Jobiba hiring network

Application Security Head Jobs

4,781 active opportunities · Updated for October 2026

Fresh results

15 shown

Explore current application security head jobs. Use filters to narrow by work mode, employment type, experience and date posted.

R
Roblox
📍 San Mateo• Full-time• From $295.3K/yr
1mo ago

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. Join Roblox as an Engineering Manager of Application Security and lead a team responsible for improving the security of our products, services, and development ecosystem. In this role, you will drive security across the software lifecycle, partnering with engineering teams to identify risks, improve secure development practices, and build scalable solutions that protect Roblox at scale. You will balance hands-on security work with longer-term investments in automation, tooling, and developer enablement. You will work closely with engineering, infrastructure, and security teams to reduce risk while enabling teams to move quickly and safely. This role reports to the Senior Manager of Application Security and is based in San Mateo with a hybrid schedule. You Have: 8+ years of experience in Information Security 2+ years of experience managing engineers Strong background in Application Security or Product Security Experience driving security programs across the software development lifecycle Solid understanding of common vulnerabilities (e.g., OWASP Top 10) and secure coding practices Experience working closely with engineering teams in modern environments (cloud, microservices, CI/CD) Prov

awsci/cdgit
View job →
C
Coinbase
📍 Canada• Full-time• Remote• From C$154K/yr
1mo ago

Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase . As an Offensive Security Engineer on the Application Security team within Security, you'll pioneer how Coinbase uses frontier AI models to scale vulnerability discovery, red team AI systems, and automate security workflows. This role bridges traditional penetration testing with next-generation AI-augmented offensive security, directly accelerating our ability to protect products and customers. You'll own the development of AI-driven security tooling and collaborate across Vulnerability Management, Offensive Security, and Incident Response to fundamentally shift how we operate. What you'll do: Build, deploy, and maintain custom security scanners that leverage frontier models to detect vulnerabilities at scale across Coinbase's product surface. Lead red teaming efforts against internal AI systems, including jailbreak testing, prompt injection analysis, and tool abuse simulation. Develop AI-driven automation for vulnerability triage, validation, and remediation workflows to accelerate the bug bounty and vulnerability response pipelines. Partner with engineering teams to prioritize, remediate, and verify fixes for critical vulnerabilities discovered through AI-augmented and manual testing. Mentor junior security engineers on integrating AI into offensive security workflows to scale team capabilities. Required Skills and Experience: 3+ years of experience in application s

REMOTEpythonawsai
View job →
C-
CLEAR - Corporate
📍 New York• Full-time• From $225K/yr
15 days ago

CLEAR is building THE secure identity company of the future. Our mission is to make experiences safer and easier—physically and digitally. With more than 43 million Members and a growing network of partners across the world, CLEAR's secure identity platform is transforming the way people live, work, and travel. Whether it’s at the airport, stadium, or throughout your everyday life, CLEAR unlocks the magic of frictionless experiences. We are seeking a Senior Product Security Engineer to serve as a technical leader and strategic contributor within our Product Security team. This role goes beyond execution — you will drive the evolution of CLEAR’s application security posture by influencing architecture, shaping security engineering processes, and mentoring team members in security and engineering. You’ll lead security initiatives across the organization and help embed security into every stage of our software development lifecycle. What you'll do: Drive security strategy and implementation across all CLEAR products and engineering teams, ensuring consistent protection of customer and business-critical assets. Partner with engineering leadership to align application security initiatives with company-wide technology and product roadmaps, balancing innovation with risk mitigation. Provide technical leadership across CLEAR’s application security initiatives, guiding architecture, design, and development to meet high security standards. Serve as a trusted advisor to cross-functional teams — including Engineering, DevOps, Product, GRC, and IT — enabling secure-by-design practices across the organization. Design and drive implementation of scalable automated security controls and testing frameworks integrated into CLEAR’s CI/CD pipelines. Lead complex threat modeling, architecture reviews, and risk assessments across high-value systems and platforms, driving meaningful security outcomes. Engage with CLEAR's customers to provide insight and support their fraud and ident

javascriptpythonjava
View job →
R
1mo ago

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem. What You'll Do Core Responsibilities Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure. Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals. Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture. Software Supply Chain Security: Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security. Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws. Tooling Integration: Configure and tune automated security te

javascripttypescriptpython
View job →
C
Cloudflare
📍 Hybrid• Full-time• Hybrid• $166K – $208K/yr
1mo ago

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in. The Role: We are seeking a highly skilled AI Security Research & Red team engineer to join our Red Team within the Security Threat Detection, Response and Emulation organization. This is a critical role that will be at the forefront of protecting our company and customers from malicious threats. You will be responsible for driving security research, exercises, and activities that emulate real world attackers and attacks to drive improvem

awsgcpai
View job →
A
Asana
📍 Warsaw• Full-time• $522K – $594K/yr
1mo ago

The Security team is responsible for protecting Asana’s employees, users, and customers . We are a team of security engineers and risk and compliance practitioners who build innovative safeguards to ensure that our data is protected against threats and that we comply with legal, regulatory, and customer requirements . We collaborate closely with teams across the organization to foster a culture of security throughout our product and operations . We're looking for a Manager of Offensive Security to lead our Offensive Security function in Warsaw . In this role, you will own and grow a team spanning red team operations, application security, and vulnerability management, driving both the strategic direction and the hands-on execution of our offensive security program . You will work directly with engineering leadership, legal, and senior stakeholders to ensure our security posture is contin uously tested, measured, and improved . This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements. We offer a Contract of Employment (UoP) for our employees in Poland. What you’ll achieve Lead, grow, and mentor a team of offensive security engineers across red team, application security, and vulnerability management disciplines while staying actively engaged in day-to-day technical operations . Define team roadmap, OKRs, and priorities in alignment with broader security and engineering strategy . Foster a culture of technical excellence, continuous learning, and psychological safety within the team, partnering with recruiting to scale the team . Plan and execute red team operations and adversary simulation exercises across Asana's infrastructure, products, and corporate environment . Perform clo

javascripttypescriptpython
View job →
C
Cloudflare
📍 In Office• Full-time
1mo ago

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in. Job Title - Product Security Engineer Available Location - Bengaluru, India Role Summary As a Product Security Engineer, you will support security assessments and vulnerability operations for Cloudflare’s core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SL

awsagileai
View job →
D
1mo ago

As a Platform Security Engineer you will partner with different stakeholders across the organization to secure our infrastructure and application components of the Datadog platform. As part of the Platform Security organization we secure the building blocks of Datadog’s applications and infrastructure. We do this by building solutions solving systemic risks making the secure path easier and the insecure path harder. At Datadog, we place value in our office culture - the relationships that it builds, the creativity it brings to the table, and the collaboration of being together. We operate as a hybrid workplace to ensure our employees can create a work-life harmony that best fits them. What You’ll Do: Solve our most challenging cloud infrastructure security & application security problems starting with our core building blocks and golden paths. Enable our engineers to build and ship secure solutions quickly. Build and extend Datadog’s Platform Security solutions. Leverage and influence the direction of Datadog’s products to secure our infrastructure, and provide internal feedback that enables our teams to improve the products for ourselves and our customers. Who You Are: You have a BS/MS/PhD in a Computer Science, Engineering or related scientific field or equivalent professional experience. You don’t want to just provide security recommendations, you want to help implement solutions to solve systemic issues. Passionate about advocating for and implementing solutions to complex security problems, at-scale, in a large multi-cloud self-managed Kubernetes environment. Proven experience in securing enterprise SaaS applications including securing the underlying authentication flows, authorization patterns, and input validation at API boundaries. Demonstrated experience in securing the deployment & management mechanisms for software and infrastructure changes. Familiarity with common security frameworks such as OWASP, MITRE ATT&CK, PAST

pythonawsazure
View job →
F
Forma.ai
📍 Toronto• Full-time
15 days ago

About Forma.ai: Forma.ai is a Series B startup that's revolutionizing how sales compensation is designed, managed and optimized. We handle billions in annual managed commissions for market leaders like Edmentum, Stryker, and Autodesk. Our growth has been fuelled by our passion for fundamentally changing and shaping how companies use sales intelligence to drive business strategy. We’re welcoming equally driven individuals who are excited about creating something big! The Opportunity As a Staff Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems, and incident-response practices. Security today is shared across Engineering and DevOps. You'll work closely with both teams and have real room to shape how Forma approaches security as we grow. Depending on your interests and the needs of the business, the role could develop into a deeper individual-contributor position or help build a dedicated security team. You'll work directly with Engineering, DevOps, IT, Product, Legal, and Privacy to identify risks, design practical controls, automate security processes, and help teams ship secure and reliable software. What you'll do Cloud and infrastructure security Design and implement security controls across Forma's AWS environments, with a focus on IAM, least-privilege access, service identities, and account boundaries. Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management. Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services. Application, data, and AI security Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations

pythonawskubernetes
View job →
R
Replit
📍 Foster City• Full-time• Remote
1mo ago

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for an AI Agent Security Architect to function as the primary technical authority for Replit’s autonomous and AI agent security blueprint. In this critical role, you will design, implement, and maintain the runtime defense systems, guardrail frameworks, and sandboxing architectures that govern AI agents executing code, invoking tools, and reasoning across our platform. You will be a key technical contributor—leading high-impact AI security initiatives and bridging the gap between non-deterministic AI behavior and rigorous cybersecurity controls for both engineering and executive leadership. What You'll Do AI Agent Security Strategy & Technical Execution AI Agent Security Blueprint: Define the long-term vision and architectural patterns for securing autonomous agent workflows, Model Context Protocol (MCP) integrations, multi-turn reasoning loops, and multi-agent coordination. Runtime Guardrails & Policy Enforcement: Architect and deploy dynamic input/output guardrail systems, semantic firewalls, and real-time intent verification filters to prevent goal hijacking, system prompt leaks, and indirect prompt injections. Agent Execution & Tool Sandboxing: Partner with Infrastructure and AppSec teams to design secure, short-lived, micro-isolated environments (e.g., microVMs, WebAssembly, container sandboxes) where agents can dynamically execute code, run shell commands, and interact with host operating systems safely. Agentic Threat Modeling & Red Teaming: Conduct specialized threat modeling against non-deterministic systems. Lead automated and manual AI red-teaming initiatives to uncover vulnerabilities in RAG context pipelines, vector stores, and tool-calling interfaces. Identity

REMOTEjavascripttypescriptpython
View job →
S
Supabase
📍 Remote• Full-time
1mo ago

About the Role We’re looking for a Product Security Engineer to join our team and help strengthen how security is built into Supabase’s products, platform, and engineering workflows as we continue to scale. You’ll work closely with software engineers, infrastructure teams, and technical leadership , helping us proactively reduce risk earlier in the development lifecycle and ship securely by default. This role is ideal for someone who thrives in async, fast-paced environments and is excited about building developer tools that scale to millions. Success in this role means improving the security posture of the product without becoming a blocker to speed, autonomy, or builder velocity. What You’ll Own In this role, you’ll: Identify and close gaps across application security, secure design review, and vulnerability management. Conduct threat modeling, secure design reviews, and code reviews to identify practical remediation paths. Partner closely with engineering teams to provide product-focused security expertise and shape a modern security program. Mature how we think about security in a developer-first environment, balancing pragmatism with strong technical judgment. Distinguish between theoretical risk and material business risk to prioritize security efforts effectively. Improve security posture through scalable mechanisms like tooling, automation, secure defaults, and developer-friendly guardrails. Support security incident response by helping triage, investigate, and coordinate remediation for product and platform security issues. Participate in security on-call rotations, helping respond to urgent security events with clear judgment and calm execution. Help manage and mature our bug bounty and vulnerability disclosure processes, including triage, validation, prioritization, and coordination with engineering teams. You Might Be a Good Fit If You Have strong experience in product security, application security, or security engineering. Are comfortable working with

kubernetesrestai
View job →
C
Cloudflare
📍 Hybrid• Full-time• Hybrid
1mo ago

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in. Available Locations: Austin, TX Role Summary As a Product Security Engineer, you will support security assessments and vulnerability operations for Cloudflare’s core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SLAs. On any given day, you might conduc

awsagileai
View job →
O
Okta
📍 Washington• Full-time• From $180K/yr
1mo ago

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. The Security Team Okta is The World's Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transform how people move through the digital world, putting Identity at the heart of business security and growth. At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every box—we're looking for lifelong learners and people who can improve us with their unique experiences. Join our team! We're building a world where Identity belongs to you. The Staff Product Security Engineer Opportunity The Security team's mission is to strengthen Okta's position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers. The Staff AI Product Security Engineer joins a team with a clear mission: to shape the future of application security by researching and building systems that prove how AI can fundamentally augment, automate, and scale defense. This is a hybrid research, offensive and software engineering role centered on leveraging AI to uncover vulnerabilities, automate root cause analysis, automate exploitation, and generate secure code patches at cloud scale. This role is built for engineers who want to push the limits of what AI can do for security, from benchmarking SOT

typescriptpythonjava
View job →
L
1mo ago

Sr. Security Engineer, Corporate Security At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive. Lyft connects people to transportation to change the way we live and get around our communities. Lyft’s engineering team is growing rapidly, and we are looking for Security Engineers to help us scale. Come be part of a new team at Lyft focused on enabling and empowering engineering teams to deliver at scale. Our drivers and passengers entrust Lyft with their personal information and travel details to get where they're going and expect us to keep that data safe. Lyft's security team leads efforts across the company to ensure our systems are secure and worthy of our users' trust. The security team designs and builds Lyft's security architecture, consult with other teams as they build and launch new products and features, proactively plans for the unexpected, and responds to incidents that occur. Our work affects the entire company and takes place at all levels of the stack, from infrastructure to web application security, as well as mobile apps, IT, and autonomous vehicles. We try to approach security from a software engineering standpoint. We believe in scaling security through automation and tooling and we ship frequently. Check out our blog posts at https://eng.lyft.com/tagged/security to learn more about some of the things we’ve built. We're looking for an engineer to own the security of the systems Lyft employees rely on every day: identity, endpoints, and the data that moves between them. Corporate Security sits where security meets IT, so the work spans detection engineering, platform operations, and the automation that ties them together. We'd rather write code than file tickets, and we measure ourselves on control coverage and time-to-remediate. If you want real ownership over how security works at company scale, this is that role. Responsibiliti

pythonaigo
View job →
R
Roblox
📍 San Mateo• Full-time• From $293.8K/yr
1mo ago

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Enterprise Security Engineer, you will advance Roblox’s Enterprise Security strategy by shaping and evolving security architecture in alignment with business objectives. You will lead the design, deployment, and governance of security solutions that safeguard Roblox’s corporate infrastructure while enabling scalable, secure operations. Partnering cross-functionally with Corporate Engineering and Trust & Safety, you will translate organizational priorities into resilient security capabilities that balance risk, compliance, and productivity. You will join the Platform, Enterprise, and Application Security group, reporting directly to the Senior Manager of Enterprise Security Engineering. You'll partner with security professionals across the InfoSec team, and work cross-functionally with teams throughout Roblox to drive security initiatives that scale with our business. You will: Define and maintain enterprise-wide security standards and principles that guide how security is implemented across business workflows, ensuring consistency, scalability, and alignment with organizational risk posture. Lead and drive initiatives across core security domains, including Endpoint Secur

awsgitai
View job →
🔔

Get new application security head jobs by email

Daily job updates · Unsubscribe anytime