1

Application Security Engineer Jobs in Boston, MA

Manager Application Security

Boston, MA · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required ... As part of the cybersecurity organization, this role partners closely with engineering, platform ...

Manager Application Security

Westwood, MA · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required ... As part of the cybersecurity organization, this role partners closely with engineering, platform ...

Manager Application Security

Westwood, MA · On-site +1

$133K - $190K/yr

Description Manager, Application Security Hybrid Work Arrangement Hybrid work arrangement required ... As part of the cybersecurity organization, this role partners closely with engineering, platform ...

Senior Security Engineer

Boston, MA

$124K - $170K/yr

The Senior Security Engineer will have responsibility for supporting and advancing Harvard Medical ... Administer and support application security platforms and testing tools. * Assist with ...

The Senior Security Engineer will have responsibility for supporting and advancing Harvard Medical ... Administer and support application security platforms and testing tools. * Assist with ...

Product Security Engineer

Boston, MA · On-site

$135 - $175/hr

Conduct application security assessments and penetration tests to identify vulnerabilities and ... Proven experience as an Application Security Engineer or similar role. * Strong understanding of ...

Company Description Engineering Title: Application Security Specialist Location: Cambridge, MA Duration: 6 Months(Extendable) Roles & Responsibilities: Creating application security related policies ...

Showing results 21-40

Application Security Engineer information

See Boston, MA salary details

$32

$72

$104

How much do application security engineer jobs pay per hour?

As of Aug 23, 2026, the average hourly pay for application security engineer in Boston, MA is $72.14, according to ZipRecruiter salary data. Most workers in this role earn between $61.39 and $82.02 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are popular job titles related to Application Security Engineer jobs in Boston, MA?

For Application Security Engineer jobs in Boston, MA, the most frequently searched job titles are:

What job categories do people searching Application Security Engineer jobs in Boston, MA look for?

The top searched job categories for Application Security Engineer jobs in Boston, MA are:

What cities near Boston, MA are hiring for Application Security Engineer jobs?

Cities near Boston, MA with the most Application Security Engineer job openings:

Infographic showing various Application Security Engineer job openings in Boston, MA as of August 2026, with employment types broken down into 100% Full Time. Highlights an 75% In-person, and 25% Remote job distribution, with an average salary of $150,050 per year, or $72.1 per hour.

Manager Application Security

Citizens

Boston, MA • On-site, Remote

$133K - $190K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 26 days ago


Job description

Description

Manager, Application Security

Hybrid Work Arrangement
Hybrid work arrangement required with 4 days on site and 1 remote in one of the following organizational hubs: Johnston, RI - Westwood OR Boston, MA  - Iselin, NJ - Manchester, NH

The Manager, Application Security is responsible for leading, scaling, and maturing enterprise application security capabilities across a complex technology environment. This role owns the application security program end to end, ensuring secure software development practices are embedded into the SDLC while balancing regulatory, risk, and business requirements.
As part of the cybersecurity organization, this role partners closely with engineering, platform, cloud, DevOps, and risk teams to drive measurable risk reduction without slowing delivery.

Key Responsibilities
Lead the enterprise application security program across web and mobile platforms
Define and execute the application security vision, strategy, and roadmap aligned to business and risk objectives
Establish and enforce application security standards, secure coding practices, and control requirements
Partner with engineering leadership to embed security into architecture, design, and delivery decisions
Oversee integration of application security testing tools, including SAST, DAST, and SCA, into CI CD pipelines
Lead application security assessments and risk based remediation planning
Provide threat informed guidance to engineering teams on high risk vulnerabilities and design patterns
Collaborate with vulnerability management, cloud security, and infrastructure teams to drive cohesive risk reduction
Establish governance, metrics, and reporting to measure application security maturity and effectiveness
Represent application security in audit, regulatory, and risk management engagements
Translate technical security risks into clear, business relevant insights for senior leaders
Build, mentor, and develop application security engineers and subject matter experts
Continuously improve tooling, automation, and processes to scale AppSec capabilities efficiently

Required Experience and Skills
10 plus years of cybersecurity experience with a strong focus on application security
5 plus years of people or program leadership experience operating an application security program in an enterprise environment
Deep understanding of application security risks, including OWASP Top 10
Hands on experience with modern SDLC, CI CD, and DevSecOps practices
Experience implementing and managing application security testing tools and processes
Ability to assess application architecture, design patterns, and authentication and authorization models
Strong experience partnering with engineering teams to drive secure by design outcomes
Excellent written and verbal communication skills, including executive level reporting
Proven ability to influence engineering, product, risk, and compliance stakeholders

Preferred Experience
Experience in highly regulated industries such as financial services or healthcare
Familiarity with cloud native and microservices based architectures
Experience with API security platforms and runtime visibility tools
Background in penetration testing or threat modeling
Experience defining application security metrics, KPIs, and maturity models

Education and Certifications
Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field
Preferred certifications include CISSP, CISM, CISA, GPEN, or equivalent

Pay Transparency
The salary range for this position is from $133,000 to $190,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to work location, relevant skills, and experience.

We offer competitive pay, comprehensive medical, dental, and vision coverage, retirement benefits, maternity and paternity leave, flexible work arrangements, education reimbursement, wellness programs, and more. Citizens' paid time off policy exceeds the mandatory paid sick or paid time away policies of local and state jurisdictions in the United States. For an overview of our benefits, visit our Careers site - https://jobs.citizensbank.com/benefits.

#LI-Citizens1

Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.

Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague's or a dependent's reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Education:Why Work for UsEmployment Type: 1ST