About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role We’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate remediation of vulnerabilities across OpenAI’s infrastructure and applications. You will be the technical owner of this effort, combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at scale. As OpenAI increasingly uses automation throughout the company, we believe our security testing must become increasingly automated as well. Advances in model capabilities create an opportunity to test more of our attack surface than would be possible through human effort alone and a need to ensure that we remain ahead of those same capabilities as they become available to attackers. In this role, you’ll build a portfolio of specialized agents that develop a deep understanding of OpenAI’s infrastructure, applications, processes, and security boundaries. These agents will combine internal context with feedback from running systems to explore our cloud environments, Kubernetes clusters, web applications, endpoints, external attack surface, and other high-value targets. The goal is for agents to not only discover vulnerabilities, but also to validate exploitability, document impact, drive remediation, and verify fixes. Success will be measured through outcomes like vulnerabilities fixed, attack surface covered, and performance on evals
Jobs in United States
Application Security Head in United States
2,494 active opportunities · Updated October 2026
Showing
15 jobs
Explore current application security head jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.
About the Team The Solutions Engineering team is made up of trusted technical advisors who help organizations adopt OpenAI’s technology safely, effectively, and responsibly. We partner closely with customers, Sales, Product, Engineering, and Security to translate frontier AI capabilities into practical workflows that create real-world impact. Cybersecurity is one of the most urgent areas where AI can help. As frontier models become more capable at reasoning over code, logs, infrastructure, and security evidence, organizations need guidance on how to evaluate, validate, and deploy these systems safely. Our goal is to help customers move from identifying risks to implementing solutions. About the Role We are committed to bringing together people from diverse backgrounds and perspectives who are excited to help build and deploy safe, useful AI. We are seeking a solutions engineer to partner with our Enterprise customers and ensure they achieve tangible business value from our models through the OpenAI suite of products. You will partner with senior business stakeholders to understand their pre-sales needs, guide their AI strategy, and identify the highest value use cases and applications. You will work with business and technical teams to demonstrate the value of our solutions and recommend architectural patterns to kickstart their implementation and development. You will work closely with Enterprise Sales, Security, and Product teams. We are looking for a Field Security Specialist to help security leaders and hands-on practitioners understand how OpenAI models, APIs, Codex, and agentic workflows can be applied to real cybersecurity use cases. This is a customer-facing specialist role for someone who can move fluidly between CISO-level conversations, practitioner-level technical depth, and hands-on solution design. You’ll help customers evaluate OpenAI for workflows like secure code review, vulnerability triage, threat modeling, remediation, SOC workflows, detection en
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector. As a Forward Deployed Security Engineer (FDSecE) you will be responsible for securing these novel applications of OpenAI’s technology. We’re looking for motivated, tenacious, and curious people who will work closely with engineering teams to ensure our infrastructure deployments are highly secure against our adversaries. As an FDSecE, you will embed directly throughout the lifecycle, working on-site and being hands-on to ensure the overall security of these deployments from design to production and through ongoing operations. This role is preferred to be based in Washington DC but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. Travel to and working from customer sites is required for this role. In this role, you will: Deeply embed with our most strategic public sector customers to implement and maintain robust security controls. Be a design and technical thought partner by leveraging security expertise on protective controls including access controls, authentication, encryption, network, and system security. Collaborate closely with teammates, cross-functional teams, customers, and service providers to achieve security and compliance goals. Ensure continuity of critical security and monitoring c
$100K – $130K/yr
Healthcare is complex. We’re here to change that. RVO Health is a health technology company on a mission to make health easier to navigate, more accessible, and more affordable for everyone. Here, you'll help over 40 million people every month, with a team that genuinely cares about the work and each other. AT A GLANCE RVO Health is a first-of-its-kind comprehensive consumer healthcare platform that meets people where they are in their personal journeys and connects them with both the information and the care they need. RVO Health is a partnership between Red Ventures and UnitedHealth Group. Together we're focused on delivering on our vision of a stronger and healthier world. RVO Health has the largest consumer health and wellness audience online. Every month, we help nearly 100 million people take steps on their daily journey to lifelong well-being. As part of our RVO Health Security team, you will play a major part in strategic initiatives that improve our security posture and protect our sensitive data. You will work in a collaborative Agile environment, working closely with the business, IT, and engineering teams. You will apply your skills in a highly dynamic, innovative, cloud-native environment with a strong security-minded culture. Where You'll Be Location: Denver, CO | Hybrid We believe great collaboration happens when we're together, solving problems, learning from each other, and connecting as a team. That's why we’re in our offices Tuesday through Thursday each week. You are welcome to work remotely Mondays and Fridays if you wish. Address: 1801 California St. Denver, CO 80202 What You’ll Do Design, implement, and maintain security controls and architectures to protect the company's cloud infrastructure, applications, and data from cyber threats. Improve our cloud security posture and vulnerability management program — pull-request scanning, triage and tracking of findings to closure across engineering teams, and coverage and license optimization. Build
From $124K/yr
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform. We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler. Role We are looking for a Senior Enterprise Applications Administrator to join our team. This is a hybrid role in San Jose, CA or Remote in Denver, CO, reporting to the Collaboration Solutions Manager in the IT Digital Employee Experience department. In this position, you will support and assist in driving the visionary innovation of Zscaler over the next decade, shaping the future of our technology across collaboration applications and the emerging AI space. You will work closely with support and executive support teams while leading a team to deliver cutting-edge services into both enterprise and FedRAMP environments. What you’ll do (Role Expectations) Develop and articulate the strategic vision for Google Workspace and MS365, aligning with organizational goals and industry best practices, while collaborating with our compliance team on FedRAMP compliance Lead the design, implementation, and optimization of Goog
We are hiring a Security Software Engineer to design and implement the hardware-backed security foundations used across OpenAI’s device ecosystem. A central focus of this role is hardening the boundary between our policy systems and the HSMs that protect sensitive cryptographic keys. This boundary determines which operations may be performed, what may be signed, which policies must be satisfied, and how changes to trusted software and policy are authorized. You will develop security-critical software and firmware within, or immediately adjacent to, an HSM trust boundary. Depending on your background, this may include HSM trusted applications, firmware services, cryptographic mechanisms, device drivers, PKCS#11 components, secure-provisioning protocols, or signing-policy enforcement systems. This is a hands-on software-engineering role. You will be expected to design systems, write and review production code, debug across hardware and software boundaries, and carry projects from initial requirements through deployment. It is not an HSM administration, PKI operations, compliance, or architecture-only position. In This Role, You Will Design and implement security-critical software and firmware for HSMs, secure elements, trusted execution environments, and hardware roots of trust. Build and harden the policy-to-HSM boundary responsible for authorizing certificate issuance and cryptographic signing operations. Develop HSM trusted applications, firmware components, host interfaces, device drivers, SDKs, or cryptographic service integrations. Implement or extend cryptographic interfaces such as PKCS#11, OpenSSL providers or engines, platform key-storage APIs, or comparable hardware-security interfaces. Build firmware and software that cryptographically enforces key generation, provisioning, usage, rotation, recovery, and destruction policies. Design and implement HSM-backed certificate authority, code-signing, key-management, and device-identity systems. Develop end-to-end
From $165.4K/yr
About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do Identity & access Advance our identity posture: SSO coverage, phishing-resistant MFA rollout, SCIM lifecycle automation, and least-privilege access across the SaaS and cloud estate. Build the detections and guardrails that catch account takeover, MFA fatigue attacks, and session token theft before they turn into incidents. Endpoint & device lifecycle Write and ship device policy as code — configuration profiles, remediation scripts, and enforcement rules across macOS and Windows — with staged rollout and rollback built in from day one. Maintain and improve our EDR stack's detection and response coverage across the fleet. SaaS posture Reduce SaaS risk at scale through SSPM tooling and automation , including detection of risky OAuth grants, shadow IT, and configuration drift across our critical SaaS applications. Own security configuration for the SaaS tools hundreds of Flexporters use daily (Google Workspace, Slack, and similar), and keep pace as we add AI agents and MCP integrations to that surface. Automation & enablement Automate the parts of corporate security that don't need a human — device provisioning, access reviews, vendor securi
From $165.4K/yr
About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do Identity & access Advance our identity posture: SSO coverage, phishing-resistant MFA rollout, SCIM lifecycle automation, and least-privilege access across the SaaS and cloud estate. Build the detections and guardrails that catch account takeover, MFA fatigue attacks, and session token theft before they turn into incidents. Endpoint & device lifecycle Write and ship device policy as code — configuration profiles, remediation scripts, and enforcement rules across macOS and Windows — with staged rollout and rollback built in from day one. Maintain and improve our EDR stack's detection and response coverage across the fleet. SaaS posture Reduce SaaS risk at scale through SSPM tooling and automation , including detection of risky OAuth grants, shadow IT, and configuration drift across our critical SaaS applications. Own security configuration for the SaaS tools hundreds of Flexporters use daily (Google Workspace, Slack, and similar), and keep pace as we add AI agents and MCP integrations to that surface. Automation & enablement Automate the parts of corporate security that don't need a human — device provisioning, access reviews, vendor securi
From $196.8K/yr
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in the offensive security assessments that strengthen our defense capabilities. Working closely with the larger InfoSec team, detection engineers, and external engineering partners, you'll identify security weaknesses, validate detection mechanisms, and provide actionable recommendations to enhance our security posture. You'll collaborate with various architecture and engineering teams to continuously validate and improve our security controls and detection capabilities, with a strong focus on developing repeatable testing frameworks and metrics-driven security improvements. You Have: 4+ years: of relevant professional experience in offensive security, with demonstrated experience in purple team exercises, breach attack simulation, and detection engineering collaboration. Development experience: proficiency in Python or Go for building security tooling and automation, including experience with SOAR platforms and configuration management. Security assessment expertise: performing full-stack security assessments of web applications, APIs, cloud infrastructure, and backend systems. Platform expertise
About the Team OpenAI’s Platform and Infrastructure Engineering organization advances the mission of deploying artificial general intelligence (AGI) for the benefit of all by delivering secure, scalable, and resilient technology solutions. Our team builds and maintains robust infrastructure that safeguards OpenAI’s data and systems while ensuring employees are well-equipped and seamlessly connected. By prioritizing security, reliability, and user-centric solutions, we empower OpenAI employees to drive impactful AI research, corporate operations, and product innovation. About the Role As a Software Engineer: Internal Applications, Enterprise, you will build internal products that make technology support and administration safer, faster, and less dependent on manual intervention. You will help reduce reliance on broadly privileged human actions, turn recurring technology problems into paved paths, and build agentic systems that can help resolve tickets end to end. A core part of the role is building the interfaces that bring employees, AI agents, and human responders together in a shared ITSM experience, with the right context, controls, and handoffs at each step. We are seeking engineers who enjoy working across frontend and backend layers on ambiguous, high-leverage enterprise problems. You should bring strong product judgment, solid backend engineering fundamentals, and an interest in building software that changes how technology support, system administration, and agent-assisted operations are delivered. The best fit will care as much about the quality of the operator and employee experience as the correctness of the backend systems behind it. In this role, you will: Build frontend experiences that let employees request help, let agents gather context and take safe actions, and let human responders review, approve, or take over without losing the thread. Reduce reliance on broadly privileged manual actions by replacing them with narrow, auditable, policy-aware aut
From $154K/yr
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform. We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler. Role We are looking for a Sr. Staff Software Development Engineer-AI Security to join our team. This is a Hybrid (based in San Jose, CA or Bellevue, WA with a 3 days in office requirement) role, reporting to the Director of Software Engineering in the Emerging Tech department. You will be responsible for designing and implementing core infrastructure components and distributed systems, serving as a foundational architect for our AI security solution. This high-impact role focuses on scaling security infrastructure to support hundreds of millions of users, collaborating with stakeholders across the development lifecycle to drive innovation and technical excellence. What you’ll do (Role Expectations) Architect, develop, and optimize a low-latency, high-throughput AI Security plane utilizing Rust, specifically leveraging its async/await model for highly efficient I/O and service-oriented architecture Build resi
SUMMARY STATEMENT We are looking for a Solution Architect to design the technical solutions behind our client engagements and give delivery teams a clear, workable path from concept to production. You will work across enterprise data, software applications and GenAI - translating complex business problems into practical architectures that delivery teams can build and scale. This could include architecting an agentic workflow for clinical operations, a conversational analytics product grounded in enterprise data, or an AI-enabled decision platform for commercial teams. You will work directly with clients, define the architecture, test the most important technical decisions yourself and establish the foundations for successful delivery. This is an architecture-first role with meaningful hands-on engineering: you will stay close enough to implementation to prove the architecture works and support it through production delivery, without becoming the primary engineer for every component. You will also help shape the reusable patterns, technical standards and accelerators behind Lynx’s growing AI-native life sciences practice. KEY RESPONSIBILITIES Solution Architecture Own the end-to-end solution architecture for client engagements, including data models, system design, integration patterns and technology choices. Translate business requirements into clear technical designs and implementation paths that delivery teams can build from. Design solutions spanning enterprise data, APIs, applications, cloud platforms and GenAI capabilities. Lead technical discovery with clients: understand requirements, assess existing systems and identify dependencies, constraints and delivery risks. Present architectural options and trade-offs clearly to technical teams, business stakeholders and senior leaders. Make pragmatic decisions across build speed, cost, scalability, security and maintainability. Review key implementation decisions and remain
From $131K/yr
Help shape the technology that enables a global organisation to do its best work. As Senior Manager, Platform Engineering, you’ll lead the team responsible for Diligent’s Atlassian and Microsoft platforms while setting the architectural direction for the wider internal IT estate. You’ll combine people leadership, enterprise platform strategy and hands-on technical judgement to create secure, reliable and scalable experiences for employees worldwide. From modernising service management and automating joiner, mover and leaver processes to enabling AI safely through Microsoft Copilot and Atlassian Rovo, your work will reduce friction, strengthen governance and deliver measurable business impact. Working across IT, Security, HR, Finance, Legal, Compliance and business teams, you’ll turn complex requirements into well-governed platforms that are easy to use, resilient and ready for the future. Here’s a breakdown of what you’ll do (not all of it, just the important stuff) Lead, coach and grow a global team of platform engineers and systems administrators, building a high-performing and inclusive culture. Own the strategy, architecture, governance and roadmap for Atlassian Cloud, including Jira, Jira Service Management, Confluence, Atlassian Guard and Rovo. Set the direction for Diligent’s Microsoft 365 E5 estate, including Teams, SharePoint, Exchange Online, Intune, Defender, Purview, Power Platform and Copilot. Design scalable integration and automation patterns across identity, HRIS, ITSM and business systems using APIs, event-driven automation, Okta Workflows, Power Platform and scripting. Partner with IT Support to improve self-service, automate repetitive work and reduce ticket volume, escalation effort and time to resolution. Establish strong standards for security, access governance, AI adoption, reliability, compliance and business continuity across the internal technology estate. These are the essentials you’ll need to get an interview Significant experience in i
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An Overview of this role We are seeking a Staff Product Manager to serve as an internal PM embedded within this team. This is not a traditional external-facing product role—it is an internal platform product leadership position. You will own the roadmap for our enterprise systems, act as the strategic voice of the business within engineering, and bring senior product craft to a team of Analysts and engineers who build and operate GitLab's revenue infrastructure. This role is ideal for a seasoned product leader who has deep Quote-to-Cash or Finance domain knowledge, thrives at the intersection of business strategy and techni
From $108.4K/yr
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As an Senior AI Engineer at GitLab, you'll help build the foundation for GitLab's transformation into an AI-first company. Reporting to the Director, Enterprise AI, you'll be a hands-on technical leader responsible for delivering internal AI-powered solutions that drive measurable business outcomes. Building fast matters, but it's not enough on its own. This role starts with understanding the real problem: mapping how work moves across teams, tools, and handoffs, identifying the true constraint, and validating whether AI is the right solution before you begin development. From there, you'll take ownership
Other cities to consider
More places hiring for this role
Get new application security head jobs in United States by email
Daily job updates · Unsubscribe anytime