1

Application Security Jobs (NOW HIRING)

Application Security

Bethesda, MD · On-site

$63 - $84/hr

Application Security Location: Bethesda, MD Duration: Fulltime Client: Direct Client Duties Systematically address application security issues and develop secure coding practices for multiple ...

Application Security Engineer

Nashville, TN · On-site

$56.75 - $75.75/hr

The Application Security Engineer will serve as a trusted technical advisor, performing application security assessments, supporting secure software development practices, and helping engineering ...

Manager Application Security

Boston, MA · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required with 4 days on site and 1 remote in one of the following organizational hubs: Johnston, RI ...

Manager Application Security

Johnston, RI · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required with 4 days on site and 1 remote in one of the following organizational hubs: Johnston, RI ...

Manager Application Security

Iselin, NJ · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required with 4 days on site and 1 remote in one of the following organizational hubs: Johnston, RI ...

Manager Application Security

Boston, MA · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required with 4 days on site and 1 remote in one of the following organizational hubs: Johnston, RI ...

Application Security Engineer

Media, PA · On-site

$58.50 - $78/hr

Application Security Engineer Location: Corporate Department: Information Technology Job Summary: The Application Security Engineer is responsible for operating, supporting, maintaining, and ...

Manager Application Security

Manchester, NH · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required with 4 days on site and 1 remote in one of the following organizational hubs: Johnston, RI ...

Manager Application Security

Manchester, NH · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required with 4 days on site and 1 remote in one of the following organizational hubs: Johnston, RI ...

Manager Application Security

Westwood, MA · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required with 4 days on site and 1 remote in one of the following organizational hubs: Johnston, RI ...

Manager Application Security

Iselin, NJ · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required with 4 days on site and 1 remote in one of the following organizational hubs: Johnston, RI ...

Manager Application Security

Johnston, RI · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required with 4 days on site and 1 remote in one of the following organizational hubs: Johnston, RI ...

Manager Application Security

Johnston, RI · On-site +1

$133K - $190K/yr

Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required with 4 days on site and 1 remote in one of the following organizational hubs: Johnston, RI - Westwood OR Boston ...

Application Security Engineer

Rockville, MD · On-site

$60 - $80/hr

Application Security Engineer Location: Rockville, MD or McLean, VA (Hybrid - 3 days onsite with 2 days remote) Duration: 6 Months with possible extension Interview process: Onsite panel Job Summary:

Application Security Engineer

Phoenix, AZ · On-site

$58.25 - $78/hr

The Application Security Engineer is responsible for supporting the security and privacy of the SmartRent platform through the management of information security risk, system resilience, and ...

next page

Showing results 1-20

Application Security information

See salary details

$38

$53

$95

How much do application security jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for application security in the United States is $53.69, according to ZipRecruiter salary data. Most workers in this role earn between $42.79 and $55.77 per hour, depending on experience, location, and employer.

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications such as Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, authorization, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, penetration testing, and code reviews to identify and fix security issues throughout the development lifecycle.
What cities are hiring for Application Security jobs? Cities with the most Application Security job openings:
What states have the most Application Security jobs? States with the most job openings for Application Security jobs include:
Infographic showing various Application Security job openings in the United States as of August 2026, with employment types broken down into 77% Full Time, 18% Part Time, and 5% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $111,673 per year, or $53.7 per hour.

Application Security | Application Security Engineer

PepsiCo

Plano, TX

$80K - $134K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 9 days ago


PepsiCo rating

7.5

Company rating: 7.5 out of 10

Based on 895 frontline employees who took The Breakroom Quiz

155th of 437 rated food and drinks producers


Job description

Overview

PepsiCo's Global Application Security Program integrates security into software development at enterprise scale. Our mission is to make application security risks visible, actionable, and measurable so they can be remediated efficiently.

This role is responsible for implementing and operating foundational application security controls, optimizing security tooling, and enabling security automation at scale. The ideal candidate will improve signal quality, reduce false positives, and help developers remediate the risks that matter most.

Responsibilities
  • Configure, tune, and maintain application security tools to maximize accuracy, coverage, and performance.
  • Establish and maintain security baselines, policies, and scanning rules aligned with organizational standards.
  • Improve finding quality by reducing false positives and ensuring results accurately reflect business risk.
  • Develop and maintain risk-based prioritization models to focus remediation on the highest-impact vulnerabilities.
  • Integrate security tool outputs into centralized vulnerability management workflows.
  • Validate findings, investigate false positives, and track remediation through closure.
  • Partner with engineering teams to implement security guardrails and secure development practices.
  • Continuously evaluate and optimize security tooling, processes, and platform effectiveness.
  • Perform targeted security assessments of high-risk applications to identify coverage gaps and critical vulnerabilities.
  • Manage and optimize Web Application Firewall (WAF) and CDN security capabilities, including DDoS protection, bot mitigation, and traffic management.
  • Evaluate emerging security technologies and recommend improvements to increase automation, coverage, and operational efficiency.
  • Develop and maintain technical documentation, operational runbooks, and security standards.
  • Support vulnerability response, remediation activities, and application security incident investigations.
  • Participate in Agile development, including sprint planning, backlog refinement, estimation, stand-ups, and retrospectives.
  • Develop metrics and KPIs to measure program effectiveness and drive continuous improvement.
  • Participate in a 24/7 on-call rotation, including weekends and holidays.

Compensation and Benefits:

  • The expected compensation range for this position is between $80,200 - $134,250.
  • Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
  • Bonus based on performance and eligibility target payout is 8% of annual salary paid out annually.
  • Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
  • In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.
Qualifications

Years of Experience

  • Bachelor's degree in computer science, Engineering, or a related technical field, with 3-4 years of relevant professional experiences or equivalent in job experience

Mandatory Technical Skills

  • Experience with secure software development and identifying vulnerabilities within application code.
  • Experience analyzing application security findings and providing actionable remediation guidance.
  • Hands-on experience with application security, vulnerability management, and security engineering.
  • Experience securing cloud-native applications in AWS (preferred), Azure, or GCP.
  • Proficiency with Python and/or Go.
  • Experience with SAST, SCA, Secrets, DAST, API, and Container security tools.
  • Experience tuning security scanners and reducing false positives, including OWASP Top 10 findings.
  • Experience deploying, configuring, and managing Web Application Firewalls (WAFs).
  • Knowledge of Policy-as-Code frameworks (OPA, HashiCorp Sentinel, or similar).
  • Strong understanding of web and mobile application security, including the OWASP Top 10, SSRF, RCE, deserialization, and memory corruption vulnerabilities.
  • Familiarity with securing CI/CD pipelines and integrating security into development workflows.
  • Understanding of API security, including OAuth, JWT, authentication, authorization, and access control.
  • Understanding of CDN security, including DDoS protection, bot mitigation, rate limiting, and caching.
  • Understanding of cryptographic principles, key management, and encryption best practices.

Non-technical Skills:

  • Strong written and verbal communication skills.
  • High integrity with sound judgment and accountability.
  • Excellent analytical, problem-solving, and critical thinking abilities.
  • Self-motivated, curious, and committed to continuous learning.
  • Strong collaboration, relationship-building, and influencing skills.
  • Comfortable working in a fast-paced, global environment with changing priorities and ambiguity.
  • Ability to perform effectively under pressure.

Differentiating Behaviors:

  • Demonstrates curiosity, innovation, and a continuous improvement mindset.
  • Makes sound decisions by balancing technical, business, and operational trade-offs.
  • Remains calm, organized, and methodical in high-pressure situations.
  • Effectively prioritizes work and manages competing commitments.
>

Our Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance. All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status. PepsiCo is an Equal Opportunity Employer: Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity / Age If you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law & EEO is the Law Supplement documents. View PepsiCo EEO Policy. Please view our Pay Transparency Statement

Employment Type: FULL_TIME

What PepsiCo employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


PepsiCo logo

About PepsiCo

Sourced by ZipRecruiter

PepsiCo products are enjoyed by consumers more than one billion times a day in more than 200 countries and territories around the world. PepsiCo generated $86 billion in net revenue in 2022, driven by a complementary beverage and convenient foods portfolio that includes Lay's, Doritos, Cheetos, Gatorade, Pepsi-Cola, Mountain Dew, Quaker, and SodaStream. PepsiCo's product portfolio includes a wide range of enjoyable foods and beverages, including many iconic brands that generate more than $1 billion each in estimated annual retail sales.

Industry

Food and drink manufacturing

Company size

10,000+ Employees

Headquarters location

Purchase, NY, US

Year founded

1965