WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: We're looking for an Application & Development Security Lead to help shape and strengthen secure software development governance across one of the world's largest technology and creative ecosystems. Working within WPP's Digital Security & Risk Management team, you'll partner with engineering, product and platform teams to govern secure-by-design ways of working, improve software security governance, and provide oversight across modern development environments. This role isn't about writing code day-to-day. Instead, you'll influence governance of how secure software is built, deployed and maintained across cloud-native platforms, APIs, AI-enabled applications and global engineering teams. This is an opportunity to influence software security governance at global scale, helping shape how security supports innovation across one of the world's largest and most diverse technology environments. You'll work alongside talented security and engineering professionals while helping build secure, resilient products and platforms for the future. What you'll be doing: Define an
Jobiba hiring network
Application Security Head Jobs
4,781 active opportunities · Updated for October 2026
Fresh results
14 shown
Explore current application security head jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Note: if you are an intern, new grad, or staff applicant, please do not apply using this link and visit our jobs page for those specific postings. Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the Organization Secure Frameworks: We provide security guarantees for common threats, helping teams secure their services by default. We build and maintain core application-layer security libraries and frameworks for development teams, including web security frameworks, cryptography libraries, and other threat mitigations across the Stripe technology stack. More recently, our scope has expanded to protective measures for AI agents. We are a hands-on engineering team that builds security protections and frameworks, rather than conducting security reviews. Core Infrastructure : We’re the home for Stripe's critical tier0 infrastructure systems (Compute, Networking, DocumentDB, Distributed Caching and High assurance engineering). We build the foundational platform for Stripe products and services to allow them to operate at scale. We drive reliability, availability, efficiency and scalability of these systems. Developer Infrastructure : We’re responsible for the productivity of all developers at Stripe. Ensure Stripe’s engineers have a reliable, fast, and easy-to-use inner dev loop to maximize productivity while building everything from low-latency microservices to large-scale data pipelines and machine learning models. Reliability Insights and Excellence : We build tools and frameworks
About Ramp Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. The problems are high-stakes, data-dense, and unforgiving. We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it. About the Role The Product Security team helps make Ramp the most secure place for our customers to collect, manage, and put to work their business’ financial information. Our work centers in three areas: Ramp builds products with an eye for security Ramp detects and responds to threats before they cause harm Security powers Ramp’s growth Check out our Engineering Blog for more on our tech stack, mission and values! What You’ll Do Build security-focused application primitives and integrate them into our existing products Design and deploy platform-level mitigations to common security issues Lead remediation of prioritized issues across our technology stack: collaborating with other engineers to triage and fix vulnerabilities discovered internally, through penetration testing, and through our bug bounty program Partner with engineering teams to design and deploy solutions which are inherently secure Champion the use of tooling (linters, static analysis, posture assessment scanners, query inspectors, etc.) which help Ramp engineers build secure system
Who we are About Privy Our mission is to make privacy and user ownership the default online. To do so, we build simple, flexible APIs and tools for developers that make it easy to build new products on crypto rails. Privy owns the abstractions and infrastructure layer above wallets, integrating across chains, third-party providers, and Stripe products like Treasury and Link. We get to solve hard technical problems while leveraging Stripe's distribution to reach customers like Ramp, Klarna, Deel, Kraken, Hyperliquid, and Fomo — powering experiences for both mainstream users and crypto natives. Learn more about Privy: Privy and Stripe: Bringing crypto to everyone About the team Engineering at Privy is distinguished by: High urgency: Shipping very small iterations, very fast, to learn very quickly. Product taste: Our customers are developers, and to build effective products for them requires technical knowledge - you will often be "the PM". Security mindset: A great portion of our product is trust. While we have a dedicated security team, every engineer brings security to their designs from the start. In practice, we use boring technology like Node, React, and AWS so we can focus our engineering energy entirely on pushing the boundaries of Privy's core product, e.g. through hardware enclaves, multi-region low latency APIs, and blockchain abstractions that are accessible to mainstream developers. What you’ll do As a Security Engineer at Privy, you will help keep a rapidly growing platform secure through hands-on investigation, operational ownership, and building real code to solve real problems. You’ll work across security operations, incident response, application and infrastructure security, and internal tooling. This is not a role limited to reviewing logs and designs or simply escalating findings. You will carry real ownership for the day-to-day work that protects Privy: investigating anomalies, improving security workflows, and building the automa
Security Architect - AI-Powered Security Engineering About the Team The security team at Meesho is like the Avengers to Meesho's S.H.I.E.L.D. When 5% of Indian households shop with us, it’s important to build resilient systems to manage millions of orders every day. We’ve done this, with zero downtime! We value speed over perfection, and see failures as opportunities to become better. By 2030, Meesho will be the world’s most trusted and secure digital ecosystem, operating on an AI-native, Zero-Trust, self-healing architecture. As we shift toward an era where autonomous agents generate and deploy code, we want to ensure our security scales seamlessly with engineering velocity. We place special emphasis on the continuous growth of each team member, fostering a strong 'Founder’s Mindset' that helps us move fast. About the Role We are looking for a highly technical, hands-on Security Architect (Individual Contributor) to guide and lead our AI-Powered Security Engineering charter. In this role, you will bridge the gap between conventional DevSecOps, infrastructure security, and the rapidly evolving landscape of AI. You will optimize our AI-driven Software Development Lifecycle (SDLC) by designing secure-by-default guardrails for both human developers and AI coding agents. Your mission is to ensure near-zero vulnerabilities from application and data security failures reach production. A significant portion of your focus will involve advanced Red Teaming, utilizing LLMs to improve Meesho's security posture, and architecting defenses for our autonomous AI systems against prompt injection, data leakage, and jailbreaking attacks.
About Us: Paytm is India's leading mobile payments and financial services distribution company. Pioneer of the mobile QR payments revolution in India, Paytm builds technologies that help small businesses with payments and commerce. Paytm’s mission is to serve half a billion Indians and bring them to the mainstream economy with the help of technology. Job Summary: We are seeking a highly motivated and skilled Akamai CDN & WAF Engineer with 2-5 years of hands-on experience in configuring, deploying, and managing Akamai's Content Delivery Network (CDN) and Web Application Firewall (WAF) solutions. The ideal candidate will possess a strong understanding of web performance optimization, security best practices, and have a proven track record of implementing and troubleshooting Akamai services in a production environment. This role requires a proactive individual with excellent problem-solving skills and the ability to collaborate effectively with cross-functional teams. Responsibilities: Configuration and Deployment: Configure and deploy Akamai CDN services (e.g., Domain onboarding, delivery rules, caching policies, origin configurations) and WAF rulesets (e.g., security policies, custom rules, DOS and client reputation) based on application requirements and security guidelines. Production Support: Provide day-to-day operational support for Akamai CDN and WAF infrastructure, including monitoring performance, identifying and resolving issues, and implementing necessary changes. Performance Optimization: Analyze website performance metrics and implement Akamai CDN features and configurations to optimize website speed, reduce latency, and improve user experience. Security Implementation: Implement and manage Akamai WAF policies to protect web applications from various security threats, including OWASP Top 10 vulnerabilities, bot attacks, and DDoS attacks. Rule Management: Create, review, and maintain custom WAF rules and exceptions based on application-specific ne
Location Details: At GoDaddy the future of work looks different for each team. Some teams work in the office full-time, others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely. This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings. This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands. GoDaddy is not currently considering candidates for this role in California, Seattle, or NYC. Join Our Team GoDaddy is hiring a Staff Software Engineer to help define and scale our Internal Developer Platform —a centralized system that powers how engineers across the company build, deploy, and operate software. This platform is used by 1,000+ engineers to manage everything from cloud infrastructure and application lifecycle to security, compliance, and cost transparency. In this role, you’ll operate as a technical leader at platform scale, shaping the architecture and direction of systems that directly impact engineering velocity across the company. You’ll work on high-impact initiatives such as AI-powered developer tooling, next-generation API platforms, and the evolution of a unified developer experience spanning APIs, CLI, and UI. This is a high-ownership, high-visibility role where Staff Engineers drive decisions, influence product direction, and partner across infrastructure, security, and platform teams. If you’re motivated by building systems that improve how other engineers work—and want to have a measurable impact on developer productivity at scale—this team sits at the center of GoDaddy’s engineering ecosystem. What You’ll Get to Do... Design and build platform services that power GoDaddy’s internal developer ecosystem, used by 1,000+ engineers. Lead architecture and technical direction for high-scale APIs, infrastructure orchestration,
Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading. About the team + role We are building an elite team, applying frontier technologies to the world's biggest financial problems. We're looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn't a place for complacency, it's where ambitious people do the best work of their careers. We're a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards. The Software Platform team accelerates developer velocity and increases system reliability by building the foundational platforms and tools that power Robinhood engineering. Within this group, the Kubernetes Compute team focuses on building and operating a highly available, scalable Kubernetes-powered container platform. We ensure that our infrastructure seamlessly supports reliable application deployments, integrates core platform capabilities, and enables multi-region scalability. We are expanding our core container systems to support our next phase of technical growth! As a Software Developer, you will focus on building, maintaining, and scaling our container provisioning platforms. Working alongside senior engineers, you will write code to improve our infrastructure capabilities and actively participate in our technical transition to Amazon EKS. In this role, you will collaborate with teams across the organization to ensure robust platform integrations for everyday application needs like security and networking. Your efforts will directly improve system visibility, automation, and reliability across the platform. This role is based in our Toronto office(s), with in-perso
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires strong technical ability to reproduce vulnerabilities , deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly. What You’ll Do Vulnerability Intake, Triage & Validation Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. Independently validate, reproduce, severity-score, and document findings. Identify duplicates and maintain a clean vulnerability records pipeline. Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC). Remediation Coordination & SLA Management Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation. Provide detailed reproduction steps, proof-of-concepts, and technical analyses. Track SLAs, remediation progress, regression testing, and systemic improvements. Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance. Bug Bounty & Vulnerability Disclosure Program Management Design and evolve the bug bounty program, including scope, rules, and reward structures. Man
Application Software Engineer, Phantom Works (Experienced or Senior) Company: The Boeing Company The Boeing Company is looking for an Application Software Engineer (Experience or Senior ) to join the Phantom Works Open Architecture Systems Integrated Software (OASIS) Solutions team located in Berkeley, MO. This position will focus on supporting the Boeing Defense, Space & Security (BDS) Software Engineering organization. Phantom Works is where imagination meets engineering excellence — a place where bold ideas are shaped to transform the future of defense. Driven by curiosity and relentless problem-solving, our team pushes boundaries across aerospace, autonomy, emerging technologies and advanced materials to create breakthrough capabilities that keep people and warfighters safe, and missions successful. With a culture of collaboration, integrity, and rigorous testing, Phantom Works transforms daring concepts into trusted, operational solutions that inspire confidence and expand what’s possible in the skies and beyond. The selected team member will enjoy working collaboratively with others, has commitment to customer satisfaction and process improvement, and is successful working in a multi-contract/multi-program environment. The Application Software Engineer will support the development of solutions to a wide range of complex problems that require ingenuity and innovation. The ideal candidate should be adaptable to new development environments and eager to work with and learn new technologies. Position Responsibilities: Designs, develops, tests, and maintains embedded software throughout the end-to-end lifecycle that meets industry, customer, safety, and regulation standards. Reviews, analy
Role: Security Engineer III Location: Hyderabad, India (Hybrid) Department: Infrastructure/Info Security About GHX: GHX (Global Healthcare Exchange) is a leading healthcare technology company on a mission to simplify the business of healthcare and improve patient outcomes. Founded in 2000, GHX has built the GHX Global Network — the world’s largest cloud-based supply chain community connecting healthcare providers, suppliers, distributors, and partners to automate key processes, reduce costs, and increase operational efficiency. Its solutions span electronic trading, procurement automation, inventory and contract management, business intelligence, and data synchronization, helping healthcare organizations improve productivity and focus more on patient care. Over the years, GHX has enabled significant cost savings for the industry and continues to innovate with intelligent automation and AI-driven capabilities. Website: https://www.ghx.com/ LinkedIn: https://www.linkedin.com/company/ghx/ Role Overview We are seeking a highly skilled Cybersecurity Engineer with 4+ years of experience to secure our production AWS ecosystems and modern AI-driven application pipelines. In this business-critical role, you will take operational ownership of the entire Wiz Cloud Native Application Protection Platform (CNAPP) suite. You will bridges the gap between infrastructure protection and software development by deploying Wiz Code and Wiz Code to Cloud architectures, tracing software defects, vulnerabilities, and hardcoded secrets directly from git environments up to running containerized architectures. Additionally, you will design guardrails protecting LLM structures and pipeline environments from next-generation adversarial patterns. Key Responsibilities Shift-Left Security & Wiz Portfolio Ownership Wiz CNAPP: Architect, configure, and maintain the Wiz CNAPP suite globally across our AWS enterprise structure, leveragin
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you will bridge the gap between security, compliance, DevOps, and Platform engineering teams. You will identify infrastructure misconfigurations, secure multi-cloud environments, and manage continuous vulnerability lifecycles across cloud workloads, containers, and data repositories to satisfy strict regulatory compliance frameworks. You will also serve as a technical infrastructure responder during security incidents, deploying real-time cloud or network countermeasures to protect our production ecosystem. What You'll Do Core Responsibilities Infrastructure Scanning & Triage: Perform continuous security scanning across our cloud posture and workloads. Review, validate, and prioritize flaws and misconfigurations based on CVSS scores, real-world exploitability, and infrastructure network exposure. Posture Management & Visibility : Own and optimize Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), and Data Security Posture Management (DSPM) tools to ensure uniform compliance, prevent data leakage, and maintain hardened baselines. Infrastructure-as-Code (IaC) Security: Configure, tune, and embed automated IaC security scanning tools into CI/CD pipelines to identify architectural risks (e.g., overly permissive IAM, public S3 buckets/Cloud Storage) before they are deployed to production. Workload & Container Security: Manage the continuous vulnerability scanning lifecycle for container images, registries, and Virtual Machines (VMs), partnering with SRE and Platform teams to build aut
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. We are looking for a Security Operations Lead (SOC Lead) to build, mature, and operate our 24/7 detection and response capabilities across a modern cloud-native and AI-driven environment. This role leads the global SOC function—monitoring, SIEM ownership, detection engineering, alert triage, and operational readiness—while also evaluating and integrating emerging AI-based SOC products and autonomous response platforms . You will oversee monitoring across multi-cloud environments (GCP primary, AWS/Azure secondary), Kubernetes, SaaS services, endpoints, developer tools, and AI workloads . You’ll collaborate closely with Cloud Security, Compliance/GRC, SRE, Platform Engineering, IT/Endpoint teams, and AI Infrastructure to ensure our detection strategy scales and stays ahead of evolving threats. This is a hands-on leadership role perfect for someone who wants to shape the SOC of the future while solving complex challenges in a high-scale AI setting. What You’ll Do SOC Leadership & 24/7 Monitoring Lead, mentor, and scale a global SOC team responsible for 24/7 monitoring, alert intake, triage, correlation, and escalation. Build operational rigor: processes, runbooks, SLAs, metrics, and quality standards for high-scale environments. Cover monitoring across: Cloud infrastructure (GCP, AWS, Azure) Kubernetes/GKE/EKS/AKS clusters SaaS platforms (Google Workspace, GitHub, Slack, Okta, etc.) Endpoints (macOS, Linux, Windows) including EDR/XDR telemetry Developer platforms + CI/CD pipelines AI/ML systems and model-serving workflows AI-Based SOC Integration & Innovation Evaluate, adopt, and integrate AI-native SOC technologies for triaging, detection, and correlation Identify opportunities to automate triage, investigations,
About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in. Available Location - Canada; Remote Job Title - Senior Security Compliance Specialist The Team Security Compliance is a critical business function at Cloudflare. Compliance certifications allow our customers to be confident in the security and privacy of our products, while also providing frameworks for well-tuned information security management systems and programs. These standards provide clarity to Cloudflare’s teams on how to incorporate secur
Get new application security head jobs by email
Daily job updates · Unsubscribe anytime