About the Team OpenAI builds powerful AI systems like ChatGPT, the OpenAI API, and enterprise products that serve millions of users across the globe. As we scale, securing our infrastructure, protecting sensitive data, and meeting global compliance standards are essential to our success and societal impact. Security at OpenAI is a cross-cutting function that spans infrastructure, applied engineering, legal, policy, and product. Technical Program Managers (TPMs) play a critical leadership role in aligning teams and delivering execution at scale and this role will be foundational in shaping how we secure OpenAI’s systems, users, and commitments. About the Role We’re seeking a Senior Technical Program Manager to drive cross-functional security, privacy, IT and compliance initiatives at the intersection of infrastructure, product, and policy. You will execute complex programs that reduce internal data access, prevent misuse, and ship security capabilities. You will focus your efforts on the most critical initiatives within Security, crossing the spectrum of insider threat, information security, physical security, and information technology challenges. This role is deeply technical and execution-focused. It requires a structured operator who thrives in ambiguity, partners effectively across boundaries, and applies principled judgment to scale trust, governance, and security across OpenAI’s systems and products. In this role, you will: Drive execution of critical security and compliance programs such as vulnerability management, merger and acquisition security and integration, infrastructure hardening, and datacenter security management. You will need to deeply collaborate on technical architecture and resolve technical problems in partnership with engineering. Partner with IT, Infrastructure, Application, Legal, Privacy, and Security teams to build scalable programs, and deliver critical security outcomes across multiple disciplines, including insider threat, information
Jobs in United States
Application Security Engineer in United States
2,494 active opportunities · Updated October 2026
Showing
15 jobs
Explore current application security engineer jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. The Release Engineer is responsible for implementing and supporting automated software delivery processes that enable reliable, secure, and repeatable deployments across development, test, non-production, and production environments. This role serves as a technical bridge between Software Engineering, Quality Engineering, Infrastructure, and Operations teams to improve deployment speed, stability, and operational efficiency. The Release Engineer is responsible for implementing and supporting automated software delivery processes that enable reliable, secure, and repeatable deployments across development, test, non-production, and production environments. This role serves as a technical bridge between Software Engineering, Quality Engineering, Infrastructure, and Operations teams to improve deployment speed, stability, and operational efficiency. Key Responsibilities Develop, support, and maintain automated CI/CD pipelines to streamline application delivery. Standardize build, release, and deployment processes across applications and platforms. Establish repeatable, auditable, and traceable release management practices to ensure deployment consistency and compliance. Manage and support Git-based source control, branching strategies, and release workflows. Integrate automated testing, quality gates, security controls, and compliance checks into deploym
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit is building the security GRC function that will scale with an AI-native product. As the Risk & Compliance lead, you'll own our certification and audit program end to end: SOC 2, ISO 27001, and eventually ISO 42001 (AI management systems), while also owning the company's master security risk register and continuous compliance monitoring. You'll report to the Head of Security GRC, who retains overall accountability for the risk program, and work closely with Engineering to make sure controls hold up in practice, not just on paper. What You'll Do Own the end-to-end certification roadmap (SOC 2 Type II, ISO 27001, and future frameworks like ISO 42001) including scoping, gap assessments, remediation, and audit execution Manage relationships with external auditors and drive the annual audit calendar so certifications renew without last-minute scrambles Own and maintain the company's master security risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting Build and maintain continuous compliance monitoring so control status reflects real-time state rather than point-in-time snapshots Own the core audit artifacts that back every certification including ISMS documentation, Statements of Applicability, risk assessments, and potentially FedRAMP System Security Plans (SSPs) Run regular audits and readiness assessments, and track remediation of findings and control gaps to closure Support GDPR and broader privacy compliance alongside the Legal/Privacy team, without owning the legal interpretation of requirements Partner with the GRC Engineer to define what evidence collection and control monitoring should be automated versus manually reviewed Track and
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit’s ecosystem is powered by an expanding array of external services and essential AI model partners. As our lead for Security Vendor Risk & Contract Reviews, you will architect and execute a risk management program focused on substantive evaluation rather than just processing checklists. You’ll analyze SOC 2 documentation, security assessments, and system architectures to determine actual risk profiles, collaborating with our Legal team to secure necessary contractual protections. This role reports to the Head of Security GRC and involves high-impact partnerships across Legal, Engineering, and Product teams. What You'll Do Run substantive third-party risk management (TPRM), independently evaluating real risk, not just processing questionnaire responses Review SOC 2 reports, pen test findings, and architecture documentation to form an independent view of vendor risk, extending the same rigor to AI/model providers Partner with Legal on vendor and AI contract terms, including DPAs, subprocessor agreements, and AI-specific provisions Review contracts for non-standard security language when flagged by Legal or deal desk, and recommend redlines Maintain the vendor and AI/model risk register, feeding findings into the company's master risk register Enable sales through maturing the customer trust program Build the capability for continuous monitoring of vendor ecosystem Required Skills & Experience 8+ years in third-party/vendor risk management, security risk, or a related GRC role Demonstrated ability to independently assess vendor risk rather than relying on questionnaire responses alone, fluent in reading SOC 2 reports, ISO certificates, pen test summaries, and architecture documentation Experi
$200K – $240K/yr
About Sentry Software runs the world and the pace is faster than ever. Sentry helps developers fix errors and performance issues before users notice, so teams can spend less time firefighting and more time building. Trusted by 200,000+ organizations, Sentry is today’s application monitoring standard and our team is building its AI-native future. About the role The Platform org at Sentry is the engine that everything else runs on, spanning developer platform, core infrastructure underpinning the product, SRE, security, and IT. It's a broad, technically complex, and deeply consequential organization. We're looking for a Staff Technical Program Manager who can operate at the intersection of technical depth and strategic execution: someone who thrives in complexity, builds trust with senior engineering leaders, and has a gift for turning ambiguity into clarity and momentum. You'll report to the Head of Technical Program Management and work closely with the VP of Platform Engineering, their staff, and partner teams across Engineering, Product, and Design (EPD). This is a high-visibility role with real influence. You'll work directly with the CTO and senior leaders, shape how the Platform org operates, and help Sentry scale through one of its most important chapters. In this role, you will: Drive strategic execution. Partner with the VP of Platform Engineering and senior EPD leaders to translate priorities into clear, measurable plans. Own sequencing, milestones, and key decisions, and make sure leadership always has reliable visibility into progress and tradeoffs. Build data-driven delivery health. Establish the metrics and dashboards that reflect delivery confidence, risk, and engineering health across the Platform org. Keep planning and reporting high-signal and lightweight, focused on outcomes rather than activity. Manage capacity, dependencies, and risk. Create visibility into resourcing, cross-team dependencies, and constraints so leaders can align investment to the
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. Replit is the fastest way to turn ideas into software. With Replit Agent, anyone can build and ship a real application in natural language, without setting up a single tool. We've grown explosively, from $2M to $400M+ revenue in under a year, with a global community of 60+ million users, and Replit Agent is now one of the fastest-growing products in history. That same wave is now hitting the enterprise. Companies like Visa, Ernst & Young and Comcast are rolling Replit out to thousands of employees so finance teams, operations leads, and product managers can build without waiting on an engineering backlog. When a company puts Replit in the hands of thousands of employees, they're trusting us with their data and their workflows. That trust has to be earned: SSO and SCIM that just work, governance their security team will sign off on, and real control over where their apps run and how their data is handled. Getting this right is what turns a pilot into a company-wide standard, and it's one of the biggest levers on Replit's next phase of growth. About the Role We're hiring a Staff Product Manager to own Replit's enterprise product end to end. We've built one of the best coding agents in the world. The work now is making it just as powerful inside a big company, where putting it in front of every non-technical employee unlocks enormous leverage. That means extending what Agent can do in an enterprise context and building the platform that lets large organizations adopt it safely and at scale. This is a role with unusual leverage. We're still early in our enterprise journey but the traction is remarkable, which means most of the platform is still to be built and you'll have an outsized hand in shaping it. You'll decide w
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We're redefining how software is built and who gets to build it. Our mission is to achieve Autonomy for All: making programming accessible, collaborative, and powered by AI. Realizing that vision requires a platform that legitimate users can trust and adversarial actors cannot exploit. We're hiring a Data Scientist to help build Replit's Trust & Safety and Anti-Abuse program from the ground up. You'll turn noisy behavioral, identity, payment, infrastructure, and content signals into the measurement systems, detections, and decisions that protect Replit's users, platform, and economics. You'll work closely with Engineering, Support, Legal, Security, Infrastructure, Money, and Growth to make abuse economically unviable while keeping friction low for legitimate users. Replit sits at the frontier of AI-native abuse. Our platform is a target for phishing and scam hosting, cryptomining, LLM token farming, card and coupon fraud, referral abuse, and increasingly, abuse driven by AI agents themselves. You'll help define how we identify, measure, and respond to these threats without compromising the experience of good users. Who You Are You're a data scientist who moves fast, goes deep, and thinks adversarially. You can spin up an analysis in hours that would take others days, not by cutting corners, but because you've built the intuition and technical toolkit to get to the right answer quickly. You dig past the top-line abuse rate to understand selection effects, missing labels, policy changes, attacker adaptation, and the false positives hidden inside an aggregate metric. You understand that Trust & Safety data is imperfect and outcomes are high stakes. Ground truth is delayed, biased, and often incomple
About the Team The SaaS and Software Governance team sits within Corporate IT and helps OpenAI scale from startup-speed tooling to mature enterprise architecture. The team owns practical governance for software, SaaS, integrations, APIs, identity, data access, and agent-enabled workflows, with a mandate to improve security, reduce software sprawl, and help business teams move faster through better foundations. About the Team OpenAI is scaling from an emerging, high-velocity startup into a mature enterprise operating model. The IT Software Architect will help shape the software, SaaS, Data integration, and agent-enabled architecture that lets the company move quickly while improving security, compliance, data quality, and customer, partner, and employee experience. This role is not a traditional ivory-tower architecture function. It is a hands-on governance and enablement role that partners with business teams, IT operations, Security, Procurement, Business Platforms, Applied teams and Data Engineering to guide software decisions, reduce unmanaged sprawl, and build reusable enterprise foundations. Why This Role Matters OpenAI’s software footprint is expanding rapidly across SaaS, internally built tools, agents, integrations, APIs, third-party platforms, and application systems that OpenAI. The company needs a stronger tools architecture layer that can help teams make good decisions early, avoid duplicate tools, govern sensitive data and identities, and identify where OpenAI should build instead of buy. The person in this role will help turn software governance from an approval checkpoint into an enterprise capability: a system that improves speed, reliability, security, and business outcomes. What You'll Do Own the target architecture for enterprise software, SaaS, integrations, APIs, and agent-enabled business systems across Corporate IT. Drive deprecation and consolidate targets for enterprise software. Build lightweight governance patterns that guide teams before
Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! Why This Role Is Different This is not a typical “Applied Scientist” or “ML Engineer” role. As a Member of Technical Staff, Applied ML, you will: Work directly with enterprise customers on problems that push LLMs to their limits. You’ll rapidly understand customer domains, design custom LLM solutions, and deliver production-ready models that solve high-value, real-world problems. Train and customize frontier models — not just use APIs. You’ll leverage Cohere’s full stack: CPT, post-training, retrieval + agent integrations, model evaluations, and SOTA modeling techniques. Influence the capabilities of Cohere’s foundation models. Techniques, datasets, evaluations, and insights you develop for customers will directly shape the next generation of Cohere’s frontier models. Operate with an early-startup level of ownership inside a frontier-model company. This role combines the breadth of an early-stage CTO with the infrastructure and scale of a deep-learning lab. Wear multiple hats, set a high technical bar, and define what Applied ML at Cohere becomes. Few roles in the industry combine application, research, customer-facing engineeri
Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! Why This Role Is Different This is not a typical “Applied Scientist” or “ML Engineer” role. As a Member of Technical Staff, Applied ML, you will: Work directly with enterprise customers on problems that push LLMs to their limits. You’ll rapidly understand customer domains, design custom LLM solutions, and deliver production-ready models that solve high-value, real-world problems. Train and customize frontier models — not just use APIs. You’ll leverage Cohere’s full stack: CPT, post-training, retrieval + agent integrations, model evaluations, and SOTA modeling techniques. Influence the capabilities of Cohere’s foundation models. Techniques, datasets, evaluations, and insights you develop for customers will directly shape the next generation of Cohere’s frontier models. Operate with an early-startup level of ownership inside a frontier-model company. This role combines the breadth of an early-stage CTO with the infrastructure and scale of a deep-learning lab. Wear multiple hats, set a high technical bar, and define what Applied ML at Cohere becomes. Few roles in the industry combine application, research, customer-facing engineeri
The Applications Development Technology Senior Lead Analyst is a senior level position responsible for establishing and implementing new or revised application systems and programs in coordination with the Technology Team. The overall objective of this role is to lead applications systems analysis and programming activities. Responsibilities: Lead the architecture, design, development, and delivery of enterprise UI applications. Strong hands-on experience with Angular and Ext JS for developing scalable and responsive user interfaces. Strong experience with Java and Spring Boot for designing and developing backend services and APIs. Experience deploying, supporting, and troubleshooting applications in ECS/containerized environments . Define application architecture, technical standards, reusable components, and development best practices. Provide technical leadership to development teams, including design reviews, code reviews, performance optimization, and troubleshooting . Strong understanding of CI/CD pipelines , including automated build, testing, deployment, and release processes. Hands-on experience with GitHub , including source-code management, branching strategies, pull requests, code reviews, and integration with CI/CD pipelines. Strong knowledge of open-source technologies and frameworks , with hands-on implementation experience. Ability to evaluate and select appropriate open-source libraries, frameworks, and tools , considering security, licensing, maintainability, vulnerabilities, and enterprise standards. Drive application modernization, technical improvements, and adoption of engineering best practices. Work closely with architects, developers, infrastructure teams, product owners, and business stakeholders to deliver solutions successfully. Prov
Become a part of our caring community Humana is seeking a Lead Cloud Architect – NoSQL Databases to provide strategic leadership, architecture direction, and engineering oversight for enterprise NoSQL database platforms across Humana’s cloud environments. This role will focus on the design, implementation, modernization, and governance of NoSQL database solutions, including MongoDB, Azure Cosmos DB, Neo4j, and vector database technologies. The successful candidate will help define and advance Humana's enterprise NoSQL strategy, support platform rationalization initiatives, and ensure database solutions are secure, scalable, resilient, automated, and aligned with enterprise architecture standards. This role requires hands-on technical depth, strong cloud architecture experience, and the ability to collaborate across security, engineering, quality, application, and business teams. Key Responsibilities Develop, document, and maintain enterprise-wide NoSQL database standards, reference architectures, design patterns, and best practices. Lead architecture and engineering efforts for NoSQL platforms including MongoDB, Azure Cosmos DB, Neo4j, and vector databases. Support NoSQL platform rationalization and modernization initiatives, including migration planning and execution from Cosmos DB to MongoDB where appropriate. Architect secure, highly available, scalable, and performant NoSQL database solutions across cloud environments, including Azure and/or Google Cloud Platform. Define database architecture patterns for document databases, graph databases, key-value workloads, and vector search use cases. Guide application teams on NoSQL data modeling, partitioning, indexing, query patterns, performance optimization, and operational readiness. Oversee automation of NoSQL provisioning, configuration, monit
From $192K/yr
Databases and data stores are at the center of our applications, for legacy applications and modern AI applications alike. Yet most observability and optimization approaches lack a holistic approach or application context. Datadog has been on a mission to revolutionize how databases are operated, flipping what is often seen as a black box of complexity prone to security and performance risks, into a well oiled machine enabling our builders and businesses to move faster and smarter. We’re looking for an experienced product manager passionate about joining this mission to lead this product opportunity. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Lead ambitious investments that rethink how customers operate and get value from their databases, diving into ambiguity, working with our customers on new models, and shipping new products and changes to existing products. Develop a deep understanding of our customers and their issues, what problems are really behind those issues, and how we can improve how databases are operationalized across SRE teams, DBAs and application developers. Continuously refine your understanding of database management systems and datastores from SQL and OLTP based to NoSQL e.g. AWS RDS, PostgreSQL, SQL Server, MongoDB, MySQL, etc Define, build and launch the next generation of database monitoring and optimization capabilities for our customers Join a talented engineering team with a record of disrupting observability approaches to further the mission of demystifying and optimizing databases using your team’s creativity, alongside your customers’ problems, as a key resource. Collaborate with other Product teams in Datadog to maintain and improve all Datadog products, improve the seamless integration across th
Linux System Administrator Alexandria, VA Secret clearance or higher The Test and Training Enabling Architecture (TENA) program at Leidos is looking to add a Linux System Administrator . Our mission is to develop tools for the United States Department of Defense test and training communities, to increase the speed of the development cycle, to get capabilities to the warfighter more rapidly. The Linux System Administrator will work within a team engineers, developers and system administrators, adding new capabilities to our enclaves, as well as ensuring the existing systems are secure and performing as intended. This position is required to work on-site in our Alexandria, VA office. Primary Responsibilities: Provide support for installing and maintaining Linux servers. Provide technical leadership for migrating on premise infrastructure to hybrid cloud solution. Provide support for troubleshooting from OS to application-level issues. Manage networking equipment including switches, routers and firewalls. Manage configuration and maintenance of core enclave infrastructure services including DCHP, DNS, e-mail, Apache Web Servers, Tomcat application servers, Atlassian applications, MariaDB database servers. Configure and monitor security tools required for DoD networks. Participate and contribute to design discussions related to improving the capabilities, performance and security posture of new and existing services. Basic Qualifications: US Citizen with at least an active Secret clearance. Bachelor’s degree with 4+ years of experience or a Master’s degree with 2+ years of experience. Additional experience may be considered in lieu of a degree. 4+ years of experience providing System Administration to DoD IT systems. DoD 8570 IAT level I
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. We're seeking an experienced Commercial Counsel to join our growing legal team and serve as a strategic partner to our rapidly expanding enterprise sales organization. In this high-impact role, you'll drive complex commercial negotiations that fuel our growth, working closely with our sales teams to close sophisticated technology agreements with enterprise customers across diverse industries. You'll play a critical role in scaling our commercial legal processes while navigating the evolving landscape of AI-powered development tools and ensuring our customers can confidently deploy Replit's platform in their organizations. What You'll Do Drive Enterprise Deals : Serve as the lead legal advisor for complex, high-value enterprise sales transactions, working directly with our Account Executives and customer legal teams to negotiate and close sophisticated software agreements Navigate AI & Technology Compliance : Help enterprise customers understand and navigate the legal and regulatory implications of adopting AI-powered development tools, addressing data privacy, security, and compliance requirements across various industries Build Scalable Frameworks : Design and implement contract playbooks, template agreements, and streamlined processes that enable our sales team to move quickly while maintaining legal rigor as we scale Risk Management : Identify, analyze, and proactively manage complex commercial and legal risks while maintaining deal velocity in our fast-paced, high-growth environment Cross-Functional Partnership : Collaborate closely with Product, Engineering, Security, and Privacy teams to ensure our commercial offerings align with product capabilities and regulatory requirements Strategic Advisory : Provide st
Other cities to consider
More places hiring for this role
Get new application security engineer jobs in United States by email
Daily job updates · Unsubscribe anytime