1

Application Security Engineer Jobs in Pittsburgh, PA

Software Security Engineer

Pittsburgh, PA · On-site

$110K - $120K/yr

As a Software/Application Security Engineer, you'll work hands-on alongside developers and DevOps engineers to build security into how we ship software - reviewing code, harden the AI agents, MCP ...

As a Software/Application Security Engineer, you'll work hands-on alongside developers and DevOps engineers to build security into how we ship software -- reviewing code, harden the AI agents, MCP ...

Endpoint Security Engineer At BNY, our culture allows us to run our company better and enables employees' growth and success. As a leading global financial services company at the heart of the global ...

Endpoint Security Engineer At BNY, our culture allows us to run our company better and enables employees' growth and success. As a leading global financial services company at the heart of the global ...

Endpoint Security Engineer At BNY, our culture allows us to run our company better and enables employees' growth and success. As a leading global financial services company at the heart of the global ...

next page

Showing results 1-20

Application Security Engineer information

See Pittsburgh, PA salary details

$28

$64

$93

How much do application security engineer jobs pay per hour?

As of Aug 29, 2026, the average hourly pay for application security engineer in Pittsburgh, PA is $64.46, according to ZipRecruiter salary data. Most workers in this role earn between $54.86 and $73.27 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are popular job titles related to Application Security Engineer jobs in Pittsburgh, PA?

For Application Security Engineer jobs in Pittsburgh, PA, the most frequently searched job titles are:

What job categories do people searching Application Security Engineer jobs in Pittsburgh, PA look for?

The top searched job categories for Application Security Engineer jobs in Pittsburgh, PA are:

What cities near Pittsburgh, PA are hiring for Application Security Engineer jobs?

Cities near Pittsburgh, PA with the most Application Security Engineer job openings:

Infographic showing various Application Security Engineer job openings in Pittsburgh, PA as of August 2026, with employment types broken down into 57% Full Time, and 43% Contract. Highlights an 60% In-person, and 40% Hybrid job distribution, with an average salary of $134,086 per year, or $64.5 per hour.

Software Security Engineer

Pittsburgh, PA • On-site

$110K - $120K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted yesterday


Job description

Software Security Engineer
Department: Security
Employment Type: Full Time
Location: Pittsburgh Onsite
Compensation: $110,000 - $120,000 / year
Description
About The RoleWolfe is a Pittsburgh-based FinTech company building the next generation of financial products, and we are actively embedding AI across our product, our internal processes, and the way our teams work day-to-day. As a Software/Application Security Engineer, you'll work hands-on alongside developers and DevOps engineers to build security into how we ship software - reviewing code, harden the AI agents, MCP integrations, and LLM-backed features we're actively shipping, hardening CI/CD pipelines, and helping teams find and fix vulnerabilities across application code, containers, and cloud infrastructure.
This role is built for a developer. Whether you're a software engineer moving into security or an early-career security engineer expanding into AppSec, you'll work hands-on alongside developers and DevOps engineers and learn enterprise security tooling - including secure code development AI/ML and LLM-powered tools - with support to earn certifications and grow alongside a security team that mentors in person. You'll be working alongside developers using languages such as TypeScript/Node, Deno, Bun, Dart, Next.js, php, react, and Python codebases, plus Terraform/Ansible and containerized services on AWS.
We're looking for candidates who are enthusiastic about an in-office culture. This is a 5-day onsite role in Pittsburgh, PA.
Responsibilities
  • Perform code reviews, SAST/DAST testing, penetration tests, and threat modeling, and work with developers to remediate vulnerabilities across application code, libraries, containers, and infrastructure as code.
  • Integrate and run automated security tooling (such as Snyk, SemGrep, or Cycode) within CI/CD pipelines across code repositories (such as GitHub, GitLab, Jenkins, or AWS DevOps), and automate findings triage and reporting.
  • Build the automation that triages, routes, and reports vulnerability findings, and run our enterprise Bug Bounty program.
  • Operate and improve Bot Management, WAF, secrets management, and API security controls across Wolfe's applications.
  • Apply and promote secure coding standards aligned to OWASP and SANS CWE Top 25, and contribute to measuring DevSecOps maturity using a framework such as DSOMM or BSIMM.
  • Partner with developers, security operations, product management, and incident response teams, sharing secure-coding and vulnerability-management practices as you grow your own expertise.

Impact Statement
For more clarity on the role, below are the success metrics and measurements for this role in the first 90 to 120 days.:
  • Update existing Software Security Strategy and make improvements on monitoring and reporting on KPI's
  • Make a significant improvement to least one automated security tool (DAST, SAST, SCA, or container scanning) in the production CI/CD pipeline, with results feeding a documented triage workflow.
  • Driving additional Bug Bounty submissions and improve bot management turning & protections prior to end of Q3.
  • Provide product and technology advisement and testing for new application and AI functionality
  • Develop and plan a purposeful Application and AI development training program

Qualifications
  • 2+ years of experience in software development, software security, or DevSecOps with security exposure - including developers looking to move into a dedicated security role - plus a Bachelor's in Information Security, Cybersecurity, Computer Science, or a related field (equivalent experience accepted in lieu of a degree).
  • A real coding background and working knowledge of secure coding principles (OWASP Top 10, SANS CWE Top 25).
  • Some hands-on exposure to CI/CD pipelines (GitHub, GitLab, Jenkins, or AWS DevOps) and an interest in integrating security tooling into them.
  • Strong verbal and written communication skills, with the ability to explain security concepts to both technical and non-technical teammates.
  • Eagerness to learn enterprise security tooling (vulnerability scanners, Bot Management, SAST/DAST/SCA) and maturity frameworks like DSOMM or BSIMM - deep prior experience with these is a plus, not a requirement.
  • No certifications required; experience with CISSP, OSCP, GCSA, AWS Security Specialty, or CSSLP is a plus, and we'll support you in earning them.

Compensation, Benefits, and Perks
Wolfe is committed to providing a comprehensive benefits package to support your well-being, along with competitive compensation. Our benefits and perks include but not limited to:
  • Restricted Stock Units (RSUs)
  • Profit Share and/or Incentive Bonus
  • Medical, Prescription, Vision, and Dental insurance for employees and dependents (Wolfe pays 80% of premium)
  • Short-Term Disability Insurance (Wolfe pays 100% of premium)
  • Voluntary Long-Term Disability Insurance, Life Insurance, Critical Illness Insurance, Accident Insurance, and Hospital Indemnity coverage
  • PTO (vacation and sick time)
  • Corporate Holidays and Floating Holidays
  • 401(k)
  • Employee recognition program
  • Charitable Donation to a charity of your choice yearly
  • Employee Referral Bonus
  • Tuition Reimbursement
  • Internal Training and Information sessions
  • Family Picnic, Holiday Party, and other outings
  • Internal Culture Club