1

Application Security Engineer Jobs (NOW HIRING)

Application Security (AppSec) Engineer $60/hr W2 Onsite - Maryland Heights, MO Cog Kit BGV must be cleared to start What are the top 3 skills required for this role? * Application Security (AppSec)

NJ · On-site

$60/hr

Application Security (AppSec) Engineer $60/hr W2 Onsite - Maryland Heights, MO Cog Kit BGV must be cleared to start What are the top 3 skills required for this role? * Application Security (AppSec)

Application Security Engineer

$60.25 - $80.25/hr

Responsibilities The Application Security Engineer plays a crucial role in securing our growing portfolio of applications. This role will focus on integrating security best practices into the ...

Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

We're hiring an Application Security Engineer to own security across Opal's product and platform - and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly ...

Application Security Engineer

Miami, FL · On-site

$56.25 - $75/hr

Application Security Engineer - Agentic AI, Identity & eCommerce Security Location: Miami, FL (Onsite 4 days/week) Engagement: Contract, 6-12 months (strong likelihood of extension) Overview Our ...

Application Security Engineer

Washington, DC · On-site

$66.50 - $89/hr

Application Security Engineer Location: Washington, DC * Support PeopleSoft HCM/FSCM/ELM/CRM/EPM application security. * Implement specifically SSO for Oracle ELM, HCM and Finance PeopleSoft Modules ...

Application Security Engineer

OR · On-site +1

$58.75 - $78.50/hr

As an Application Security Engineer, you'll play a meaningful role in helping our development organization build secure software with confidence. In this role, you'll work closely with our Compliance ...

$43.25 - $58/hr

GameChanger is hiring a remote candidate for Security Engineer, Application Security. This is a full time position. Work location: USA. The role typically involves technologies such as TypeScript ...

Showing results 41-60

Application Security Engineer information

See salary details

$29

$66

$96

How much do application security engineer jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for application security engineer in the United States is $66.40, according to ZipRecruiter salary data. Most workers in this role earn between $56.49 and $75.48 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What cities are hiring for Application Security Engineer jobs?

Cities with the most Application Security Engineer job openings:

What are the most commonly searched types of Application Security Engineer jobs?

The most popular types of Application Security Engineer jobs are:

Who are the top companies hiring for Application Security Engineer jobs?

The top employers for Application Security Engineer jobs are:

What states have the most Application Security Engineer jobs?

States with the most job openings for Application Security Engineer jobs include:

What are popular job titles related to Application Security Engineer jobs?

For Application Security Engineer jobs, the most frequently searched job titles are:

Infographic showing various Application Security Engineer job openings in the United States as of September 2026, with employment types broken down into 56% Full Time, and 44% Contract. Highlights an 78% In-person, and 22% Hybrid job distribution, with an average salary of $138,117 per year, or $66.4 per hour.

Application Security Engineer

Whippany, NJ • On-site

IPolarity LLC
Recruiting and Staffing Services • 1 - 10 employees

$50 - $60/hr

Full-time

Re-posted 9 days ago


Job description

Application Security (AppSec) Engineer
 $60/hr W2
 Onsite - Maryland Heights, MO
 
Cog Kit
 BGV must be cleared to start
 
 What are the top 3 skills required for this role?
 • Application Security (AppSec)
 • Secure SDLC / DevSecOps
 • SAST, DAST, IAST, SCA
 • Web, Mobile & API Security Testing
 • Manual Penetration Testing & Business Logic Testing
 • Threat Modelling
 • Vulnerability Management
 • Secure Code Review
 • CI/CD Security Integration
 
 
 Job Description/ Responsibilities
 The role focuses on embedding security testing, vulnerability management, and business logic validation directly into CI/CD pipelines and post-deployment processes, ensuring comprehensive security coverage without impacting engineering velocity.
 The ideal candidate will combine expertise in secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual penetration testing to improve application security posture across web, mobile, and microservices architectures. This aligns with Secure SDLC requirements, including SAST, DAST, SCA, and manual validation activities integrated throughout the development lifecycle.
 
 Key Responsibilities
 Application Security Engineering
 • Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications.
 • Integrate security controls and testing activities into Agile, DevOps, and CI/CD pipelines.
 • Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools.
 • Enable continuous post-deployment security validation and risk monitoring.
 Security Testing & Validation
 • Conduct manual penetration testing and business logic testing to identify vulnerabilities beyond automated scanning capabilities.
 • Perform authenticated and unauthenticated security assessments of applications and APIs.
 • Execute threat modeling, attack-path analysis, and architecture reviews for new applications and platform services.
 • Validate remediation effectiveness and secure deployment practices.
 DevSecOps Integration
 • Embed security testing into GitHub Actions, Azure DevOps, Jenkins, GitLab, or similar CI/CD platforms.
 • Automate vulnerability triage, prioritization, and remediation workflows.
 • Develop security-as-code controls and policy enforcement mechanisms.
 • Collaborate with engineering teams to implement secure coding practices and shift-left security initiatives.
 Vulnerability Management
 • Analyze findings from multiple security tools and eliminate false positives.
 • Prioritize vulnerabilities based on business risk, exploitability, and application criticality.
 • Track remediation efforts through SDLC and release cycles.
 • Develop security metrics, dashboards, and executive reporting.
 Developer Enablement
 • Conduct secure coding reviews and developer education sessions.
 • Establish security champions programs across engineering teams.
 • Provide remediation guidance and hands-on support during application releases.
 • Drive adoption of secure development standards and best practices.
 Cloud & API Security
 • Assess cloud-native applications deployed across AWS, Azure, GCP, Kubernetes, and container platforms.
 • Secure REST, GraphQL, and microservice-based APIs.
 • Evaluate infrastructure-as-code (Terraform, ARM, CloudFormation) and container security controls.
 • Support software supply chain security initiatives, including SBOM/SCA validation.
 
 
 
 • 8–15 years of experience in Application Security, DevSecOps, or Security Architecture.
 • Experience securing large-scale enterprise applications across cloud and hybrid environments.
 • Relevant certifications preferred:
 o CISSP
 o CSSLP
 o GWAPT
 o OSCP
 o CEH
 o Azure/AWS Security Certifications