1

Application Security Jobs in California (NOW HIRING)

As our first dedicated Application Security Engineer, you will define the security architecture for everything we ship. You will work directly with our Engineering teams to identify vulnerabilities ...

As our first dedicated Application Security Engineer, you will define the security architecture for everything we ship. You will work directly with our Engineering teams to identify vulnerabilities ...

You'll own high-impact security work across application security, cloud infrastructure, identity and access, secure SDLC, vendor risk, AI security, and incident readiness. You'll review designs ...

Showing results 41-60

Application Security information

See California salary details

$37

$52

$93

How much do application security jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for application security in California is $52.99, according to ZipRecruiter salary data. Most workers in this role earn between $42.21 and $55.05 per hour, depending on experience, location, and employer.

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications such as Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, authorization, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, penetration testing, and code reviews to identify and fix security issues throughout the development lifecycle.
What cities in California are hiring for Application Security jobs? Cities in California with the most Application Security job openings:
Infographic showing various Application Security job openings in California as of August 2026, with employment types broken down into 77% Full Time, 17% Part Time, 2% Temporary, and 4% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $110,211 per year, or $53 per hour.

Senior Application Security Architect

Payactiv

Milpitas, CA โ€ข On-site

$130 - $160/hr

Other

Medical, Dental, Vision, Retirement, PTO

Posted 24 days ago


Job description

Driven by Excellence. Powered by Curiosity. United in Obsession to Do Good. Position:

Senior Application Security Architect

Location:

Milpitas, CA

Job Id:

216

Openings:

1

Reports to:

Director of Information Security

Who we are

We are Payactiv, a FinTech company devoted to giving workers access to their earned wages when they need them. Payactiv is the pioneer and industry leader in Earned Wage Accessโ€” the only Certified B Corporation and Public Benefit Corporation in our industry.

Our platform helps millions of workers avoid debt, build financial stability, and take control of their financial lives. We partner with thousands of employers who recognize that financial wellness isnโ€™t a perkโ€” itโ€™s the foundation of a loyal, engaged workforce.

Payactiv is seeking a handsโ€‘on Application Security Architect who will act as the principal consultant for security architecture across the entire product lifecycle, from conceptual design through to delivery and continuous development. Your central objective is to design, implement, and supervise a robust enterpriseโ€‘wide Secure SDLC initiative.

What you will do
  • Partner with product owners, engineering teams, and solution architects to architect, formalize, and implement a Secure SDLC framework based on NIST SSDF, OWASP SAMM, BSIMM, and Microsoft SDL standards.
  • Lead the architectural review process by overseeing ADRs, evaluating system architectures, and directing threat modeling sessions using methodologies such as attack trees, PASTA, and STRIDE.
  • Establish and uphold robust benchmarks for data handling and logging, along with standards for cryptography, secure coding, and authentication/authorization frameworks such as FIDO2, mTLS, SAML, OIDC, and OAuth 2.1.
  • Manage comprehensive .NET application security: provide oversight for C#, .NET 6/7/8+, ASP.NET Core (MVC, Web API, Minimal APIs), Blazor, gRPC, and EF Core, securing the supply chain and hardening legacy environments.
  • Deliver architectural guidance for modern stacks: secureโ€‘coding expertise for Node.js, TypeScript (Express, NestJS, Next.js), and Angular, defining approved libraries and languageโ€‘specific security patterns.
  • Oversee development governance and reviews: manage Git branching strategies and repository protections across GitHub, Azure DevOps, and GitLab, and lead a tiered peerโ€‘review program for highโ€‘risk changes.
  • Architect and manage the AppSec toolchain: operate security automation including SAST, DAST, SCA, and secrets scanning, define buildโ€‘break policies, manage SBOM/SLSA compliance, and consolidate results via ASPM platforms.
  • Lead vulnerability and incident response: own applicationโ€‘layer risk management, prioritizing issues via CVSS/EPSS and coordinating responses to supplyโ€‘chain threats or zeroโ€‘day events.
  • Team leadership and mentorship: supervise AppSec engineers and Security Champions, fostering a security culture through paired coding, internal CTFs, and the development of reference architectures and playbooks.
What you need
  • 8+ years in a dedicated Application Security / Secure SDLC role.
  • 8+ years of production C# / .NET experience, expert in modern .NET (6/7/8+), ASP.NET Core, EF Core, secure deserialization, authorization policies, Data Protection, and NuGet supplyโ€‘chain hygiene.
  • Working architectโ€‘level proficiency in Python, Node.js / TypeScript, and Angular; able to define standards, review code, and threatโ€‘model these stacks.
  • Expert in Git internals, branching strategies, merge semantics, signed commits, and largeโ€‘scale repo governance on GitHub Enterprise / Azure DevOps / GitLab.
  • Proven track record standing up or significantly maturing a Secure SDLC at enterprise scale, securityโ€‘asโ€‘code, metricโ€‘driven AppSec.
  • Deep knowledge of OWASP Top 10, API Top 10, ASVS L2/L3, CWE Top 25, MITRE ATT&CK, applied cryptography, and identity protocols (OAuth 2.1, OIDC, SAML, FIDO2).
  • Excellent written communication โ€“ authors standards, ADRs and executive briefings; calm, structured incident leadership.
  • Thirdโ€‘party/vendor risk assessments, ensuring alignment with internal security policies and risk tolerance.
Nice to have
  • Public CVEs, OSS security tooling, or conference talks (BlackHat, DEF CON, OWASP, NDC, .NET Conf).
  • AI / LLM application security (OWASP LLM Top 10, prompt injection, model supply chain).
  • Fuzzing experience (SharpFuzz, libFuzzer) and prior PSIRT leadership.
What we offer
  • Companyโ€‘sponsored Health, Dental, and Vision insurance.
  • 401(k) traditional and Roth with company match.
  • Tuition Assistance or Tuition Reimbursement.
  • Unlimited Paid Time Off.
  • Monthly Gym Reimbursement.
  • Paid time off to volunteer.
  • Paid Family Leave.
  • Complimentary lunches onsite.
  • Opportunity to grow.
  • Opportunity to work with a great team committed to making a difference.

Payactiv is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all team members.

#J-18808-Ljbffr