1

Application Security Jobs in California (NOW HIRING)

We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC). In this role, you'll have ...

Sr. Application Security Engineer

Redlands, CA · On-site

$59 - $79/hr

As an Application Security Engineer at Esri, you will fill a critical role in helping secure Esri's intellectual property and sensitive data against a variety of complex threats with support from all ...

Sr. Application Security Engineer

Redlands, CA · On-site

$59 - $79/hr

They are seeking a Sr. Application Security Engineer to enhance the security of their applications, collaborating with various teams to design security measures, perform testing, and provide guidance ...

Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

We're hiring an Application Security Engineer to own security across Opal's product and platform - and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly ...

Our Application Security team collaborates closely with the application development, DevSecOps, and information security departments to design security into our applications up front, perform ...

Lead Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

They are seeking a Lead Application Security Engineer to own the security of the Ivo platform, ensuring the protection of sensitive contracts through hands-on testing, code review, and security ...

The Staff Application Security Engineer will partner with the Engineering, DevOps, Product, and Release Management teams to embed security as a foundational part of software design and delivery. The ...

Job Purpose The Application Security Engineer is responsible for strengthening the security of our applications, platforms, and development processes. This position partners with software engineers ...

Company Description Sonsoft , Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. Sonsoft Inc. is growing at a steady pace specializing in the fields of ...

Company Description Sonsoft , Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. Sonsoft Inc. is growing at a steady pace specializing in the fields of ...

We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC). In this role, you'll have ...

Own application security across Ivo's web app, API surface, and the systems behind them. * Find and fix bugs. Hunt for vulnerabilities in our own product through hands-on testing, code review, and ...

Showing results 21-40

Application Security information

See California salary details

$37

$52

$93

How much do application security jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for application security in California is $52.99, according to ZipRecruiter salary data. Most workers in this role earn between $42.21 and $55.05 per hour, depending on experience, location, and employer.

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications such as Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, authorization, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, penetration testing, and code reviews to identify and fix security issues throughout the development lifecycle.
What cities in California are hiring for Application Security jobs? Cities in California with the most Application Security job openings:
Infographic showing various Application Security job openings in California as of August 2026, with employment types broken down into 77% Full Time, 17% Part Time, 2% Temporary, and 4% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $110,211 per year, or $53 per hour.

Application Security Engineer

Heartflow

San Francisco, CA • Hybrid

$145K - $180K/yr

Full-time

Re-posted 9 days ago


HeartFlow rating

7.8

Company rating: 7.8 out of 10

Based on 10 frontline employees who took The Breakroom Quiz

135th of 243 rated software companies


Job description

We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC). In this role, you'll have the chance to use your security and software development background to protect patients as we build products that leverage AI to improve healthcare. If you enjoy working with talented engineers to solve complex technical challenges and want to see your work make a direct difference in patient outcomes, we encourage you to apply. This role is a hybrid, requiring three days a week in our San Francisco office.

What You'll Do:

  • Partner with the engineering team to provide hands-on technical guidance to software developers throughout the vulnerability remediation lifecycle. Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
  • Drive vulnerability identification using SAST, DAST, SCA and in-house AI tooling and manage external penetration testing.
  • Support engineering team on vulnerability management, including risk assessment, remediation, improving identification of vulnerabilities and translate security and privacy requirements into technical requirements.
  • Build security awareness through training on secure coding practices, security standards and latest security threats.

What You Bring:

  • Security Communication - Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences. Experience leading training, speaking internally/externally about security projects valued.
  • Programming Skills  - Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python). Comfortable with testing frameworks and CI/CD pipelines.
  • AI Development Tools - Experience using AI code tools such as Claude Code and Github Copilot for development and security testing.
  • Education & Experience  - BS in Computer Science (or related degree) or relevant certifications and equivalent experience. 5+ years of total experience with at least 1 year working in Application Security or performing security tasks in a development role.
  • Securing SDLC - Have contributed to secure SDLC activities, including threat modeling, code review, security testing and vulnerability management.
  • Knowledge of Modern AI Security Threats - Experience working with or ability to discuss current AI threats for both machine learning and generative AI.

What Helps You Stand Out:

  • Healthcare Experience - Current knowledge of HIPAA, HITRUST and the complexities of working in a regulated environment. Experience with Software as a Medical Device (SaMD) is especially valuable.
  • Infrastructure as Code & Cloud - Familiarity with AWS (or equivalent cloud providers) and configuration tools (Terraform, Chef, Ansible). Experience with containerization (Docker, Kubernetes) and orchestration (GitHub Actions or similar).

A reasonable estimate of the base salary compensation range is $145,000 to $180,000 per year, bonus, and equity. #LI-IB1


What HeartFlow employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom