privacy compliance alongside the Legal/Privacy team, without owning the legal interpretation of requirements Partner with the GRC Engineer to define what evidence collection and control monitoring should be automated versus manually reviewed Track and

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit’s ecosystem is powered by an expanding array of external services and essential AI model partners. As our lead for Security Vendor Risk & Contract Reviews, you will architect and execute a risk management program focused on substantive evaluation rather than just processing checklists. You’ll analyze SOC 2 documentation, security assessments, and system architectures to determine actual risk profiles, collaborating with our Legal team to secure necessary contractual protections. This role reports to the Head of Security GRC and involves high-impact partnerships across Legal, Engineering, and Product teams. What You'll Do Run substantive third-party risk management (TPRM), independently evaluating real risk, not just processing questionnaire responses Review SOC 2 reports, pen test findings, and architecture documentation to form an independent view of vendor risk, extending the same rigor to AI/model providers Partner with Legal on vendor and AI contract terms, including DPAs, subprocessor agreements, and AI-specific provisions Review contracts for non-standard security language when flagged by Legal or deal desk, and recommend redlines Maintain the vendor and AI/model risk register, feeding findings into the company's master risk register Enable sales through maturing the customer trust program Build the capability for continuous monitoring of vendor ecosystem Required Skills & Experience 8+ years in third-party/vendor risk management, security risk, or a related GRC role Demonstrated ability to independently assess vendor risk rather than relying on questionnaire responses alone, fluent in reading SOC 2 reports, ISO certificates, pen test summaries, and architecture documentation Experi

aigorust
View job →
A
1mo ago

At Anyscale , we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We’re commercializing Ray , a popular open-source project that's creating an ecosystem of libraries for scalable machine learning. Companies like OpenAI , Uber , Spotify , Instacart , Cruise , and many more, have Ray in their tech stacks to accelerate the progress of AI applications out into the real world. With Anyscale, we’re building the best place to run Ray, so that any developer or data scientist can scale an ML application from their laptop to the cluster without needing to be a distributed systems expert. Proud to be backed by Andreessen Horowitz, NEA, and Addition with $250+ million raised to date. About the Role Anyscale's need to detect and respond to security events across its production and corporate environments is growing as the company scales. We're looking for a Senior Detection and Response Engineer to own detection engineering and to lead incident response when it counts, coordinating the response and driving it to resolution. This is a high-ownership role with real room to shape how detection and response works at Anyscale. You will own the detection pipeline, the response runbooks, and incident response, reporting to the Head of Security and partnering with engineering. This role is based in India. In your first year, success looks like strong detection coverage across our cloud, endpoint, and runtime telemetry, a working correlation and alerting pipeline, and incident response runbooks that have been exercised in practice. What You'll Do Own and build detection coverage across cloud, endpoint, and runtime telemetry. Own a centralized correlation and alerting capability that turns telemetry into actionable detections. Own incident response: runbooks, escalation paths, and coordination during an incident, across corporate and production environments. Drive detection of anomalous activity across the environments

awsazurekubernetes
View job →
A
Anyscale
📍 Remote• Full-time
1mo ago

At Anyscale , we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We’re commercializing Ray , a popular open-source project that's creating an ecosystem of libraries for scalable machine learning. Companies like OpenAI , Uber , Spotify , Instacart , Cruise , and many more, have Ray in their tech stacks to accelerate the progress of AI applications out into the real world. With Anyscale, we’re building the best place to run Ray, so that any developer or data scientist can scale an ML application from their laptop to the cluster without needing to be a distributed systems expert. Proud to be backed by Andreessen Horowitz, NEA, and Addition with $250+ million raised to date. About the Role Anyscale's security and compliance needs are growing as we work with larger and more demanding customers. Compliance is increasingly a customer-facing, contractual function rather than an internal exercise, and we are looking for someone to own it. This role owns that function end to end: our audits, our evidence base, our risk register, and the security diligence that customers put us through before and during a contract. You will work directly with the Head of Security and across engineering, IT, legal, and sales. This is a program-ownership role with the autonomy and accountability that implies. You will not have a senior compliance function above you to defer to; you are that function. In your first year, success looks like a complete and defensible evidence base with clean audit outcomes, a repeatable way to answer customer security diligence, and a risk register that leadership actually uses. What You'll Do Own our SOC 2 Type II and ISO 27001 programs, and future frameworks as we take them on, including scope, evidence, control operation, and the relationship with our external auditors. Own and complete the control evidence base in our compliance automation platform, moving controls from partially substantia

machine learningaigo
View job →
🔔

Get new application security head jobs by email

Daily job updates · Unsubscribe anytime