1

Application Security Engineer Jobs (NOW HIRING)

Application Security Engineer

Nashville, TN ยท On-site

$56.75 - $75.75/hr

The Application Security Engineer will serve as a trusted technical advisor, performing application security assessments, supporting secure software development practices, and helping engineering ...

Application Security Engineer

Coral Gables, FL ยท On-site

$55.75 - $74.50/hr

The Application Security Engineer must understand development, coding, security engineering, and secure systems configurations. This position ensures that every step of the software development ...

Application Security Engineer

Media, PA ยท On-site

$58.50 - $78/hr

Application Security Engineer Location: Corporate Department: Information Technology Job Summary: The Application Security Engineer is responsible for operating, supporting, maintaining, and ...

Application Security Engineer

$60.25 - $80.25/hr

The Application Security Engineer supports secure coding standards, threat modeling, static and dynamic testing, and secure secrets management. This position plays a critical role in strengthening ...

Application Security Engineer

Wawa, PA

$57.25 - $76.25/hr

Application Security Engineer Location: Corporate Department: Information Technology Job Summary: The Application Security Engineer is responsible for operating, supporting, maintaining, and ...

Application Security Engineer

Washington, DC ยท On-site

$66.50 - $89/hr

Work with application developers ensure adoption of security principals and best practices. 6. Provides direction and support in security management and security architecture standards and ...

APPLICATION SECURITY ENGINEER

Fairfax, VA ยท On-site

$60 - $80.25/hr

Application Security Engineer Location: Onsite in Fairfax, VA 3 days and in Washington, DC 2 days per week. Duration: Long Term Contract Positions Require a Secret Clearance The Application Security ...

Application Security Engineer

Atlanta, GA ยท On-site

$56.50 - $75.50/hr

The Application Security Engineer will play a key role in reducing security vulnerabilities across hundreds of web properties, supporting compliance initiatives, and implementing secure development ...

next page

Showing results 1-20

Application Security Engineer information

See salary details

$29

$66

$96

How much do application security engineer jobs pay per hour?

As of Aug 4, 2026, the average hourly pay for application security engineer in the United States is $66.40, according to ZipRecruiter salary data. Most workers in this role earn between $56.49 and $75.48 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What cities are hiring for Application Security Engineer jobs? Cities with the most Application Security Engineer job openings:
What are the most commonly searched types of Application Security Engineer jobs? The most popular types of Application Security Engineer jobs are:
Who are the top companies hiring for Application Security Engineer jobs? The top employers for Application Security Engineer jobs are:
What states have the most Application Security Engineer jobs? States with the most job openings for Application Security Engineer jobs include:
What job categories do people searching Application Security Engineer jobs look for? The top searched job categories for Application Security Engineer jobs are:
Infographic showing various Application Security Engineer job openings in the United States as of July 2026, with employment types broken down into 77% Full Time, 17% Part Time, 1% Temporary, and 5% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $138,117 per year, or $66.4 per hour.

Application Security Engineer

Umusic

Nashville, TN โ€ข On-site

$56.75 - $75.75/hr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 20 days ago


Job description

We are UMG, the Universal Music Group. We are the world's leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.

How we LEAD:

We are currently seeking an Application Security Engineer to join UMG's global Tech Security & Identity organization. Reporting to the Manager, Security Engineering and Vulnerability, this role is responsible for improving the security of internally developed applications and cloud services by partnering closely with engineering, infrastructure, and product teams to integrate security throughout the software development lifecycle.

The Application Security Engineer will serve as a trusted technical advisor, performing application security assessments, supporting secure software development practices, and helping engineering teams identify and address security risks early in the development process. This role combines hands-on technical expertise with collaboration across development and security teams to strengthen UMG's application security posture while enabling innovation.

The ideal candidate has experience in application security, secure software development, cloud-native technologies, and developer enablement, along with strong communication skills and a passion for building secure software.

How you'll CREATE:
  • Perform application security assessments, threat modeling, and secure design reviews for internally developed and third-party applications.

  • Conduct application security testing using static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), API security testing, and manual validation techniques.

  • Review source code and provide secure coding guidance based on OWASP best practices and secure development principles.

  • Partner with software engineering teams to identify security risks and recommend practical remediation strategies throughout the software development lifecycle.

  • Collaborate with DevOps teams to integrate application security testing into CI/CD pipelines and software delivery workflows.

  • Provide security architecture guidance for new applications, APIs, cloud-native services, and technology integrations.

  • Support implementation of modern authentication and authorization technologies, including OAuth, OpenID Connect (OIDC), SAML, and other identity standards.

  • Evaluate, implement, and maintain application security tools and help improve security testing coverage across the development lifecycle.

  • Develop automation and scripting to improve application security testing, reporting, and engineering workflows.

  • Participate in security reviews for new technologies, cloud services, and third-party applications.

  • Support investigation and remediation of application-layer security incidents and vulnerabilities when required.

  • Create reusable security guidance, reference architectures, and technical documentation to improve secure development practices across engineering teams.

  • Deliver secure coding guidance and developer education to promote security-by-design principles.

  • Collaborate with security, infrastructure, and identity teams to continuously improve enterprise application security capabilities.

Bring your VIBE:
  • Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience.

  • 5+ years of experience in Application Security, Security Engineering, Software Engineering, or a related discipline with a security focus.

  • Experience performing application security assessments, threat modeling, and secure architecture reviews.

  • Strong understanding of secure coding principles and common application vulnerabilities, including the OWASP Top 10 and OWASP API Security Top 10.

  • Experience with application security testing technologies including SAST, DAST, SCA, API security testing, and penetration testing methodologies.

  • Experience working with modern application architectures, REST APIs, microservices, and cloud-native technologies.

  • Experience integrating security into CI/CD pipelines and DevSecOps workflows.

  • Experience working within AWS, Azure, or Google Cloud Platform environments.

  • Knowledge of modern authentication and authorization technologies including OAuth, OpenID Connect (OIDC), SAML, and JWT.

  • Understanding of security frameworks and standards including OWASP, NIST Cybersecurity Framework, and ISO 27001.

  • Strong analytical, problem-solving, and communication skills with the ability to work effectively across technical and non-technical teams.

Desirable Qualifications

  • Experience implementing Secure Software Development Lifecycle (SSDLC) practices within Agile development environments.

  • Experience with application security platforms such as GitHub Advanced Security, Microsoft Defender for Cloud, Checkmarx, Veracode, Burp Suite, Semgrep, or similar tools.

  • Experience with container security, Kubernetes, and Infrastructure as Code security.

  • Experience developing automation using Python, PowerShell, or similar scripting languages.

  • Experience performing security assessments of cloud-native applications and APIs.

  • Professional certifications such as CSSLP, GIAC GWEB, AWS Certified Security Specialty, Security+, CISSP, or equivalent.

  • Experience working within large global enterprise environments.

  • Experience in media, entertainment, or similarly distributed global organizations.

Perks Playlist:

Join an entrepreneurial, global organization where authenticity, boldness, creativity, connection, drive, and insight aren't just values-they're how we work every day. Here are some of the ways we support you along the way (and just a few of the benefits we offer):

  • Comprehensive medical, dental, and vision coverage

  • Including 100% coverage for out-patient in-network mental health services

  • Fertility coverage for eligible medical plan participants

  • Wellbeing reimbursements for fitness classes, spa treatments, meal services, travel, and so much more (up to $720/year)

  • Student Loan Repayment Assistance and Tuition Reimbursement

  • 401(k) with 100% immediate vesting on the first 5% of your contributions, plus an additional UMG contribution

A variety of ways to prioritize much-needed time away from work including:

  • Flexible Paid Time Off (PTO) for exempt employees

  • 3-weeks PTO for non-exempt employees

  • 2-weeks paid Winter Break

  • 10 Company Holidays (including Juneteenth and Wellbeing Day)

  • Summer Fridays (between Memorial Day and Labor Day)

  • Generous paid parental leave for every type of parent

Check out our full overview of benefits on the Perks Playlist page of the career site.

Disclaimer: This job description only provides an overview of job responsibilities that are subject to change.
Universal Music Group is an Equal Opportunity Employer

We are an E-Verify employer in Alabama, Arizona, Georgia, Mississippi, North Carolina, South Carolina, Tennessee, and Utah.


Please note, UMG is not enrolled in E-Verify in California and New York, and cannot support employment of candidates whose employer must enroll in E-Verify, for example candidates on STEM-OPT.

For more information, please click on the following links.

E-Verify Participation Poster:English / Spanish

E-Verify Right to Work Poster:English|Spanish


Job Category:Technology