Jobiba hiring network

Application Security Head Jobs

4,774 active opportunities · Updated for October 2026

Fresh results

15 shown

Explore current application security head jobs. Use filters to narrow by work mode, employment type, experience and date posted.

About the Team The Solutions Engineering team is made up of trusted technical advisors who help organizations adopt OpenAI’s technology safely, effectively, and responsibly. We partner closely with customers, Sales, Product, Engineering, and Security to translate frontier AI capabilities into practical workflows that create real-world impact. Cybersecurity is one of the most urgent areas where AI can help. As frontier models become more capable at reasoning over code, logs, infrastructure, and security evidence, organizations need guidance on how to evaluate, validate, and deploy these systems safely. Our goal is to help customers move from identifying risks to implementing solutions. About the Role We are committed to bringing together people from diverse backgrounds and perspectives who are excited to help build and deploy safe, useful AI. We are seeking a solutions engineer to partner with our Enterprise customers and ensure they achieve tangible business value from our models through the OpenAI suite of products. You will partner with senior business stakeholders to understand their pre-sales needs, guide their AI strategy, and identify the highest value use cases and applications. You will work with business and technical teams to demonstrate the value of our solutions and recommend architectural patterns to kickstart their implementation and development. You will work closely with Enterprise Sales, Security, and Product teams. We are looking for a Field Security Specialist to help security leaders and hands-on practitioners understand how OpenAI models, APIs, Codex, and agentic workflows can be applied to real cybersecurity use cases. This is a customer-facing specialist role for someone who can move fluidly between CISO-level conversations, practitioner-level technical depth, and hands-on solution design. You’ll help customers evaluate OpenAI for workflows like secure code review, vulnerability triage, threat modeling, remediation, SOC workflows, detection en

awsci/cdgit
View job →
O
OpenAI
📍 Washington• Full-time
1mo ago

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector. As a Forward Deployed Security Engineer (FDSecE) you will be responsible for securing these novel applications of OpenAI’s technology. We’re looking for motivated, tenacious, and curious people who will work closely with engineering teams to ensure our infrastructure deployments are highly secure against our adversaries. As an FDSecE, you will embed directly throughout the lifecycle, working on-site and being hands-on to ensure the overall security of these deployments from design to production and through ongoing operations. This role is preferred to be based in Washington DC but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. Travel to and working from customer sites is required for this role. In this role, you will: Deeply embed with our most strategic public sector customers to implement and maintain robust security controls. Be a design and technical thought partner by leveraging security expertise on protective controls including access controls, authentication, encryption, network, and system security. Collaborate closely with teammates, cross-functional teams, customers, and service providers to achieve security and compliance goals. Ensure continuity of critical security and monitoring c

pythonawsazure
View job →
PE
1mo ago

Role Summary We are seeking an experienced SOC / Security Operations Lead to oversee and strengthen the organization's Security Operations Center (SOC), threat detection, incident response, vulnerability management, data protection, and security monitoring capabilities. The ideal candidate will possess extensive experience in managing enterprise security operations, SIEM/SOAR platforms, threat hunting, incident response, DLP, endpoint security, and vulnerability management programs. The role requires leadership of a multi-functional security operations team responsible for protecting critical business systems, customer data, and digital assets while ensuring compliance with RBI regulations and industry security standards. Key Responsibilities Security Operations Center (SOC) Management -Lead and manage 24x7 Security Operations Center (SOC) functions. -Establish and enhance SOC processes, playbooks, escalation procedures, and operational metrics. -Ensure timely detection, triage, investigation, containment, and remediation of security incidents. -Develop SOC maturity roadmaps aligned with industry best practices and regulatory expectations. -Monitor security KPIs, SLAs, MTTR, MTTD, and incident response effectiveness. SIEM, XSIAM & Threat Detection -Lead implementation, administration, and optimization of: -Palo Alto Cortex XSIAM -SIEM Platforms -SOAR Platforms -UEBA Solutions -Threat Intelligence Platforms -Develop and tune correlation rules, detection logic, and analytics use cases. -Enhance detection coverage across cloud, endpoints, applications, networks, and third-party environments. -Drive threat hunting and proactive security monitoring initiatives. Incident Response & Threat Management -Lead enterprise cyber incident response activities. -Develop and maintain incident response plans, runbooks, and communication procedures. -Coordinate investigations involving malware, ransomware, phishing, insider threats, account compromise, fraud, and adv

RH
RVO Health
📍 Denver• $100K – $130K/yr
12 days ago

Healthcare is complex. We’re here to change that. RVO Health is a health technology company on a mission to make health easier to navigate, more accessible, and more affordable for everyone. Here, you'll help over 40 million people every month, with a team that genuinely cares about the work and each other. AT A GLANCE RVO Health is a first-of-its-kind comprehensive consumer healthcare platform that meets people where they are in their personal journeys and connects them with both the information and the care they need. RVO Health is a partnership between Red Ventures and UnitedHealth Group. Together we're focused on delivering on our vision of a stronger and healthier world. RVO Health has the largest consumer health and wellness audience online. Every month, we help nearly 100 million people take steps on their daily journey to lifelong well-being. As part of our RVO Health Security team, you will play a major part in strategic initiatives that improve our security posture and protect our sensitive data. You will work in a collaborative Agile environment, working closely with the business, IT, and engineering teams. You will apply your skills in a highly dynamic, innovative, cloud-native environment with a strong security-minded culture. Where You'll Be Location: Denver, CO | Hybrid We believe great collaboration happens when we're together, solving problems, learning from each other, and connecting as a team. That's why we’re in our offices Tuesday through Thursday each week. You are welcome to work remotely Mondays and Fridays if you wish. Address: 1801 California St. Denver, CO 80202 What You’ll Do Design, implement, and maintain security controls and architectures to protect the company's cloud infrastructure, applications, and data from cyber threats. Improve our cloud security posture and vulnerability management program — pull-request scanning, triage and tracking of findings to closure across engineering teams, and coverage and license optimization. Build

awsazureai
View job →
Z
Zscaler
📍 Denver• Full-time• From $124K/yr
17 days ago

Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform. We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler. Role We are looking for a Senior Enterprise Applications Administrator to join our team. This is a hybrid role in San Jose, CA or Remote in Denver, CO, reporting to the Collaboration Solutions Manager in the IT Digital Employee Experience department. In this position, you will support and assist in driving the visionary innovation of Zscaler over the next decade, shaping the future of our technology across collaboration applications and the emerging AI space. You will work closely with support and executive support teams while leading a team to deliver cutting-edge services into both enterprise and FedRAMP environments. What you’ll do (Role Expectations) Develop and articulate the strategic vision for Google Workspace and MS365, aligning with organizational goals and industry best practices, while collaborating with our compliance team on FedRAMP compliance Lead the design, implementation, and optimization of Goog

awsgitagile
View job →

We are hiring a Security Software Engineer to design and implement the hardware-backed security foundations used across OpenAI’s device ecosystem. A central focus of this role is hardening the boundary between our policy systems and the HSMs that protect sensitive cryptographic keys. This boundary determines which operations may be performed, what may be signed, which policies must be satisfied, and how changes to trusted software and policy are authorized. You will develop security-critical software and firmware within, or immediately adjacent to, an HSM trust boundary. Depending on your background, this may include HSM trusted applications, firmware services, cryptographic mechanisms, device drivers, PKCS#11 components, secure-provisioning protocols, or signing-policy enforcement systems. This is a hands-on software-engineering role. You will be expected to design systems, write and review production code, debug across hardware and software boundaries, and carry projects from initial requirements through deployment. It is not an HSM administration, PKI operations, compliance, or architecture-only position. In This Role, You Will Design and implement security-critical software and firmware for HSMs, secure elements, trusted execution environments, and hardware roots of trust. Build and harden the policy-to-HSM boundary responsible for authorizing certificate issuance and cryptographic signing operations. Develop HSM trusted applications, firmware components, host interfaces, device drivers, SDKs, or cryptographic service integrations. Implement or extend cryptographic interfaces such as PKCS#11, OpenSSL providers or engines, platform key-storage APIs, or comparable hardware-security interfaces. Build firmware and software that cryptographically enforces key generation, provisioning, usage, rotation, recovery, and destruction policies. Design and implement HSM-backed certificate authority, code-signing, key-management, and device-identity systems. Develop end-to-end

awsgitrest
View job →
F
Flexport
📍 United States• Full-time• From $165.4K/yr
1mo ago

About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do Identity & access Advance our identity posture: SSO coverage, phishing-resistant MFA rollout, SCIM lifecycle automation, and least-privilege access across the SaaS and cloud estate. Build the detections and guardrails that catch account takeover, MFA fatigue attacks, and session token theft before they turn into incidents. Endpoint & device lifecycle Write and ship device policy as code — configuration profiles, remediation scripts, and enforcement rules across macOS and Windows — with staged rollout and rollback built in from day one. Maintain and improve our EDR stack's detection and response coverage across the fleet. SaaS posture Reduce SaaS risk at scale through SSPM tooling and automation , including detection of risky OAuth grants, shadow IT, and configuration drift across our critical SaaS applications. Own security configuration for the SaaS tools hundreds of Flexporters use daily (Google Workspace, Slack, and similar), and keep pace as we add AI agents and MCP integrations to that surface. Automation & enablement Automate the parts of corporate security that don't need a human — device provisioning, access reviews, vendor securi

pythonrestagile
View job →
G
Godaddy
📍 India• Full-time
1mo ago

Location Details: Remote, India At GoDaddy the future of work looks different for each team. Some teams work in the office full-time; others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings Join Our Team... GoDaddy’s Product Security team is looking for a Security Engineer who is passionate about helping build secure products and services used by millions of customers worldwide. In this role, you will work closely with engineering and platform teams to identify security risks, improve security practices, and help embed security throughout the software development lifecycle. You will have the opportunity to learn from experienced security professionals while contributing to initiatives that improve the security and resilience of our products, platforms, and cloud environments. The ideal candidate is curious, hands-on, eager to learn, takes ownership of their work, and excited to solve security challenges at scale! What you'll get to do... Identify, assess, and help remediate security risks across applications, infrastructure, cloud environments, and AI-enabled services Partner with engineering and platform teams to design, implement, and improve security controls throughout the software development lifecycle Conduct security reviews, threat modelling, and risk assessments to help build secure, resilient, and scalable systems Develop and enhance automation, tooling, and processes that strengthen security coverage, improve detection and response capabilities, and increase operational efficiency Investigate security findings, stay informed on emerging threats and technologies, and contribute to a culture of security awareness and continuous learning Your experience should include... 2+ yea

pythonjavaaws
View job →
F
Flexport
📍 San Francisco• Full-time• From $165.4K/yr
1mo ago

About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do Identity & access Advance our identity posture: SSO coverage, phishing-resistant MFA rollout, SCIM lifecycle automation, and least-privilege access across the SaaS and cloud estate. Build the detections and guardrails that catch account takeover, MFA fatigue attacks, and session token theft before they turn into incidents. Endpoint & device lifecycle Write and ship device policy as code — configuration profiles, remediation scripts, and enforcement rules across macOS and Windows — with staged rollout and rollback built in from day one. Maintain and improve our EDR stack's detection and response coverage across the fleet. SaaS posture Reduce SaaS risk at scale through SSPM tooling and automation , including detection of risky OAuth grants, shadow IT, and configuration drift across our critical SaaS applications. Own security configuration for the SaaS tools hundreds of Flexporters use daily (Google Workspace, Slack, and similar), and keep pace as we add AI agents and MCP integrations to that surface. Automation & enablement Automate the parts of corporate security that don't need a human — device provisioning, access reviews, vendor securi

pythonrestagile
View job →
R
Roblox
📍 San Mateo• Full-time• From $196.8K/yr
1mo ago

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in the offensive security assessments that strengthen our defense capabilities. Working closely with the larger InfoSec team, detection engineers, and external engineering partners, you'll identify security weaknesses, validate detection mechanisms, and provide actionable recommendations to enhance our security posture. You'll collaborate with various architecture and engineering teams to continuously validate and improve our security controls and detection capabilities, with a strong focus on developing repeatable testing frameworks and metrics-driven security improvements. You Have: 4+ years: of relevant professional experience in offensive security, with demonstrated experience in purple team exercises, breach attack simulation, and detection engineering collaboration. Development experience: proficiency in Python or Go for building security tooling and automation, including experience with SOAR platforms and configuration management. Security assessment expertise: performing full-stack security assessments of web applications, APIs, cloud infrastructure, and backend systems. Platform expertise

pythonawsazure
View job →
T
Twilio
📍 - United Kingdom• Full-time• Remote
1mo ago

Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work , and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. . Hiring and how we work We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! Also, while we are a remote-first company, you may be asked to report in person on an ad-hoc basis for team gatherings, functional off-sites or customer meetings. . See yourself at Twilio Join the team as Twilio’s next Security Engineer, Incident Response About the job The Security Incident Response Team (SIRT) is looking for a Security Engineer who is passionate about solving Twilio’s mission of security and reliability by working across the organization to lead the technical response to security events and incidents across Twilio’s global infrastructure, services and applications by effectively conducting triage, containment, remediation and driving post-incident betterments. You will work within a team that partners with R&D Engineering and R&D Business teams to develop scalable processes and technical solutions. You will be a valued member of a team of deeply technical Security Engineers to focus on creating bespoke and standard Security response processes, enhancing our capabilities for threat mitigation and incident response, and then automating as much as you possibly can (and more)! You will help us to grow

REMOTEawsgcprest
View job →
T
Twilio
📍 - Ireland• Full-time• Remote
1mo ago

Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work , and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. . Hiring and how we work We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! Also, while we are a remote-first company, you may be asked to report in person on an ad-hoc basis for team gatherings, functional off-sites or customer meetings. . See yourself at Twilio Join the team as Twilio’s next Security Engineer, Incident Response About the job The Security Incident Response Team (SIRT) is looking for a Security Engineer who is passionate about solving Twilio’s mission of security and reliability by working across the organization to lead the technical response to security events and incidents across Twilio’s global infrastructure, services and applications by effectively conducting triage, containment, remediation and driving post-incident betterments. You will work within a team that partners with R&D Engineering and R&D Business teams to develop scalable processes and technical solutions. You will be a valued member of a team of deeply technical Security Engineers to focus on creating bespoke and standard Security response processes, enhancing our capabilities for threat mitigation and incident response, and then automating as much as you possibly can (and more)! You will help us to grow

REMOTEawsgcprest
View job →
D
1mo ago

As a Senior Product Manager for AI & Data Security at Datadog, you will define and deliver capabilities that help organizations securely adopt and scale AI across their applications and infrastructure. You’ll focus on building products that provide visibility into AI systems and data usage, assess security posture, and enable teams to manage risk across the AI lifecycle. This role sits at the intersection of security, AI, and cloud platforms, and is ideal for a PM who thrives in emerging, ambiguous problem spaces. You will work cross-functionally to shape how customers discover, understand, and secure AI-powered systems in production. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Own and drive the roadmap for AI & Data Security capabilities, including data security posture management and data loss prevention Define how customers assess and manage the security posture of AI systems, including risks related to configuration, data exposure, and policy compliance Partner with engineering and design to deliver end-to-end product capabilities, from concept through launch and iteration Collaborate with security research teams to identify emerging risks in AI systems and translate them into actionable product features Engage with customers to understand AI adoption patterns and validate solutions that enable secure, scalable operations Define and track success metrics such as product adoption, usage, and impact on customer security workflows Who You Are: &l

restmachine learningai
View job →
O
Okta
📍 Washington• Full-time• From C$180K/yr
1mo ago

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. The Staff Product Security Engineer Opportunity As a Staff Product Security Engineer, you will play a critical role in safeguarding Okta’s products by conducting comprehensive security reviews, guiding engineering teams in secure development practices, and handling externally reported vulnerabilities. You will engage in code reviews, penetration testing, and architectural security assessments to ensure the security of Okta’s platforms and features. This role is not suited for individuals who rely solely on automated vulnerability scanning. Instead, you must possess a deep technical understanding of web applications, backend services, penetration testing methodologies, and secure design principles. A successful candidate will have expertise in authentication protocols (SAML, OAuth, OIDC), threat modeling, and a strong desire to automate security processes by building tools that proactively identify vulnerabilities. You will also be responsible for communicating risks, impact, and remediation strategies to developers, leadership, and external audiences through documentation, presentations, and external publications. The ideal candidate will also demonstrate a deep technical background in assessing AI-integrated software architectures and securing Large Language Models (LLMs) against emerging threats and modern vulnerability classes. The ideal candidate will have an attacker mindset—the ability to think critically, creatively, and like an adversary when solvin

pythonjavaaws
View job →
R
Robinhood
📍 Menlo Park• Full-time
1mo ago

Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading. About the team + role We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for thoughtful problem-solvers and builders who want to make a meaningful contribution. Robinhood is a place where people take ownership of their work and help improve financial access for all. We operate with high standards, clear accountability, and a strong focus on security and ethics in everything we build! The Red Team’s mission is to identify and reduce real-world security risks across Robinhood by simulating adversary behavior and testing defenses. As a Staff Offensive Security Engineer, you will plan and execute security assessments across applications, infrastructure, and physical environments, and partner closely with engineering and security teams to strengthen detection and response capabilities. You will help prioritize risk, contribute to remediation efforts, and develop tools and techniques that improve how we test and secure our systems. Your work will directly support the safety and reliability of products used by millions of customers. This role is based in our Bellevue, WA, New York, NY, or Menlo Park, CA office(s), with in-person attendance expected at least 3 days per week. At Robinhood, we believe in the power of in-person work to accelerate progress, spark innovation, and strengthen community. Our office experience is intentional, energizing, and designed to fully support high-performing teams. What you’ll do Evangelize the Offensive Security Team’s Findings and Projects with stakeholders throughout the company and collaborate with other teams to create solutions that

javascriptpythonjava
View job →
🔔

Get new application security head jobs by email

Daily job updates · Unsubscribe anytime