1

Application Security Engineer Jobs in Redmond, WA

Application Security Engineer

Seattle, WA ยท On-site

$195K - $244K/yr

As our Application Security Engineer, you'll own how we find, prioritize, and drive down application-layer risk across the consumer flows that put cash offers in homeowners' hands, the GraphQL APIs ...

Security Engineer, Application Security

Bellevue, WA ยท On-site

$66.25 - $88.50/hr

As a Security Engineer, Application Security, you will help design and implement systems that embed security into development practices across Robinhood. You will review system designs, contribute to ...

About the Role As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security ...

Sr. Application Security Engineer

Redmond, WA ยท On-site

$170K - $235K/yr

Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars. SR. APPLICATION SECURITY ENGINEER At SpaceX we're leveraging our ...

Sr. Application Security Engineer

Redmond, WA ยท On-site

$170K - $235K/yr

SR. APPLICATION SECURITY ENGINEER At SpaceX we're leveraging our experience in building rockets and spacecraft to deploy Starlink, the world's most advanced broadband internet system. Starlink is the ...

Sr. Application Security Engineer

Redmond, WA ยท On-site

$170K - $235K/yr

Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars. SR. APPLICATION SECURITY ENGINEER At SpaceX we're leveraging our ...

The Customer Service Application Security team is looking for a talented and results-driven Security Engineer to help shape how Amazon protects customer data through secure-by-design principles. In ...

The Customer Service Application Security team is looking for a talented and results-driven Security Engineer to help shape how Amazon protects customer data through secure-by-design principles. In ...

The Customer Service Application Security team is looking for a talented and results-driven Security Engineer to help shape how Amazon protects customer data through secure-by-design principles. In ...

The Customer Service Application Security team is looking for a talented and results-driven Security Engineer to help shape how Amazon protects customer data through secure-by-design principles. In ...

The Customer Service Application Security team is looking for a talented and results-driven Security Engineer to help shape how Amazon protects customer data through secure-by-design principles. In ...

The Customer Service Application Security team is looking for a talented and results-driven Security Engineer to help shape how Amazon protects customer data through secure-by-design principles. In ...

next page

Showing results 1-20

Application Security Engineer information

See Redmond, WA salary details

$33

$74

$107

How much do application security engineer jobs pay per hour?

As of Aug 7, 2026, the average hourly pay for application security engineer in Redmond, WA is $74.37, according to ZipRecruiter salary data. Most workers in this role earn between $63.27 and $84.52 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are popular job titles related to Application Security Engineer jobs in Redmond, WA? For Application Security Engineer jobs in Redmond, WA, the most frequently searched job titles are:
What cities near Redmond, WA are hiring for Application Security Engineer jobs? Cities near Redmond, WA with the most Application Security Engineer job openings:
Infographic showing various Application Security Engineer job openings in Redmond, WA as of August 2026, with employment types broken down into 78% Full Time, 16% Part Time, and 6% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $154,684 per year, or $74.4 per hour.

Application Security Engineer

Opendoor

Seattle, WA โ€ข On-site

$195K - $244K/yr

Full-time

Re-posted 29 days ago


Job description

About Opendoor
At Opendoor our mission is to tilt the world in favor of homeowners and those who aim to become one. Homeownership matters. It's how people build wealth, stability, and community. It's how families put down roots, how neighborhoods strengthen, how the future gets built. We're building the modern system of homeownership giving people the freedom to buy and sell on their own terms. We've built an end-to-end online experience that has already helped thousands of people and we're just getting started.
About The Role
Our Security Engineering team builds intelligent systems that protect Opendoor and our customers while enabling unprecedented engineering velocity. We apply software engineering and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter, not gates where they don't.
As our Application Security Engineer, you'll own how we find, prioritize, and drive down application-layer risk across the consumer flows that put cash offers in homeowners' hands, the GraphQL APIs that power our products, and the AI agents and vibe-coded tools our engineers ship every week. The job is to make it safe to build fast, not to slow things down.
What You'll Do
โ€ข Define, build and operate Opendoor's application vulnerability identification capability - the tooling, triage workflow and remediation techniques across our consumer products, internal admin tools and GraphQL API powering home acquisition, resale, mortgage, title and escrow.
โ€ข Assess, rationalize and own our AppSec tooling stack - static and dynamic security testing, software supply chain risk detection and secrets scanning and integrate findings into developer workflows where engineers already live (GitHub, Linear, Slack).
โ€ข Own and mature our HackerOne program: tightening the triage workflow, improving signal to noise on incoming reports, strengthening researcher relationships and closing the loop with engineering teams so root causes get addressed quickly.
โ€ข Lead threat modeling and security design reviews for new services, APIs, and mobile features. Turn the patterns you see into rules, lint checks, and CI guardrails so the next team doesn't make the same mistake.
โ€ข Build AI agents and automated workflows that triage vulnerability reports, validate exploit reproductions, and draft remediation pull requests, replacing manual security review with high-signal automation.
โ€ข Partner with engineering teams to harden authentication, authorization, and input validation across our codebase and production services, including the GraphQL gateway (Apollo) and our Kubernetes workloads - while driving a shift-left strategy that catches vulnerabilities before they ship.
โ€ข Build Opendoor's offensive security capability. Scope and run internal security testing, red team exercises and adversarial analysis of our highest-risk flows ensuring findings directly harden detection and response.
โ€ข Set the bar for what "secure by default" looks like for AI-maximalist engineering, including vibe-coded apps, MCP servers, and agent-driven workflows that touch production data.
โ€ข Build Opendoor's security culture by establishing secure design standards, embedding into engineering team rituals and developing a strong security mindset - creating a foundation for engineers to think like attackers without slowing down.
Tech Stack
โ€ข Languages: Go, Python, TypeScript, Ruby, Terraform
โ€ข Cloud: AWS, GCP, Azure, Kubernetes, Apollo GraphQL
โ€ข AppSec Tooling: GitHub Advanced Security (CodeQL, Dependabot, secret scanning), Semgrep, HackerOne, Burp Suite, Cloudflare WAF
โ€ข AI Tooling: Claude, OpenAI, various agent frameworks, MCP - used heavily for vulnerability triage, exploit verification, and remediation drafting
What You'll Need
โ€ข Deep conviction that AI and automation should eliminate manual work and increase the team's impact, and a track record to prove it. You've built agentic systems that replaced reactive security work, not just configured off-the-shelf tools.
โ€ข Comfort operating with high autonomy in ambiguous environments. You've defined what "good" looks like in a domain where no playbook existed, you're energized by that, not unsettled by it.
โ€ข Business enablement security mindset. You measure success by business impact and informed risk-taking, not by tickets opened or pen test reports filed.
โ€ข 5+ years of application security or software engineering experience with a security focus, with strong skills in at least one of Python, Go, TypeScript, or Ruby, and the ability to read and write code across the others.
โ€ข Hands-on expertise across the security risk detection toolchain with real deployment experience using GitHub Advanced Security, Semgrep, or equivalent.
โ€ข Strong grasp of common application and API vulnerability classes including GraphQL, REST, and gRPC security pitfalls - broken authorization, mass assignment, introspection exposure, insecure direct object references.
โ€ข Practical threat modeling skills. You can take an architecture diagram and a 30-minute conversation and walk out with the three things that actually matter.
โ€ข Experience with cloud and container security on AWS and Kubernetes, including identity and access management, secrets management, and continuous integration / continuous deployment pipeline security.
โ€ข Humility and genuine curiosity. You're as excited to learn from product engineers and enable their work as you are to break things.
Bonus Points
โ€ข Offensive security experience including pentesting, API security, or mobile security, and/or red team operations.
โ€ข Experience running a bug bounty or coordinated disclosure program at scale.
โ€ข Mobile application security review experience (iOS and Android).
โ€ข Experience securing AI and machine learning pipelines, agent frameworks, or MCP-style integrations.
โ€ข OSCP, OSWE, or similar offensive certifications.
Location
This role is based in our downtown Miami office, in-person four days per week (Monday, Tuesday, Thursday, Friday). Candidates must be based within commuting distance of the office.
The pay range for this role is:
195,200 - 244,000 USD per year (US Zone 2)