1

Application Security Engineer Jobs in California

The Opportunity We're hiring our first dedicated Lead Application Security Engineer to own the security of the Ivo platform end to end. You'll partner directly with our Head of IT & Security and ...

As an Application Security Engineer at Esri, you will fill a critical role in helping secure Esri's intellectual property and sensitive data against a variety of complex threats with support from all ...

Job Purpose The Application Security Engineer is responsible for strengthening the security of our applications, platforms, and development processes. This position partners with software engineers ...

Application Security Engineer

Torrance, CA · On-site

$61.25 - $82/hr

Strong knowledge of secure development practices Deep knowledge of common web application vulnerabilities (e.g. XSS, CSRF, clickjacking) and their mitigation strategies Knowledge of system security ...

As our first dedicated Application Security Engineer, you will define the security architecture for everything we ship. You will work directly with our Engineering teams to identify vulnerabilities ...

As our first dedicated Application Security Engineer, you will define the security architecture for everything we ship. You will work directly with our Engineering teams to identify vulnerabilities ...

You'll work directly with product, engineering, infrastructure, and AI teams to make security a practical advantage across the company. You'll own high-impact security work across application ...

AI Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

About the Role As our Security Engineer, Application & AI, you will own the security of our products and application layer - secure development practices, agent security, third-party integration ...

Showing results 21-40

Application Security Engineer information

See California salary details

$29

$65

$95

How much do application security engineer jobs pay per hour?

As of Aug 10, 2026, the average hourly pay for application security engineer in California is $65.53, according to ZipRecruiter salary data. Most workers in this role earn between $55.77 and $74.47 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are the most commonly searched types of Application Security Engineer jobs in California? The most popular types of Application Security Engineer jobs in California are:
What are popular job titles related to Application Security Engineer jobs in California? For Application Security Engineer jobs in California, the most frequently searched job titles are:
What job categories do people searching Application Security Engineer jobs in California look for? The top searched job categories for Application Security Engineer jobs in California are:
What cities in California are hiring for Application Security Engineer jobs? Cities in California with the most Application Security Engineer job openings:
What are popular job titles related to Application Security Engineer jobs in CA? For Application Security Engineer jobs in CA, the most frequently searched job titles are:
Infographic showing various Application Security Engineer job openings in California as of August 2026, with employment types broken down into 82% Full Time, and 18% Contract. Highlights an 76% In-person, and 24% Remote job distribution, with an average salary of $136,308 per year, or $65.5 per hour.

Application Security Engineer

Figure Lending

San Francisco, CA

$120K - $179K/yr

Full-time

Re-posted yesterday


Job description

About Figure

Figure (NASDAQ: FIGR) is transforming capital markets through blockchain. We're proving that blockchain isn't just theory - it's powering real products used by hundreds of thousands of consumers and institutions.

By combining blockchain's transparency and efficiency with AI-driven automation, we've reimagined how loans are originated, funded, and traded in secondary markets. From faster processing times to lower costs and reduced bias, our technology is helping borrowers, investors, and financial institutions achieve better outcomes.

Together with our 170+ partners, we've originated over $22 billion in home equity loans (HELOCs) on our blockchain-native platform, making Figure the largest non-bank provider of home equity financing in the U.S. Figure's ecosystem also includes YLDS, an SEC-registered yield-bearing stablecoin that operates as a tokenized money market fund, and several other products and platforms that are reshaping consumer finance and capital markets.

We're proud to be recognized as one of Forbes' Most Innovative Fintech Startups in 2025 and Fast Company's Most Innovative Companies in Finance and Personal Finance.

About the Role

As an Application Security Engineer at Figure, you will be pivotal in the security of our software from the first line of code through deployment. You'll build and scale our vulnerability management program, embed secure coding practices into engineering workflows, and help ensure security standards are met at every stage of the software development lifecycle. We're looking for a collaborative, hands-on engineer with a strong background in reading and writing code. You'll partner closely with Engineering, DevOps, and IT to ensure our security processes are resilient, scalable, and seamlessly integrated into our workflows.

What You'll Do

  • Architect, design, and implement end-to-end security solutions, including firewalls, intrusion detection, encryption protocols, security event management, and cloud security controls.
  • Collaborate with DevOps to integrate security into CI/CD pipelines, ensuring automation and repeatability of secure deployments.
  • Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.
  • Lead cross-team initiatives that significantly improve our security posture while balancing speed and innovation.
  • Mentor engineers on security best practices and build a culture of security by design.
  • Actively participate in incident response, on-call rotations, and post-incident reviews to continuously improve defenses.
  • Leverage AI to augment threat hunting, vulnerability scanning, and triage, using it to surface signal faster and reduce manual review load.
  • Design and build AI agents to perform in-depth testing and analysis of our infrastructure and code.

What We Look For

  • Improve and run Figure's vulnerability management program including triage, prioritization, tracking remediation, and reporting on risk reduction over time.
  • Collaborate with DevOps to integrate security gates at various points throughout the software development lifecycle, ensuring automation and repeatability of secure deployments.
  • Manage third-party penetration tests, including scoping, vendor coordination, and tracking remediation of findings.
  • Automate sources of toil, such as routine patching or dependency upgrades.
  • Conduct threat modeling and security reviews for new features and services, partnering with engineering teams early in the design process.
  • Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.
  • Lead cross-team initiatives that significantly improve our security posture while balancing speed and innovation.
  • Actively participate in incident response, on-call rotations, and post-incident reviews to continuously improve defenses.
  • Hands-on proficiency with AI-assisted security tooling and a practical sense of its strengths and limits.
  • Adhere to all company security policies and data handling procedures.
  • Complete mandatory security awareness training within required timeframes.
  • Promptly report any suspected security incidents or suspicious activity to the Security team.

Salary

  • Base Compensation Range: $120,000-$179,520/yr
  • 25% annual bonus target, paid quarterly
  • Company equity in the form of RSUs

This is the compensation range for the role in the United States. Actual compensation may vary based on a candidate's experience, skills, location, internal equity, and evolving business needs. While most offers are generally made within the middle of the range, final compensation is determined based on the factors above.

Benefits

  • Comprehensive medical, dental, and vision coverage, with 100% employer-paid premiums for employees and their dependents on select plans
    Company HSA, FSA, Dependent Care FSA, 401(k), and commuter benefits
    Employer-paid life and disability insurance
    11 observed holidays and PTO plan
    Up to 12 weeks of paid family leave
    Continuing education reimbursement

Depending on your residential location certain laws might regulate the way Figure manages applicant data. California Residents, please review our California Employee and General Workforce Privacy Notice for further information. By submitting your application, you are agreeing and acknowledging that you have read and understand the above notice.

Figure will not sponsor work visas for this position. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

#LI-SB1 #LI-Hybrid