1

Application Security Engineer Jobs in Portland, OR

Application Security Engineer

Beaverton, OR

$61.25 - $81.75/hr

As an Application Security Engineer at Oneleet, you\'ll bring security depth to our product engineering teams as we expand our cybersecurity platform. You\'ll own the security judgment layer that ...

Job Purpose The Application Security Engineer is responsible for strengthening the security of our applications, platforms, and development processes. This position partners with software engineers ...

Senior Security Engineer

Vancouver, WA · Remote

$119K - $164K/yr

Support application security efforts, including secure design reviews, threat modeling, code review ... Teams across Engineering, IT, and the business have a clear point of contact for security questions ...

Senior Security Engineer

Portland, OR · On-site

$121K - $166K/yr

Key Responsibilities Security Engineering & Architecture ... Design, implement, and maintain security controls across network, endpoint, cloud, and application ...

The Security Engineer supports the design, implementation, configuration, and maintenance of cybersecurity technologies, controls, and secure infrastructure capabilities across enterprise systems and ...

The Security Engineer role involves supporting the design, implementation, and maintenance of cybersecurity technologies and controls to protect enterprise systems and ensure compliance with security ...

... team, application security, and cloud security, setting the standard for technical rigor and client impact * Built, mentored, and retained a world-class team of offensive security engineers ...

Diverse Lynx is seeking a highly skilled Data Security Engineer to design, implement, and manage enterprise data protection and security solutions. The ideal candidate will have strong expertise in ...

Senior Security Engineer

Clackamas, OR · On-site

$120K - $165K/yr

Senior Security Engineer Department: IT Group Employment Type: Full Time Location: Clackamas Reporting To: Mark Thorsrud Description At Pacific Seafood, we do more than just provide the world with ...

Senior Security Engineer

Clackamas, OR · On-site

$120K - $165K/yr

The Senior Security Engineer at Pacific Seafood is a key role in our information technology team supporting efforts to strengthen, enhance, and protect the security posture of our enterprise ...

Senior Security Engineer

Clackamas, OR · On-site

$120K - $165K/yr

The Senior Security Engineer at Pacific Seafood is a key role in our information technology team supporting efforts to strengthen, enhance, and protect the security posture of our enterprise ...

next page

Showing results 1-20

Application Security Engineer information

See Portland, OR salary details

$31

$70

$102

How much do application security engineer jobs pay per hour?

As of Aug 5, 2026, the average hourly pay for application security engineer in Portland, OR is $70.42, according to ZipRecruiter salary data. Most workers in this role earn between $59.90 and $80.05 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are popular job titles related to Application Security Engineer jobs in Portland, OR? For Application Security Engineer jobs in Portland, OR, the most frequently searched job titles are:
What job categories do people searching Application Security Engineer jobs in Portland, OR look for? The top searched job categories for Application Security Engineer jobs in Portland, OR are:
What cities near Portland, OR are hiring for Application Security Engineer jobs? Cities near Portland, OR with the most Application Security Engineer job openings:
Infographic showing various Application Security Engineer job openings in Portland, OR as of July 2026, with employment types broken down into 77% Full Time, 17% Part Time, 1% Temporary, and 5% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $146,473 per year, or $70.4 per hour.

Application Security Engineer

Oneleet

Beaverton, OR

$61.25 - $81.75/hr

Full-time

Medical, PTO

Re-posted 10 days ago


Job description

About Oneleet

Oneleet is one of the fastest-growing security and compliance platforms in history. We are on a mission to change the compliance and security industry by making cybersecurity and compliance effective, easy, and painless. We provide a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners.

Having just raised a $33 million Series A, we are rapidly growing in customers and employees. Our team has decades of experience in security and compliance. Join our team of opinionated rebels and help us build a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry.


Who we’re looking for:

We value passionate self-starters with a growth mindset and a bias for action and personal accountability. If you love solving hard problems, thrive in ambiguity, and want to make a real impact, you’ll fit right in.

We’re especially drawn to:

  • Rebels with a cause — frustrated with the status quo and eager to disrupt it.

  • Opinionated (but not obstinate) builders — decisive yet collaborative, who help us move fast.

  • Clear communicators — who own their ideas and follow through.

Our mission is simple: make effective cybersecurity painless. We believe cybersecurity should empower, not burden. This belief unites our team and drives every decision we make.

If you’re ready to challenge the status quo and help shape the future of cybersecurity, we’d love to meet you.

As an Application Security Engineer at Oneleet, you\'ll bring security depth to our product engineering teams as we expand our cybersecurity platform. You\'ll own the security judgment layer that sits between raw tooling output and what our customers actually see — deciding what to surface, what to suppress, and how to make findings genuinely useful rather than noisy.

This is a hands-on, security-first engineering role at a Series A startup. You\'ll work closely with backend and fullstack engineers on how findings are stored, enriched, and presented, and you\'ll partner with product and design on what to build next. You\'ll be the security voice in product and engineering decisions, and you\'ll be empowered to push back when security judgment requires it.

You\'ll work directly with customers — security teams using the platform day-to-day — to understand what they actually need, and iterate quickly based on their feedback.

Key Responsibilities:
  • Own the integration, configuration, and output quality of security tooling that powers our platform

  • Tune outputs to maximize signal and minimize noise — decide what to surface, what to suppress, and what to enrich

  • Design rules, severity scoring, and triage flows that make findings actionable rather than overwhelming

  • Build the security judgment layer on top of underlying tooling — context-aware prioritization and exploitability reasoning

  • Partner with engineers on how findings are presented in the UI and how remediation flows work

  • Work with PM and design on roadmap priorities, providing the security expertise that drives what to build next

  • Review and shape architectural choices that affect security outcomes

  • Engage with customers directly to understand how they use the platform and what\'s blocking adoption

  • Benchmark our output quality against competitors and close gaps where they exist

  • Contribute back to the open source security tooling we depend on where it makes sense

Qualifications:
  • 5+ years of application security experience, with significant time shipping security products

  • Strong programming skills in at least one of Go, Python, or TypeScript — this is a product engineering role with security depth, not security operations

  • Hands-on experience tuning security tooling for production use — reducing false positives, building suppression logic, designing severity models

  • Understanding of vulnerability research, CVE/CWE taxonomies, and exploit reasoning

  • Has worked through what makes a security finding actually actionable vs. just technically true

  • Excellent communication skills and comfort working directly with customers

  • Pragmatic; knows how to build things fast without unnecessarily complicating things

  • Experience in (and thrives in) a fast-moving, start-up engineering environment

Bonus Experience:
  • Prior experience shipping a security product at a vendor

  • Contributions to open source security tooling

  • Offensive security background or OSCP / similar certifications

  • Hands-on experience with LLM agents, tool use, or autonomous AI systems

You should apply if any of the following excite you:
  • Owning the security depth of a product from tooling integration to user-facing findings

  • Being the security voice in a product team that ships fast and listens to customers

  • Building on top of best-in-class open source tooling rather than reinventing from scratch

  • Working directly with security teams using the product and iterating on real-world feedback

  • Joining a small, scrappy team where your security judgment shapes both the product and the company

Why Oneleet?

At Oneleet, you’ll join a tight-knit team of rebels redefining the cybersecurity industry. We move fast, own our work, and challenge outdated models to make security effortless and effective for companies.

Here’s what makes us special:

  • We value impact over titles, autonomy over micromanagement, and clarity over jargon.

  • You’ll tackle meaningful, hard problems with real-world consequences.

  • You’ll work with smart, kind, and ambitious teammates who lift each other up.


Perks & Benefits
  • Comprehensive health & wellness benefits

  • 20 days PTO per year, plus 8 floating holiday

  • Remote work culture

  • Team off-sites in stunning places (Amsterdam, Italy, etc).

  • Competitive compensation & equity

We hire globally and compensate competitively within each market using geographic pay bands. The range for this role reflects a US national baseline. Offers for candidates in higher cost-of-labor markets (e.g., San Francisco, New York, Zurich) may fall at or above the top of the posted range, while offers in other markets are benchmarked to local standards and are lower. Within any range, individual compensation is determined by work location, skills and experience demonstrated through the interview process, and relevant education or training. This posting reflects base salary only and does not include equity or benefits.


Remote-First & Global Hiring

We’re a remote-first company and hire globally in regions where we can legally engage talent directly or via our employer-of-record (EOR) partner. If you’re based outside the U.S., we’ll explore the most compliant hiring arrangement for your location. We make hiring decisions based on merit, skills, and potential regardless of location.

U.S. Hiring & E-Verify

For U.S.-based candidates, Oneleet participates in E-Verify to confirm employment eligibility, in accordance with federal regulations. We are an equal opportunity employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.

How we use AI in this Hiring Process

This company uses automated technology, including AI-assisted tools, to assist in reviewing applications, assessing candidate qualifications, and detecting fraudulent submissions. These tools analyze application data and identity signals to support, but not replace, human hiring decisions. All final hiring decisions are made by a human reviewer. Candidates who require accommodation or who wish to request information about how these tools are used, including requesting the bias audit results, may contact recruiting@oneleet.com. This process is conducted in compliance with applicable federal, state, and local laws.

Notice for New York City Residents:

You have a right to take at least 10 business days to decide whether to proceed with submitting your information through this process. By continuing, you confirm your understanding of this notice. If you choose to proceed before the 10-business-day period expires, you are making a knowing and voluntary decision to do so.