1

Application Security Engineer Jobs in California

AI Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

About the Role As our Security Engineer, Application & AI, you will own the security of our products and application layer - secure development practices, agent security, third-party integration ...

Showing results 41-60

Application Security Engineer information

See California salary details

$29

$65

$95

How much do application security engineer jobs pay per hour?

As of Aug 25, 2026, the average hourly pay for application security engineer in California is $65.53, according to ZipRecruiter salary data. Most workers in this role earn between $55.77 and $74.47 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are the most commonly searched types of Application Security Engineer jobs in California?

The most popular types of Application Security Engineer jobs in California are:

What job categories do people searching Application Security Engineer jobs in California look for?

The top searched job categories for Application Security Engineer jobs in California are:

What cities in California are hiring for Application Security Engineer jobs?

Cities in California with the most Application Security Engineer job openings:

What are popular job titles related to Application Security Engineer jobs in CA?

For Application Security Engineer jobs in CA, the most frequently searched job titles are:

Infographic showing various Application Security Engineer job openings in California as of August 2026, with employment types broken down into 85% Full Time, and 15% Contract. Highlights an 70% In-person, 5% Hybrid, and 25% Remote job distribution, with an average salary of $136,308 per year, or $65.5 per hour.

Senior Application Security Engineer

Tatari

Los Angeles, CA • Hybrid

$165K - $190K/yr

Full-time

Medical, Retirement, PTO

Re-posted 21 days ago


Job description

Tatari is on a mission to revolutionize TV advertising. Founded in 2016 to help transform the antiquated world of TV advertising through the intelligent application of AI and machine learning, Tatari helps some of the world's fastest growing brands including Chime, Calm, Tecovas, Manscaped, Saatva, and Liquid I.V., reach their customers using linear and streaming TV ads. Our platform combines sophisticated media buying with proprietary analytics to turn TV advertising into an automated, digital-like experience, enabling businesses of any size to advertise on TV.

That approach has earned Tatari broad industry recognition, including being named Best CTV AdTech Platform in the 8th annual MarTech Breakthrough Awards, as well as honors from Digiday (Best Connected TV Platform), AdExchanger (Most Innovative TV Advertising Technology), and Business Insider (Hottest AdTech Companies). Tatari has also been recognized as the Best Place to Work by Inc. Magazine. Backed by an executive team of former founders and senior leaders from companies including Shazam, TrueCar, AdapTV, LiveRail, Amazon, Google, Meta, Microsoft, and Yahoo, Tatari continues to scale rapidly as TV advertising enters its next major era.

We're a late-stage AdTech company with a recently attained SOC2 Type II attestation, and a clear mandate to mature our security and privacy posture.

We're looking for the right engineer to make it happen.

The Role:

As our first dedicated Application Security Engineer, you will define the security architecture for everything we ship. You will work directly with our Engineering teams to identify vulnerabilities, design mitigations, and build the tooling and automation that makes secure development the path of least resistance. You will report to the Head of Security as a key technical contributor to Tatari's Security program.

You write production-quality code. You think like an attacker. And you know how to bring engineers along with you.

Responsibilities:

  • Design and execute greenfield AppSec initiatives across Tatari's SaaS platform from threat modeling to remediation
  • Build and maintain security automation integrated into CI/CD pipelines and manage software supply chain risk
  • Own container security across build and runtime
  • Develop internal tooling and libraries that make secure coding easier for application engineers
  • Own SAST/DAST/SCA tooling: selection, tuning, CI/CD integration, and triage
  • Conduct application security reviews and threat models for new features and architectural changes
  • Identify and remediate vulnerabilities across APIs, services, and data pipelines
  • Partner with Engineering teams to establish secure coding standards and provide hands-on guidance
  • Assess and mitigate LLM-introduced risks in product features
  • Integrate agentic tooling into AppSec workflows to reduce toil
  • Contribute to security incident response when application-layer issues are involved

Qualifications:

  • Production Python experience with the engineering depth to review code meaningfully and build security tooling; Java or Rust is a bonus
  • Significant hands-on application security experience, ideally at a SaaS company, including working knowledge of established standards (OWASP Top 10, API Security Top 10, ASVS, SPVS, AISVS) and how common vulnerability classes manifest in production systems
  • Threat modeling experience with Product and Engineering teams
  • Experience building security tooling or automation (scripts, pipelines, libraries)
  • Familiarity with AWS and Kubernetes security controls as they relate to application-layer risks
  • Working knowledge of how LLMs introduce new attack surfaces and how to mitigate them, with practical experience using AI tools in security or engineering workflows
  • Demonstrated experience reviewing API designs and implementations for auth anti-patterns, token mismanagement, injection risks, and sensitive data exposure
  • Track record embedding with Engineering teams: code review, design consultation, and standards definition
  • Experience building or maturing an AppSec program where coverage, tooling, or process needed to be defined from scratch

Benefits:

  • Total compensation ($165,000-$190,000) 
  • Equity compensation
  • Health insurance coverage for you and your dependents
  • 401K, FSA, and commuter benefits
  • $150 monthly spending account
  • $1,000 annual continued education benefit
  • $500 Newbie Productivity Perk
  • Unlimited PTO and sick days
  • Monthly Company Wellness Day Off
  • Snacks, drinks, and catered lunches at the office
  • Team building events 
  • Hybrid RTO of 2 days per week in office. 

At Tatari, we believe in the importance of cultivating teams with diverse backgrounds and offering equal opportunities to all. We strive to create a welcoming, inclusive environment where every team member feels valued and diversity is celebrated.

#LI-HYBRID