1

Application Security Engineer Jobs in Colorado (NOW HIRING)

Partner with DevOps to integrate security into CI/CD pipelines, Infrastructure as Code, containers, Kubernetes, and cloud workloads, including SAST, DAST, Snyk, and other application security ...

Security Engineering Manager

Denver, CO · On-site

$155K - $180K/yr

This role is ideal for an engineering-first leader who thrives in a hands-on environment and is ... Establish and mature cloud security and application security practices, including secure ...

Senior AI Security Engineer

Boulder, CO · On-site +1

$118K - $162K/yr

Bachelor's degree in Computer Science, cybersecurity, or a related technical field required * 5+ years of experience in application security, cloud security, or AI/ML engineering, with at least 2 ...

Job Title: Security Engineer Location: Denver, CO Type: Direct Hire Our client in the Denver ... 5) Application logging experience. Desired Skills: 1) ERP Experience. 2) Legal industry ...

Help Product, Engineering, GRC, IT, and Security teams make informed decisions about AI adoption ... Hands-on experience with application security fundamentals, including threat modeling, SAST/DAST ...

Job Title: Security Engineer Location: Denver, CO Type: Direct Hire Our client in the Denver ... 5) Application logging experience. Desired Skills: 1) ERP Experience. 2) Legal industry ...

Help Product, Engineering, GRC, IT, and Security teams make informed decisions about AI adoption ... Hands-on experience with application security fundamentals, including threat modeling, SAST/DAST ...

New

Senior Product Security Engineer

Golden, CO · On-site

$118K - $162K/yr

Demonstrated focus on application security / cybersecurity. * Experience working with Internet of ... College degree in Computer Engineering, Computer Science, Software Engineering, Cybersecurity, or ...

Mobius is seeking Advanced Security Engineers to support the Missile Defense Agency (MDA) Special Access Program Central Office (SAPCO) in the National Capital region, Huntsville, AL, and Colorado ...

Showing results 41-60

Application Security Engineer information

See Colorado salary details

$31

$69

$101

How much do application security engineer jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for application security engineer in Colorado is $69.82, according to ZipRecruiter salary data. Most workers in this role earn between $59.42 and $79.38 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are the most commonly searched types of Application Security Engineer jobs in Colorado?

The most popular types of Application Security Engineer jobs in Colorado are:

What job categories do people searching Application Security Engineer jobs in Colorado look for?

The top searched job categories for Application Security Engineer jobs in Colorado are:

What cities in Colorado are hiring for Application Security Engineer jobs?

Cities in Colorado with the most Application Security Engineer job openings:

What are popular job titles related to Application Security Engineer jobs in CO?

For Application Security Engineer jobs in CO, the most frequently searched job titles are:

Infographic showing various Application Security Engineer job openings in Colorado as of September 2026, with employment types broken down into 62% Full Time, and 38% Contract. Highlights an 82% In-person, and 18% Hybrid job distribution, with an average salary of $145,232 per year, or $69.8 per hour.

Senior Information Security Engineer

Lafayette, CO • On-site, Remote

Full-time

Posted 25 days ago


Job description

Position Description:
KPA is seeking a Senior Information Security Engineer to serve as the senior technical counterpart to the Director of Security & Technology. This role owns KPA's security platforms, cloud security, identity, automation, and technical security initiatives. The ideal candidate is a hands-on security engineer with strong cloud and infrastructure experience who can independently lead complex security projects, partner effectively with IT Operations and DevOps, and continuously improve KPA's security posture.
Responsibilities:
  • Own KPA's enterprise security platforms, including CrowdStrike, Rapid7 (InsightIDR, InsightVM, InsightAppSec, MDR), Cisco Umbrella, Cisco Duo, KnowBe4, and related technologies.
  • Lead vulnerability management and remediation, endpoint security, identity security, privileged access, penetration testing, and security hardening initiatives.
  • Lead security incident response, investigations, containment, remediation, and post-incident reviews.
  • Own the ongoing operation of SOC 2 controls, security audit requirements, and technical compliance initiatives.
  • Own Cisco Meraki security, VPN infrastructure, network security controls, and secure cloud connectivity.
  • Secure Azure, AWS, Microsoft 365, Entra ID, AWS Identity Center, Auth0, and cloud-native workloads using modern security best practices.
  • Administer and improve identity governance across Microsoft Entra ID, Cisco Duo, AWS Identity Center, Auth0, SSO, SCIM, Conditional Access, PIM, privileged accounts, service accounts, and authentication architecture.
  • Partner with DevOps to integrate security into CI/CD pipelines, Infrastructure as Code, containers, Kubernetes, and cloud workloads, including SAST, DAST, Snyk, and other application security technologies.
  • Own and continually improve KPA's cloud security posture management, workload protection, identity controls, logging, alerting, detection engineering, and remediation processes.
  • Own email security across Microsoft 365, SendGrid, Amazon SES, SPF, DKIM, DMARC, and phishing protection.
  • Build security automation using PowerShell, Python, Microsoft Graph, REST APIs, and AI-assisted development.
  • Lead security assessments for new vendors, SaaS platforms, cloud services, and third-party integrations; administer third party vendor management (TPVM) and support ongoing vendor risk management.
  • Administer and improve KPA's security awareness program, security policies, standards, and technical procedures.
  • Support AI security and governance initiatives, including ChatGPT Enterprise, Claude, MCP, and emerging AI technologies.
  • Support security architecture reviews for new cloud services, platforms, integrations, and technical initiatives.
  • Proactively identify security gaps, technical debt, and opportunities to improve KPA's security posture through automation, AI, and modern engineering practices.

Qualifications:
  • 5+ years of experience in security engineering, cloud security, infrastructure security, or a related senior technical role.
  • Strong knowledge of identity security, endpoint security, vulnerability management, network security, incident response, and zero trust principles.
  • Experience securing Azure, AWS, Microsoft 365, Entra ID, Windows, and Linux.
  • Familiarity with CI/CD pipelines, Kubernetes, container security, application security scanning, and DevSecOps practices.
  • Scripting and automation experience using PowerShell, Python, REST APIs, or similar technologies.
  • Experience supporting SOC 2 & NIST CSF or comparable security and compliance frameworks.
  • Relevant certifications such as CompTIA Security+, CISSP, CCSP, AWS Certified Security, or equivalent certifications are preferred.
  • Excellent communication, documentation, project leadership, and problem-solving skills.
  • Bachelor's degree in Computer Science, Information Technology or Cybersecurity or equivalent experience.

Success Criteria:
  • Work ethic that aligns with KPA's core values:
    • Trust: earning trust through integrity, expertise, and acting in the client's best interest.
    • Innovation: continuously seeking out ways to better serve clients.
    • Excellence: holding ourselves to high standards in everything we do.
    • Results: moving with purpose to deliver meaningful outcomes.
  • Owns and continually improves KPA's enterprise security platforms and technical security controls.
  • Improves KPA's security posture across endpoints, identity, networking, cloud, and DevOps environments.
  • Delivers complex security initiatives with strong planning, communication, documentation, testing, and post-implementation validation.
  • Reduces manual security work through automation and modern engineering practices.
  • Serves as the senior escalation point for complex security incidents and technical security issues.
  • Partners effectively with IT Operations and DevOps to embed security into operational and development workflows.

Physical Requirements:
Physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
  • Working at a computer typing and view a screen - Constantly
  • Stationary sitting or standing - Constantly
  • Visual Recognition - Constantly
  • Hearing/Listening - Occasionally
  • Communicating verbally and/or in writing - Occasionally
  • Travel - Seldom

Compensation:
  • Annual base salary range between $110-150k commensurate with experience.
  • Bonus potential of 10% annually.
  • This is a full time, exempt position.