1

Application Security Engineer Jobs in Edison, NJ

Application Security Engineer

New York, NY · On-site

$64.25 - $86/hr

The Role We are seeking a seasoned Application Security Engineer to help us secure our products and platform that serve our Fortune 500 customers. In this pivotal role, you will be working in close ...

Application Security Engineer

New York, NY · On-site

$64.25 - $86/hr

About the role We're looking for an Application Security Engineer who lives in the code. Braintrust is a real-time, high-availability data platform that runs in both SaaS and self-hosted environments ...

Senior Application Security Engineer As a Senior Application Security Engineer on the Application Security team, you will be a trusted partner to engineering, product, and business teams across ...

Job Purpose The Application Security Engineer is responsible for strengthening the security of our applications, platforms, and development processes. This position partners with software engineers ...

next page

Showing results 1-20

Application Security Engineer information

See Edison, NJ salary details

$30

$68

$99

How much do application security engineer jobs pay per hour?

As of Jul 20, 2026, the average hourly pay for application security engineer in Edison, NJ is $68.74, according to ZipRecruiter salary data. Most workers in this role earn between $58.46 and $78.12 per hour, depending on experience, location, and employer.

What Does an Application Security Engineer Do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What are some common challenges faced by Application Security Engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What does an Application Security Engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an Application Security Engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are popular job titles related to Application Security Engineer jobs in Edison, NJ? For Application Security Engineer jobs in Edison, NJ, the most frequently searched job titles are:
What job categories do people searching Application Security Engineer jobs in Edison, NJ look for? The top searched job categories for Application Security Engineer jobs in Edison, NJ are:
What cities near Edison, NJ are hiring for Application Security Engineer jobs? Cities near Edison, NJ with the most Application Security Engineer job openings:
Application Security Engineer

Application Security Engineer

RedStream Technology

New York, NY

$68 - $72/hr

Other

Re-posted 21 days ago


Job description

Job Description Application Security Engineer Hybrid, NYC Contract Role Our client's Cybersecurity Organization is seeking an Application Security Engineer. This role will be an integral component of the application security program end-to-end - from discovery and inventory of business unit applications, through tooling implementation, through embedding security and AI-assisted controls into business unit DevOps pipelines. This is as much a relationship and influence role as it is a technical role; success requires partnering effectively with our client's subsidiaries.

This is a hybrid on-site position, with a requirement to be in the NYC office three times per week. Responsibilities: Application discovery and inventory across all business units, including ownership mapping, technology stack profiling, and risk tiering. Standing up and operating the AppSec tooling stack - SAST, SCA, secrets scanning, and container/IaC scanning - integrated into business unit CI/CD pipelines.

Designing and implementing AI-assisted triage workflows on top of AppSec tooling so that finding volume does not overwhelm developers and false positives are filtered before reaching engineering teams. Defining secure SDLC requirements, threat modeling practices, and security gates that business units adopt as part of their standard development process. Partnering with business unit development leaders to build the relationships and shared playbooks needed to operationalize AppSec without becoming a blocker to delivery.

Contributing to AI security strategy - evaluating emerging tools (AI code review assistants, agentic security testing, automated security requirement generation) and recommending what to operationalize and what to defer. Producing executive-ready metrics and reporting that connect AppSec activity to business risk reduction. Required Qualifications: 7+ years in application security, product security, or security engineering, with at least 3 years in environments with multiple independent business units, brands, or product lines.

Hands-on experience deploying and operating modern AppSec tooling (e.g., Semgrep, Snyk, Checkmarx, Veracode, Apiiro, Ox Security, GitHub Advanced Security). Working code-level proficiency in at least three commonly-used languages (e.g., Python, JavaScript/TypeScript, Java, C#, Go) sufficient to read, review, and triage findings. Strong scripting and automation skills in Python or equivalent; comfortable building integrations against REST APIs and operating in CI/CD environments (GitHub Actions, GitLab CI, Jenkins, Azure DevOps)

Demonstrated ability to influence engineering organizations without direct authority - negotiating standards, driving adoption, and partnering with development leaders. Practical understanding of OWASP Top 10, threat modeling methodologies (STRIDE, PASTA, or equivalent), and modern attack patterns including supply chain risks. Preferred Qualifications: Experience integrating LLM-based tooling into security workflows (alert triage, finding summarization, remediation guidance generation).

Familiarity with one or more compliance frameworks relevant to our environment (HITRUST, HIPAA, NIST AI RMF, SOC 2). Prior experience working in a regulated or healthcare-adjacent environment. Cloud security depth in at least one major provider (AWS, Azure, GCP).

Public contribution to AppSec community - OSS, conference talks, published research, or detection/rule contributions.