Jobs in United States

Application Security Head in United States

2,494 active opportunities · Updated October 2026

Explore current application security head jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.

C-
📍 New York, New York, United States· Full-time
✓ High-confidence listing

From $225K/yr

Quick readStrong listing-quality and freshness signals

CLEAR is building THE secure identity company of the future. Our mission is to make experiences safer and easier—physically and digitally. With more than 43 million Members and a growing network of partners across the world, CLEAR's secure identity platform is transforming the way people live, work, and travel. Whether it’s at the airport, stadium, or throughout your everyday life, CLEAR unlocks the magic of frictionless experiences. We are seeking a Senior Product Security Engineer to serve as a technical leader and strategic contributor within our Product Security team. This role goes beyond execution — you will drive the evolution of CLEAR’s application security posture by influencing architecture, shaping security engineering processes, and mentoring team members in security and engineering. You’ll lead security initiatives across the organization and help embed security into every stage of our software development lifecycle. What you'll do: Drive security strategy and implementation across all CLEAR products and engineering teams, ensuring consistent protection of customer and business-critical assets. Partner with engineering leadership to align application security initiatives with company-wide technology and product roadmaps, balancing innovation with risk mitigation. Provide technical leadership across CLEAR’s application security initiatives, guiding architecture, design, and development to meet high security standards. Serve as a trusted advisor to cross-functional teams — including Engineering, DevOps, Product, GRC, and IT — enabling secure-by-design practices across the organization. Design and drive implementation of scalable automated security controls and testing frameworks integrated into CLEAR’s CI/CD pipelines. Lead complex threat modeling, architecture reviews, and risk assessments across high-value systems and platforms, driving meaningful security outcomes. Engage with CLEAR's customers to provide insight and support their fraud and ident

JavaScriptPythonJavaCI/CD
R
📍 Foster City, California, United States· Full-time
✓ Quality checkedCompany trend -85.9%

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem. What You'll Do Core Responsibilities Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure. Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals. Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture. Software Supply Chain Security: Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security. Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws. Tooling Integration: Configure and tune automated security te

JavaScriptTypeScriptPythonJava
R
📍 Foster City, California, United States· Full-time· Remote
✓ High-confidence listingCompany trend -85.9%
Quick readStrong listing-quality and freshness signals

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for an AI Agent Security Architect to function as the primary technical authority for Replit’s autonomous and AI agent security blueprint. In this critical role, you will design, implement, and maintain the runtime defense systems, guardrail frameworks, and sandboxing architectures that govern AI agents executing code, invoking tools, and reasoning across our platform. You will be a key technical contributor—leading high-impact AI security initiatives and bridging the gap between non-deterministic AI behavior and rigorous cybersecurity controls for both engineering and executive leadership. What You'll Do AI Agent Security Strategy & Technical Execution AI Agent Security Blueprint: Define the long-term vision and architectural patterns for securing autonomous agent workflows, Model Context Protocol (MCP) integrations, multi-turn reasoning loops, and multi-agent coordination. Runtime Guardrails & Policy Enforcement: Architect and deploy dynamic input/output guardrail systems, semantic firewalls, and real-time intent verification filters to prevent goal hijacking, system prompt leaks, and indirect prompt injections. Agent Execution & Tool Sandboxing: Partner with Infrastructure and AppSec teams to design secure, short-lived, micro-isolated environments (e.g., microVMs, WebAssembly, container sandboxes) where agents can dynamically execute code, run shell commands, and interact with host operating systems safely. Agentic Threat Modeling & Red Teaming: Conduct specialized threat modeling against non-deterministic systems. Lead automated and manual AI red-teaming initiatives to uncover vulnerabilities in RAG context pipelines, vector stores, and tool-calling interfaces. Identity

JavaScriptTypeScriptPythonJava
R
📍 San Mateo, CA, United States· Full-time
✓ High-confidence listingCompany trend -100%

From $293.8K/yr

Quick readStrong listing-quality and freshness signals

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Enterprise Security Engineer, you will advance Roblox’s Enterprise Security strategy by shaping and evolving security architecture in alignment with business objectives. You will lead the design, deployment, and governance of security solutions that safeguard Roblox’s corporate infrastructure while enabling scalable, secure operations. Partnering cross-functionally with Corporate Engineering and Trust & Safety, you will translate organizational priorities into resilient security capabilities that balance risk, compliance, and productivity. You will join the Platform, Enterprise, and Application Security group, reporting directly to the Senior Manager of Enterprise Security Engineering. You'll partner with security professionals across the InfoSec team, and work cross-functionally with teams throughout Roblox to drive security initiatives that scale with our business. You will: Define and maintain enterprise-wide security standards and principles that guide how security is implemented across business workflows, ensuring consistency, scalability, and alignment with organizational risk posture. Lead and drive initiatives across core security domains, including Endpoint Secur

AWSGitAIGo
O
📍 United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team OpenAI’s Cyber team works to make frontier AI safe, trusted, and transformative for developers and enterprises. This team is building the security foundation for Codex: the native controls that govern what Codex can access and do, and the interfaces that allow customers and security partners to inspect, constrain, approve, and respond to Codex activity. Our goal is to make Codex secure by default, governable by enterprises, and interoperable with the security products customers already trust . This extends the existing product direction around tenant-scoped tools, guarded actions, approval systems, and scalable partner interfaces. About the Role We are looking for a deeply technical Product Manager to help build Codex security controls and the partner ecosystem around them. This role focuses on securing Codex itself : how identity, permissions, tools, MCP servers, repositories, secrets, networks, and high-impact actions are governed across Codex products. You will also help define standard interfaces through which authorized customer and partner systems can provide security context, inspect activity, return policy decisions, receive telemetry, and initiate bounded responses. You will work closely with Codex product and engineering, OpenAI Security and Safety, enterprise customers, and partners across application security, identity, cloud security, data security, infrastructure, and security operations. In this Role you Will Build native security controls for Codex Partner with engineering, design, security, and safety teams to develop controls for: Identity, roles, permissions, and tenant isolation. Access to repositories, files, tools, MCP servers, secrets, networks, and infrastructure. Read, write, execute, and deployment authority. Human and policy-based approvals. Prompt-injection and untrusted-content defenses. Audit trails, provenance, stop conditions, revocation, and rollback. Help establish a graduated authority model in which local, read-only

AWSCI/CDRestAI
S
📍 San Francisco, CA, United States· Full-time
✓ High-confidence listingCompany trend -90.5%
Quick readStrong listing-quality and freshness signals

Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. About The role As a Vulnerability Management Engineer, you will support the identification, assessment, prioritization, and remediation of vulnerabilities across applications and infrastructure. Working under the guidance of senior team members, you will assist in understanding how vulnerable dependencies enter an application, identifying remediation options, and engaging with engineering teams to track fixes. You will contribute to the maintenance of internal vulnerability-management tools, such as scripts, documentation, and reporting. The ideal candidate will have a desire to grow their AppSec expertise, will be eager to learn about modern security tooling and automation, and will be comfortable using AI tools like Claude to assist with documentation, investigation, and scripting tasks while following company security and data-handling requirements. What you’ll do Perform regular vulnerability assessments using different tools. Regularly drive remediation and reporting of cataloged vulnerabilities. Assess discovered vulnerabilities and properly prioritize their scope, impact and necessary response actions. Conduct security reviews of our products and production infrastructure. Contribute to vulnerability management, application security and/or offensive/red-team operations. Engage in security audit

PythonJavaAWSCI/CD
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team Codex is OpenAI's software engineering agent. Codex Security extends that work into one of the most important product areas in AI: helping organizations find, validate, prioritize, and fix real vulnerabilities in the software they build and depend on. The Codex Cyber team is building the product and platform foundations for AI-native application security. This includes Codex Security product experiences, cloud-based security analysis, platform controls across Codex, customer deployment and support tooling, and infrastructure that helps security researchers and cyber models improve over time. The team is early, small, and growing quickly, with a mandate to move fast and hire exceptional builders. About the Role We are looking for software engineers first: strong full-stack or product-minded generalists who can own ambiguous product and platform problems end to end. Security experience is helpful, and security curiosity is important, but this is not a role for security specialists who only occasionally write code. The right person is an excellent builder who is excited to work in security and can turn complex research, product, and customer needs into reliable systems. You will work across user-facing product surfaces, developer workflows, backend services, security analysis pipelines, cloud infrastructure, and internal tooling. You may build features that make Codex Security more useful for application security teams, systems that scale cloud-based security analysis, platform controls that make agentic coding safer, or infrastructure that helps security researchers and models become more effective. You will collaborate closely with engineering, product, security research, infrastructure, and customer-facing partners as Codex Cyber becomes a major product and platform investment for OpenAI. In this role, you will: Build end-to-end product features for Codex Security, from developer-facing interfaces to APIs, backend services, and workflow tooling. Own a

AWSRestAIGo
C
📍 Tampa Florida United States, United States
✓ High-confidence listingCompany trend +800%
Quick readStrong listing-quality and freshness signals

The Engineering Lead Analyst – SonarQube & Code Quality Engineering is a senior-level engineering role responsible for leading static code analysis, automated code quality governance, security vulnerability remediation, and AI-augmented developer enablement across enterprise software delivery pipelines. In this role, you will champion software reliability, maintainability, clean-coding standards, and automated quality gates. You will partner with development teams, system architects, and platform engineering to integrate and manage enterprise-scale code quality platforms (such as SonarQube) both on-premises and in cloud/SaaS environments. Additionally, you will drive modern engineering practices by embedding Behavior-Driven Development (BDD) within your own software delivery and leveraging Agentic AI workers and Model Context Protocol (MCP) architectures to optimize developer experience, streamline code governance, and boost engineering velocity. Key Responsibilities 1. Code Quality & Static Analysis Platform Ownership Lead the architecture, deployment, administration, and continuous enhancement of enterprise Static Application Security Testing (SAST) and Code Quality platforms (e.g., SonarQube , DeepSource, Codacy, Semgrep). Configure, calibrate, and enforce automated Quality Gates, code rulesets, technical debt calculation models, and code-coverage baselines across multi-language enterprise repositories. Oversee version upgrades, patching, high availability, and operational maintenance for on-premises and SaaS/cloud-hosted code quality infrastructure. 2. CI/CD & Pipeline Integration <li style=

JavaScriptTypeScriptPythonJava
O
📍 San Francisco, California, United States· Full-time
✓ High-confidence listingCompany trend -80.2%
Quick readStrong listing-quality and freshness signals

About the Role We’re looking for a senior individual contributor to lead GTM Strategy & Operations for Security & Safety, in close partnership with the Policy team. This role will help translate policy, security, and safety considerations into clear GTM strategies, operating models, launch plans, and scalable execution mechanisms. You’ll work across Product, Policy, Safety, Security, Legal, Data, Sales, Customer Success, Marketing, and Revenue Operations to understand customer and field needs, shape business recommendations, and support the successful adoption of security- and safety-critical products and capabilities. This role is ideal for someone who combines strong strategic and operational judgment with the ability to work effectively on complex policy-adjacent topics. You’ll help ensure that GTM plans reflect relevant policy requirements and that recurring customer and field insights inform future policy and product decisions. In this role, you will: Define the GTM operating model for the Security & Safety program, including ownership, decision forums, planning cadences, and escalation paths. Partner with Policy, Product, Security, Safety, Legal, and Data to translate policy considerations into actionable GTM guidance and operating processes. Develop go-to-market strategy for cybersecurity models, including target customers, use cases, commercialization approach, launch readiness, success metrics, and field enablement. Build mechanisms to capture recurring customer and field needs related to security, safety, application security, and policy implementation. Translate customer feedback and field requirements into recommendations for product roadmaps, policy development, enablement, and operational priorities. Support the operationalization of data-retention policies and related customer or deployment requirements across GTM. Track customer demand, implementation blockers, and market signals to refine GTM strategy and inform Policy and Product partne

AWSRestAIGo
M
📍 New York City, New York, United States
✓ High-confidence listingCompany trend +212.5%
Quick readStrong listing-quality and freshness signals

Our Purpose Mastercard powers economies and empowers people in 200&#43; countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Data Scientist What is the opportunity? We are seeking a highly skilled and motivated Data Scientist to join our Cyber Analytics team within the Security Solutions Data Science organization. This role is critical to driving advanced analytics initiatives, improving fraud detection capabilities, and supporting strategic decision-making across cybersecurity and payment fraud domains. What will you do? • Gain subject matter knowledge on web application security, commonly exploited cyber vulnerabilities, and methods of online and payment card fraud including the common points of purchase for compromised cards. • Build, develop, and maintain innovative data-driven analytical solutions, including predictive models and machine learning algorithms, on large volumes of data to support analytics and reporting needs across products, markets, and services. • Competently handle large datasets, sifting for patterns and trends and translating those insights into technical rules and solutions. • Combine cybersecurity and transaction data into new and insightful views of fraud and vulnerability across the Mastercard network. • Collaborate with cross-functional teams including product, engineering, and operations to understand product, usage, and data pipelines as well as delivering scalable solutions. • T

PythonSQLMachine LearningRecruitment
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team We are a small and fast-moving partnerships team that shapes and executes OpenAI’s most important collaborations. Your mission is to build and grow partnerships across the cybersecurity ecosystem. Reporting to the Cybersecurity Partnerships Lead, you will own a portfolio of cybersecurity technology partners and help them validate, launch, and scale solutions powered by OpenAI models and platforms. About the Role You are an experienced partnerships operator who combines business development, partner management, technical curiosity, and strong execution. You can manage external relationships while driving detailed cross-functional work across product, engineering, technical success, sales, marketing, legal, security, and operations. You move with urgency, follow through consistently, and are comfortable managing a portfolio in a fast-changing market. In this role, you will: Source, close and manage a portfolio of cybersecurity technology partners. Identify high-value use cases across security operations, identity, cloud security, application security, threat intelligence, governance, risk, and compliance. Develop partner plans covering integration, launch, enablement, co-marketing, co-sell, and growth. Support partnership structuring and coordinate product, technical, commercial, legal, and security workstreams. Help partners move from concept and technical validation to production launch and scaled customer adoption. Run regular partner reviews, track commitments, resolve blockers, and identify expansion opportunities. Coordinate closely with product, engineering, technical success, sales, marketing, legal, security, and operations. Measure partner pipeline, launches, model adoption, consumption, customer outcomes, and partner health. You might thrive in this role if you have: 8+ years of experience in partnerships, business development, alliances, partner success, or ecosystem roles. Experience in cybersecurity, enterprise software, cloud platforms, o

AWSRestAIGo
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the team The AI Deployment Engineering team is responsible for helping developers and enterprises safely and effectively deploy OpenAI technologies in production. We act as trusted technical advisors and thought partners for customers, working side by side with their teams to identify high-value use cases, design practical architectures, and move from prototype to durable deployment. Cybersecurity is one of the most urgent domains where AI can help. Security teams are under pressure to reason across code, logs, infrastructure, tickets, alerts, and vulnerability data faster than ever. As frontier models become more capable, organizations need deep technical guidance on how to evaluate, validate, and safely deploy AI systems in security-critical workflows. About the role We are looking for a Cyber AI Deployment Engineer to partner with customers and help them apply OpenAI models, APIs, Codex, and agentic workflows to real cybersecurity use cases. You will work with CISOs, security executives, application security leaders, SOC teams, security engineering teams, and hands-on practitioners to identify where AI can create measurable security outcomes. This is a customer-facing technical role for someone who can move fluidly between executive strategy, practitioner-level cyber depth, and hands-on solution design. You will help customers evaluate and deploy workflows such as secure code review, vulnerability triage, threat modeling, remediation, SOC and incident response workflows, detection engineering, cloud security, GRC automation, and security validation. You will collaborate closely with Sales, Solutions Engineering, Product, Engineering, Research, and Security to turn customer needs into safe deployment patterns, reusable field assets, and product feedback. This role is based in our San Francisco HQ. We offer relocation support to new employees. In this role, you will: Deeply embed with strategic customers as the technical lead for AI-enabled cybersecurity work

JavaScriptPythonJavaAWS
R
📍 New York City, NY, United States· Full-time
✓ High-confidence listingCompany trend -99.2%

From $10K/yr

Quick readStrong listing-quality and freshness signals

About Ramp Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. The problems are high-stakes, data-dense, and unforgiving. We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it. About the Role The Product Security team helps make Ramp the most secure place for our customers to collect, manage, and put to work their business’ financial information. Our work centers in three areas: Ramp builds products with an eye for security Ramp detects and responds to threats before they cause harm Security powers Ramp’s growth Check out our Engineering Blog for more on our tech stack, mission and values! What You’ll Do Build security-focused application primitives and integrate them into our existing products Design and deploy platform-level mitigations to common security issues Lead remediation of prioritized issues across our technology stack: collaborating with other engineers to triage and fix vulnerabilities discovered internally, through penetration testing, and through our bug bounty program Partner with engineering teams to design and deploy solutions which are inherently secure Champion the use of tooling (linters, static analysis, posture assessment scanners, query inspectors, etc.) which help Ramp engineers build secure system

PythonAWSRestAI
G
📍 United States· Full-time
✓ High-confidence listingCompany trend -100%

From $182K/yr

Quick readStrong listing-quality and freshness signals

Location Details: At GoDaddy the future of work looks different for each team. Some teams work in the office full-time, others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely. This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings. This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands. GoDaddy is not currently considering candidates for this role in California, Seattle, or NYC. Join Our Team GoDaddy is hiring a Staff Software Engineer to help define and scale our Internal Developer Platform —a centralized system that powers how engineers across the company build, deploy, and operate software. This platform is used by 1,000+ engineers to manage everything from cloud infrastructure and application lifecycle to security, compliance, and cost transparency. In this role, you’ll operate as a technical leader at platform scale, shaping the architecture and direction of systems that directly impact engineering velocity across the company. You’ll work on high-impact initiatives such as AI-powered developer tooling, next-generation API platforms, and the evolution of a unified developer experience spanning APIs, CLI, and UI. This is a high-ownership, high-visibility role where Staff Engineers drive decisions, influence product direction, and partner across infrastructure, security, and platform teams. If you’re motivated by building systems that improve how other engineers work—and want to have a measurable impact on developer productivity at scale—this team sits at the center of GoDaddy’s engineering ecosystem. What You’ll Get to Do... Design and build platform services that power GoDaddy’s internal developer ecosystem, used by 1,000+ engineers. Lead architecture and technical direction for high-scale APIs, infrastructure orchestration,

TypeScriptReactNode.jsAWS
R
📍 Foster City, California, United States· Full-time
✓ Quality checkedCompany trend -85.9%

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires strong technical ability to reproduce vulnerabilities , deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly. What You’ll Do Vulnerability Intake, Triage & Validation Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. Independently validate, reproduce, severity-score, and document findings. Identify duplicates and maintain a clean vulnerability records pipeline. Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC). Remediation Coordination & SLA Management Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation. Provide detailed reproduction steps, proof-of-concepts, and technical analyses. Track SLAs, remediation progress, regression testing, and systemic improvements. Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance. Bug Bounty & Vulnerability Disclosure Program Management Design and evolve the bug bounty program, including scope, rules, and reward structures. Man

PythonGCPCI/CDAI
🔔

Get new application security head jobs in United States by email

Daily job updates · Unsubscribe anytime