1

Application Security Jobs in Florida (NOW HIRING)

Application Security Engineer

Miami, FL · On-site

$56.25 - $75/hr

As our Application Security Engineer, you'll own how we find, prioritize, and drive down application-layer risk across the consumer flows that put cash offers in homeowners' hands, the GraphQL APIs ...

Application Security Engineer

Miami, FL · On-site

$125 - $150/hr

As our Application Security Engineer, you'll own how we find, prioritize, and drive down application-layer risk across the consumer flows that put cash offers in homeowners' hands, the GraphQL APIs ...

The Opportunity As a Sr. Application Security Engineering at Syncro, you will be responsible for owning the security posture across the organization alongside the CTO. You will partner with our ...

New

We are seeking an application security engineer in a 100% remote role. Experienced candidates will have extensive SAST and DAST experience, securing CI/CD pipeline * 3-5+ years of recent focused ...

next page

Showing results 1-20

Application Security information

See Florida salary details

$28

$40

$71

How much do application security jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for application security in Florida is $40.12, according to ZipRecruiter salary data. Most workers in this role earn between $31.97 and $41.68 per hour, depending on experience, location, and employer.

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications like Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, firewalls, and vulnerability scanners to identify and mitigate risks throughout the development lifecycle.

What cities in Florida are hiring for Application Security jobs?

Cities in Florida with the most Application Security job openings:

Infographic showing various Application Security job openings in Florida as of September 2026, with employment types broken down into 79% Full Time, 18% Part Time, and 3% Contract. Highlights an 87% Physical, 2% Hybrid, and 11% Remote job distribution, with an average salary of $83,453 per year, or $40.1 per hour.

Senior Application Security Engineer

Jacksonville, FL • On-site

$54.50 - $72.75/hr

Other

Posted 12 days ago


Job description

Description:

Location: Jacksonville, FL - In office 5 days

Onsite Interviews (1-Hour)

Eligible for Conversion – Based on performance and budget approval

Must Haves:

Experience managing and tuning SAST, DAST, or SCA security scanning platforms.

Experience in integrating application security controls into CI/CD and DevSecOps workflows.

Experience analyzing vulnerabilities and partnering with development teams to drive remediation.

Nice-to-Have

Experience in regulated environments (financial services preferred).

Automation, scripting, and security reporting/dashboard experience.

Code Quality Analysis tool administration and configuration experience.

POSITION PURPOSE: Own and optimize application security testing capabilities across the software development lifecycle, with emphasis on SAST, DAST, SCA, SonarQube, scanning configuration, vulnerability triage, and actionable reporting.

Position Summary

The Senior Application Security Engineer is responsible for designing, implementing, and optimizing application security capabilities across the software development lifecycle. Working under limited supervision, this individual contributor partners with development, DevOps, architecture, risk, and cybersecurity teams to integrate security testing into delivery processes, identify application vulnerabilities, and improve secure development practices.

The role provides technical expertise for Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secure code review, and code quality analysis. The engineer configures and tunes scanning technologies, validates findings, supports remediation, and develops meaningful reporting for technical and executive stakeholders.

Key Responsibilities and Duties

Administer, configure, tune, and optimize application security platforms supporting SAST, DAST, and SCA capabilities.

Manage and maintain SonarQube and similar code analysis technologies, including scanning configurations, rule profiles, quality gates, access, integrations, and reporting.

Develop and maintain application security scanning standards, procedures, runbooks, and operating documentation.

Integrate application security testing into CI/CD pipelines and DevSecOps workflows in partnership with development and platform engineering teams.

Triage and validate security findings, reduce false positives, document risk decisions, and improve the accuracy and usefulness of scan results.

Partners with application teams to prioritize and remediate vulnerabilities based on exploitability, business context, compensating controls, and organizational risk criteria.

Provide secure coding guidance and technical consultation aligned with OWASP practices, the NIST Secure Software Development Framework, and internal security standards.

Create dashboards, metrics, and key risk indicators that communicate application security coverage, finding trends, remediation performance, scan health, and control effectiveness.

Analyze recurring vulnerability patterns and recommend preventive controls, developer education, rule changes, or pipeline improvements.

Support threat modeling, architecture reviews, secure design assessments, and targeted code reviews for new and existing applications.

Assist with audit, examination, and risk assessment requests by providing accurate evidence and documentation for application security controls.

Research emerging application security threats, vulnerabilities, attack techniques, and testing methods to continuously improve the program.

Serve as a senior technical subject matter expert and mentor, without formal responsibility for assigning, reviewing, or delegating the work of other employees.

Minimum Qualifications

Bachelor’s degree in Information Security, Computer Science, Software Engineering, or a related field preferred, or equivalent relevant experience.

5 or more years of cybersecurity, software engineering, DevSecOps, vulnerability management, or application security experience.

3 or more years of direct experience operating, administering, or integrating application security scanning technologies.

Hands-on experience with SAST and DAST scanning configuration, execution, tuning, triage, and reporting.

Working knowledge of SCA, secure code review, vulnerability management, and remediation practices.

Experience with SonarQube or a comparable code quality and security analysis platform.

Understanding of modern application architectures, APIs, containers, microservices, and cloud-native delivery patterns.

Familiarity with CI/CD platforms, source code management, build automation, and DevSecOps processes.

Ability to communicate technical risk and remediation guidance clearly to developers, engineers, managers, and nontechnical stakeholders.

Preferred Qualifications

7 or more years of cybersecurity, software security, software engineering, or application security experience.

Advanced experience with SonarQube administration, custom rule profiles, quality gates, project onboarding, integration, and reporting.

Experience with commercial application security technologies such as Veracode, Checkmarx, Fortify, Contrast Security, Burp Suite Enterprise, or comparable platforms.

Experience integrating security testing into GitHub, GitLab, Azure DevOps, Jenkins, or similar CI/CD platforms.

Knowledge of OWASP Top 10, OWASP ASVS, NIST SSDF, secure SDLC practices, and common application weakness classifications.

Experience producing operational dashboards, executive metrics, key risk indicators, and trend reporting.

Experience working in regulated financial services or another highly regulated enterprise environment.

Experience supporting FFIEC, OCC, SOX, PCI DSS, or comparable audit and regulatory requirements.

Experience automating application security workflows and reporting through PowerShell, Python, APIs, or vendor scripting.

Preferred Certifications

CSSLP

GWAPT, GWEB, GSSP, or another relevant GIAC certification

OSWE or a comparable advanced application security certification

CISSP

Microsoft Azure Security Engineer Associate, AWS Certified Security – Specialty, or a comparable cloud security certification

Core Competencies

Application Security Engineering

SAST, DAST, SCA, code analysis, secure SDLC

Platform Ownership

Configuration, tuning, integrations, health, upgrades

Vulnerability Management

Validation, prioritization, remediation, exceptions

DevSecOps Collaboration

CI/CD integration, developer enablement, automation

Risk Communication

Technical guidance, dashboards, KRIs, executive reporting

Governance

Standards, procedures, evidence, regulated environments