1

Application Security Engineer Jobs in California

Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

Zof AI is seeking an Application Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent ...

Application Security Engineer

Sunnyvale, CA · On-site

$70 - $93.50/hr

We are looking for an Application Security Engineer with a strong focus on Vulnerability Management to help secure Cerebras software, infrastructure, and AI platforms. You will own and evolve key ...

Application Security Engineer

Sunnyvale, CA · On-site

$69 - $92.25/hr

We are looking for an Application Security Engineer with a strong focus on Vulnerability Management to help secure Cerebras software, infrastructure, and AI platforms. You will own and evolve key ...

Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

We're hiring an Application Security Engineer to own security across Opal's product and platform - and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly ...

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud ...

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud ...

Application Security Engineer

Palo Alto, CA · On-site

$69.25 - $92.50/hr

They are seeking an innovative Application Security Engineer responsible for ensuring the security and integrity of cloud-native applications throughout the software development lifecycle, with a ...

Become a key player in our Information Security team as a Senior Application Security Engineer, where you will leverage your expertise in application security, security engineering, and software ...

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud ...

Become a key player in our Information Security team as a Senior Application Security Engineer, where you will leverage your expertise in application security, security engineering, and software ...

... Engineering, Information Systems, or equivalent years of experience in a related technical field * 3+ years of experience in the field of application security or related security role * Passion for ...

We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC). In this role, you'll have ...

... Engineering, Information Systems, or equivalent years of experience in a related technical field * 3+ years of experience in the field of application security or related security role * Passion for ...

The Staff Application Security Engineer will partner with the Engineering, DevOps, Product, and Release Management teams to embed security as a foundational part of software design and delivery. The ...

next page

Showing results 1-20

Application Security Engineer information

See California salary details

$29

$65

$95

How much do application security engineer jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for application security engineer in California is $65.53, according to ZipRecruiter salary data. Most workers in this role earn between $55.77 and $74.47 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are the most commonly searched types of Application Security Engineer jobs in California?

The most popular types of Application Security Engineer jobs in California are:

What job categories do people searching Application Security Engineer jobs in California look for?

The top searched job categories for Application Security Engineer jobs in California are:

What cities in California are hiring for Application Security Engineer jobs?

Cities in California with the most Application Security Engineer job openings:

What are popular job titles related to Application Security Engineer jobs in CA?

For Application Security Engineer jobs in CA, the most frequently searched job titles are:

Infographic showing various Application Security Engineer job openings in California as of September 2026, with employment types broken down into 63% Full Time, and 37% Contract. Highlights an 82% In-person, and 18% Hybrid job distribution, with an average salary of $136,308 per year, or $65.5 per hour.

Application Security Engineer

San Francisco, CA • On-site

$69.25 - $92.50/hr

Other

Posted 15 days ago


Job description

Zof AI is seeking an Application Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent workloads and tenants, secrets and credential handling, supply chain security, and the enterprise controls that buyers audit before they trust us with a repository. If you have worked as an Application Security Engineer, Product Security Engineer, Cloud Security Engineer, or Infrastructure Security Engineer, this is that discipline at Zof AI. The ideal candidate thinks in threat models, ships controls instead of policy documents, and treats customer code as the most sensitive asset we hold.

Engineering · Mid to Senior · Full-time · On-site · San Francisco, CA

Responsibilities
  • Own the security posture of a platform that reads, executes, and modifies customer source code.
  • Harden the sandbox, tenant, and workload isolation boundaries agents run inside.
  • Design secrets management, credential handling, and least privilege access across the platform.
  • Secure the software supply chain from dependencies through build and deploy.
  • Build the technical controls behind SOC 2 and enterprise security requirements.
  • Teach our agent fleets to find, prove, and remediate real vulnerabilities in customer code.
  • Run threat modeling, design reviews, and incident response as a regular practice.
  • Partner with engineering and sales to clear enterprise security reviews and questionnaires.
Requirements
  • Experience securing production software systems or cloud infrastructure.
  • Strong software engineering foundation and comfort shipping code, not just reviewing it.
  • Working knowledge of application security and common vulnerability classes.
  • Experience with cloud security, identity, and access control.
  • Familiarity with compliance frameworks such as SOC 2.
  • Clear written and verbal communication.
  • Comfort operating in a fast-moving environment.
  • High ownership of security outcomes, not just findings.
Nice to have
  • Experience with sandboxing, container isolation, or multi-tenant architecture.
  • Experience with LLM or agent security, including prompt injection and tool use risk.
  • Experience with static analysis, fuzzing, or automated vulnerability detection.
  • Experience leading enterprise security reviews or SOC 2 audit readiness.

Hands-on experience working with AI agents and threat modeling what they are allowed to do is required

#J-18808-Ljbffr