1

Application Security Engineer Jobs in Boston, MA

Application Security Engineer

Boston, MA · Hybrid

$145K - $155K/yr

The Application Security Engineer (ASE) will serve in a multi-functional role, advising development teams on secure coding and accepted industry procedures. The ASE is responsible for leading SDLC ...

Senior Application Security Engineer

Boston, MA · On-site

$63.75 - $85.25/hr

This role serves as the primary Application Security Engineering resource partnering with development, cloud, architecture, infrastructure, and vulnerability management teams to embed security ...

Senior Application Security Engineer

Boston, MA · On-site

$63.75 - $85.25/hr

This role serves as the primary Application Security Engineering resource partnering with development, cloud, architecture, infrastructure, and vulnerability management teams to embed security ...

Staff Application Security Engineer

Boston, MA

$63.75 - $85.25/hr

Integrate AI into Application Security to Enable Secure-by-Design Engineering Drive the adoption of AI-enabled development practices that embed application security directly into the software ...

Staff Application Security Engineer

Boston, MA · On-site +1

$63.75 - $85.25/hr

As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll define the frameworks, methodologies, and architectural ...

Manager Application Security

Boston, MA · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required ... As part of the cybersecurity organization, this role partners closely with engineering, platform ...

Manager Application Security

Boston, MA · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required ... As part of the cybersecurity organization, this role partners closely with engineering, platform ...

next page

Showing results 1-20

Application Security Engineer information

See Boston, MA salary details

$32

$72

$104

How much do application security engineer jobs pay per hour?

As of Aug 2, 2026, the average hourly pay for application security engineer in Boston, MA is $72.14, according to ZipRecruiter salary data. Most workers in this role earn between $61.35 and $82.02 per hour, depending on experience, location, and employer.

What Does an Application Security Engineer Do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What are some common challenges faced by Application Security Engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What does an Application Security Engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an Application Security Engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are popular job titles related to Application Security Engineer jobs in Boston, MA? For Application Security Engineer jobs in Boston, MA, the most frequently searched job titles are:
What job categories do people searching Application Security Engineer jobs in Boston, MA look for? The top searched job categories for Application Security Engineer jobs in Boston, MA are:
What cities near Boston, MA are hiring for Application Security Engineer jobs? Cities near Boston, MA with the most Application Security Engineer job openings:
Infographic showing various Application Security Engineer job openings in Boston, MA as of July 2026, with employment types broken down into 100% Full Time. Highlights an 75% In-person, and 25% Remote job distribution, with an average salary of $150,042 per year, or $72.1 per hour.

Application Security Engineer

Bright Vision Technologies

Westford, MA • Remote

$100K - $150K/yr

Full-time

Posted 7 days ago


Job description

Application Security Engineer – Remote
Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States.
This is a fantastic opportunity to join an established and well-respected organization offering tremendous career growth potential.
Job Title: Application Security Engineer
Location: 100% Remote (U.S.)
Position Type: Full-time, Direct W2
Salary Range: $100,000–$150,000 Annually
Experience Required: 6+ years
Sponsorship: U.S. Citizens, Green Card Holders, EAD Holders, and H-1B transfer candidates are encouraged to apply. We are unable to sponsor new H-1B visa petitions for this position.
Job Summary:
We are looking for an Application Security Engineer to embed security throughout the software development lifecycle, partnering with engineering teams to design secure systems, identify vulnerabilities, and reduce risk across our application portfolio. The role blends hands-on offensive and defensive skills with strong communication and collaboration, helping development teams build secure software efficiently rather than slowing them down. The ideal candidate brings deep technical security expertise, strong software engineering fundamentals, and a track record of shipping security improvements that meaningfully reduce risk in production.
Key Responsibilities
  • Conduct threat modeling and security architecture reviews for new and existing applications and services.
  • Perform manual code reviews, secure design consultations, and pair with engineering teams on hardening critical components.
  • Operate and tune SAST, DAST, IAST, SCA, and secret-scanning tools across CI/CD pipelines.
  • Drive vulnerability management workflows including triage, prioritization, owner assignment, and SLA tracking.
  • Build paved-road libraries and frameworks that make secure patterns the default for engineering teams.
  • Lead red-team and purple-team exercises against internal applications and drive remediation of identified weaknesses.
  • Implement and operate runtime protections including WAF, RASP, bot protection, and abuse-detection mechanisms.
  • Design and enforce secure authentication, authorization, session management, and cryptographic patterns.
  • Partner with infrastructure and platform teams to harden container, Kubernetes, and cloud environments.
  • Develop and deliver application security training, lunch-and-learns, and onboarding content for engineering staff.
  • Respond to security incidents involving application vulnerabilities or active exploitation.
  • Track and apply emerging threats and CVEs that may affect the application portfolio.
  • Maintain comprehensive, current technical documentation — including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures — so that the system remains supportable, auditable, and easy to onboard new engineers onto over time.
  • Stay current with application security research and emerging defensive tooling.
Required Qualifications
  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
  • Five or more years of application security or security engineering experience.
  • Strong understanding of OWASP Top 10, common vulnerability classes, and modern exploit patterns.
  • Hands-on experience performing code review across at least two major languages.
  • Deep familiarity with SAST, DAST, SCA, and CI/CD-integrated security tooling.
  • Strong understanding of authentication, authorization, and cryptographic primitives.
  • Experience with cloud security and modern infrastructure controls.
  • Strong communication skills with technical and non-technical audiences.
  • Proficiency in at least one programming language for tooling and automation.
  • Experience working closely with engineering teams in an Agile environment.
Preferred Qualifications
  • Industry certifications such as OSCP, OSCE, GWAPT, or CISSP.
  • Experience with offensive security tooling and red-team operations.
  • Bug bounty experience, public CVEs, or open-source security contributions.
  • Familiarity with AI/LLM application security considerations.
  • Exposure to regulated industries with strict compliance requirements.
How to Apply
Would you like to know more about this opportunity? For immediate consideration, please send your resume to venkat.r@bvteck.com or contact us at (908) 505-3899. Learn more about Bright Vision Technologies at www.bvteck.com.
Bright Vision Technologies is an Equal Opportunity Employer.
 

Equal Employment Opportunity (EEO) Statement

Bright Vision Technologies (BV Teck) is committed to equal employment opportunity (EEO) for all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, veteran status, or any other protected status as defined by applicable federal, state, or local laws. This commitment extends to all aspects of employment, including recruitment, hiring, training, compensation, promotion, transfer, leaves of absence, termination, layoffs, and recall.

BV Teck expressly prohibits any form of workplace harassment or discrimination. Any improper interference with employees\' ability to perform their job duties may result in disciplinary action up to and including termination of employment.