1

Application Security Engineer Jobs in Boston, MA

Senior Application Security Engineer

Boston, MA ยท On-site

$63.75 - $85.25/hr

This role serves as the primary Application Security Engineering resource partnering with development, cloud, architecture, infrastructure, and vulnerability management teams to embed security ...

Staff Application Security Engineer

Boston, MA ยท On-site

$63.75 - $85.25/hr

Integrate AI into Application Security to Enable Secure-by-Design Engineering Drive the adoption of AI-enabled development practices that embed application security directly into the software ...

Staff Application Security Engineer

Boston, MA ยท On-site +1

$63.75 - $85.25/hr

As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll define the frameworks, methodologies, and architectural ...

Manager Application Security

Boston, MA ยท On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required ... As part of the cybersecurity organization, this role partners closely with engineering, platform ...

next page

Showing results 1-20

Application Security Engineer information

See Boston, MA salary details

$32

$72

$104

How much do application security engineer jobs pay per hour?

As of Aug 23, 2026, the average hourly pay for application security engineer in Boston, MA is $72.14, according to ZipRecruiter salary data. Most workers in this role earn between $61.39 and $82.02 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are popular job titles related to Application Security Engineer jobs in Boston, MA?

For Application Security Engineer jobs in Boston, MA, the most frequently searched job titles are:

What job categories do people searching Application Security Engineer jobs in Boston, MA look for?

The top searched job categories for Application Security Engineer jobs in Boston, MA are:

What cities near Boston, MA are hiring for Application Security Engineer jobs?

Cities near Boston, MA with the most Application Security Engineer job openings:

Infographic showing various Application Security Engineer job openings in Boston, MA as of August 2026, with employment types broken down into 100% Full Time. Highlights an 75% In-person, and 25% Remote job distribution, with an average salary of $150,050 per year, or $72.1 per hour.

Application Security Engineer

Overture Partners

Burlington, MA โ€ข On-site

$70 - $80/hr

Contractor

Medical, Life, Retirement

Posted 13 days ago


Job description

** Due to client requirements, applicants must be able to work on a w2 basis
** Onsite is required

Application Security Engineer
Job Overview
We are seeking an experienced Application Security Engineer to provide security leadership for a growing internal application development environment, including emerging AI-enabled solutions. This is a newly created role with an immediate need for someone who can embed practical security controls into the development lifecycle while partnering closely with engineering, data, security, and technology stakeholders.
To secure an interview, candidates should bring hands-on Application Security and Secure SDLC experience, understand modern development practices beyond checklist-based risk reviews, and be comfortable evaluating applications, architecture, vulnerabilities, third-party components, and emerging AI security risks.
Must Haves
  • Approximately 3-5 years of relevant technology or security experience, including practical exposure to Application Security, secure coding, or Secure SDLC activities.
  • Strong understanding of how modern applications are designed, developed, tested, deployed, and secured throughout the Software Development Life Cycle (SDLC).
  • Demonstrated ability to perform substantive application risk assessments and identify meaningful technical security concerns rather than relying solely on compliance checklists.
  • Working knowledge of Secure SDLC, CI/CD security, release controls, vulnerability remediation, and application security testing.
  • Familiarity with security testing approaches such as SAST, DAST, IAST, SCA, API security testing, infrastructure-as-code scanning, container scanning, and secrets detection.
  • Experience reviewing vulnerability or source-code scanning results using platforms such as SonarQube, Checkmarx, Fortify, Veracode, GitHub security capabilities, or comparable tools.
  • Ability to collaborate effectively with developers, architects, security professionals, and technology stakeholders while navigating competing priorities and technical disagreements.
  • Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Information Security, or a related discipline; equivalent relevant professional experience may be considered.

What the Client Needs You to Do
You will serve as a hands-on security partner for teams building new applications and AI-enabled capabilities. Your primary objective is to integrate security into development from design through release, ensuring new functionality receives appropriate technical review without unnecessarily slowing delivery.
You will evaluate proposed solutions, review architecture, establish secure development expectations, analyze scanning results, validate vulnerability remediation, assess third-party technology, and determine the security implications of new functionality before deployment.
The successful candidate must be comfortable challenging technical decisions constructively. This position requires someone who understands how software is actually built and can translate security requirements into practical guidance developers can implement.
Key Responsibilities
  • Embed Application Security practices throughout design, development, testing, deployment, and ongoing enhancement activities.
  • Review new application features and releases to confirm appropriate security requirements and development controls have been addressed.
  • Establish practical secure coding expectations, technical guardrails, and development security standards in partnership with engineering stakeholders.
  • Analyze application security scanning results, distinguish meaningful vulnerabilities from lower-priority findings, and validate appropriate remediation.
  • Evaluate application architectures, integrations, APIs, infrastructure components, and technical design decisions for potential security weaknesses.
  • Assess third-party software, libraries, services, and other external components introduced into application environments.
  • Partner with developers and technology teams to incorporate security testing and controls into CI/CD and release processes.
  • Evaluate AI-enabled applications for risks involving data exposure, source integrity, prompt injection, unauthorized disclosure, model misuse, and other emerging attack patterns.
  • Test internally developed solutions prior to release and provide actionable recommendations when security concerns are identified.
  • Collaborate across security and technology functions to resolve vulnerabilities, address technical risks, and strengthen secure development practices.

Additional Information
The technical environment includes a mixture of modern application development technologies. Experience with Python is particularly valuable, while exposure to Java, .NET, or comparable enterprise development frameworks is beneficial. Candidates do not need to specialize in one programming language; broader understanding of sound development and application security principles is more important.
Experience with Azure, Azure DevOps, GitHub Enterprise, GitHub Advanced Security, or comparable cloud-based development and DevSecOps platforms is preferred.
Candidates with knowledge of AI security will have an advantage. Relevant areas include the OWASP Top 10 for Large Language Model Applications, NIST AI Risk Management Framework, responsible AI concepts, prompt injection, sensitive-data leakage, hallucination risk, model misuse, AI agents, and prompt security.
This position is best suited for a technically curious security professional who can operate beyond policy and compliance activities. A software developer or engineer who has transitioned into Application Security may be particularly well aligned.
Strong interpersonal judgment is essential. You will work with stakeholders who may have different levels of security maturity and occasionally challenge security recommendations. The successful candidate can explain technical risk clearly, establish credibility with developers, resolve reasonable disagreements, and determine when a material security concern requires escalation.
W2 employees of Overture Partners who work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), 401(k) starting on day one, a variety of voluntary benefits including life and disability insurance, and sick time if required by law in the worked-in state/locality.
#25572