1

Appsec Engineer Jobs in Massachusetts (NOW HIRING)

Ability to work cross-functionally with cloud, DevOps, AppSec, and platform teams. Preferred / Nice-to-Have Qualifications * Experience securing MLOpspipelines and AI-enabled platforms. * Familiarity ...

... AppSec, and Identity) and reference architectures. • Ensure guidance is practical, clearly ... Required : • Proven background in security engineering or architecture within network, cloud, and ...

Manager Application Security

Westwood, MA · On-site +1

$133K - $190K/yr

... engineers and subject matter experts Continuously improve tooling, automation, and processes to scale AppSec capabilities efficiently Required Experience and Skills 10 plus years of cybersecurity ...

Manager Application Security

Westwood, MA · On-site +1

$133K - $190K/yr

... engineers and subject matter experts Continuously improve tooling, automation, and processes to scale AppSec capabilities efficiently Required Experience and Skills 10 plus years of cybersecurity ...

Manager Application Security

Boston, MA · On-site +1

$133K - $190K/yr

... engineers and subject matter experts Continuously improve tooling, automation, and processes to scale AppSec capabilities efficiently Required Experience and Skills 10 plus years of cybersecurity ...

Manager Application Security

Boston, MA · On-site +1

$133K - $190K/yr

... engineers and subject matter experts Continuously improve tooling, automation, and processes to scale AppSec capabilities efficiently Required Experience and Skills 10 plus years of cybersecurity ...

Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives ... Learn more at semgrep.dev. About the role As a Senior Engineering Manager for Semgrep Guardian, you ...

New

... AppSec, and Identity) and reference architectures. Ensure guidance is practical, clearly defining ... Balance security requirements with operational complexity and engineering speed. * Architecture ...

Showing results 41-60

Appsec Engineer information

What does an AppSec engineer do?

An Application Security (AppSec) Engineer is responsible for ensuring the security of software applications by identifying and mitigating vulnerabilities throughout the software development lifecycle. They work closely with development teams to implement secure coding practices, perform code reviews, conduct security assessments, and respond to security incidents. Additionally, AppSec Engineers often use automated tools to scan for security flaws and help educate teams on the latest security threats and best practices.

What are the key skills and qualifications needed to thrive as an AppSec engineer?

To thrive as an AppSec Engineer, you need a solid understanding of application security principles, secure coding practices, and vulnerability assessment, typically supported by a degree in computer science or a related field. Familiarity with tools like static and dynamic application security testing (SAST/DAST), OWASP frameworks, and certifications such as CISSP or OSCP is highly valued. Strong analytical thinking, problem-solving abilities, and effective communication skills help you collaborate across development and security teams. These skills are crucial for identifying, mitigating, and preventing security risks in software applications, thereby protecting organizational assets and user data.

What are some common challenges AppSec engineers face when collaborating with development teams?

Appsec Engineers often work closely with software developers to integrate security best practices into the development lifecycle. A common challenge is balancing security requirements with project timelines and feature delivery, as development teams may prioritize speed over thorough security reviews. Effective communication and the ability to educate colleagues about secure coding practices are essential for overcoming these challenges. Additionally, Appsec Engineers may need to adapt to various development methodologies, such as Agile or DevOps, which can impact how and when security is incorporated into projects.

What are popular job titles related to Appsec Engineer jobs in Massachusetts?

For Appsec Engineer jobs in Massachusetts, the most frequently searched job titles are:

What job categories do people searching Appsec Engineer jobs in Massachusetts look for?

The top searched job categories for Appsec Engineer jobs in Massachusetts are:

Infographic showing various Appsec Engineer job openings in Massachusetts as of August 2026, with employment types broken down into 95% Full Time, 2% Part Time, and 3% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution.

Principal Security Engineer, Cloud & Infrastructure

Cambridge Mobile Telematics

Cambridge, MA • On-site, Remote

$130K - $163K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 19 days ago


Job description

We're hiring a Principal Security Engineer I, Cloud & Infrastructure to own the security architecture of CMT's products, from our mobile SDKs and APIs to the services that power our platform. This is a highly autonomous individual contributor role where you'll set the technical direction for product security and influence engineering teams to deliver secure solutions.

You'll stay hands-on with architecture while shaping security strategy across the organization through technical leadership, collaboration, and sound engineering judgment rather than people management.

You'll also define how we securely build AI-powered products and adopt AI development tools, establishing the guardrails that enable innovation while reducing security risk.

CMT is looking for a Principal Security Engineer I, Cloud & Infrastructure to help us change the world. CMT has helped protect over 65 million drivers and prevent over 126,000 crashes worldwide. We build AI to solve some of the most difficult challenges in mobility - understanding and reducing risk, detecting crashes, and getting people life-saving help. The problems are hard. The impact is real. No matter your role, your work will matter at CMT.

Responsibilities:

  • Own the end-to-end security architecture for CMT's products, including mobile SDKs, backend services, APIs, data pipelines, and partner integrations
  • Define security standards, reference architectures, and engineering guardrails, and drive adoption across teams
  • Embed security into the SDLC through threat modeling, secure design reviews, and actionable engineering requirements
  • Lead threat modeling and translate findings into prioritized engineering work
  • Define application security strategy for testing, secure coding, secrets management, and software supply chain security
  • Own security architecture for protecting sensitive driver and location data
  • Define security architecture and guardrails for AI/ML features and AI development tools
  • Own the AppSec and Product Security roadmap, including technology strategy and prioritization
  • Serve as the senior security authority for architecture reviews, risk decisions, and technical guidance
  • Support customer and partner security reviews and mentor engineers on secure design
  • Complete any additional tasks as they arise

Qualifications:

  • Bachelor's degree or equivalent years of experience and/or certification in a related field
  • 7+ years of experience in security, with deep, hands-on expertise in application and product security architecture
  • Broad AWS expertise - fluency in the fundamentals, including cloud networking, cloud firewalls, security groups, and IAM policies
  • Experience with infrastructure as code, build pipelines, and cloud platform security
  • Proven ability to provide technical leadership and drive security initiatives through influence
  • Strong software engineering foundation with experience reviewing code and system architecture
  • Deep knowledge of threat modeling, secure SDLC, OWASP, authentication, cryptography, API security, and mobile security
  • Experience securing products that process sensitive personal data and support regulatory requirements
  • Working knowledge of AI/ML and LLM security, including secure AI adoption
  • Excellent written and verbal communication skills

Nice to Haves:

  • Experience with mobile SDK security, reverse engineering, and anti-tampering
  • Familiarity with data-intensive architectures and ML-driven products
  • Experience developing AI governance or secure AI adoption programs
  • Experience in telematics, IoT, connected vehicles, fintech, or other high-trust industries
  • Relevant certifications such as CSSLP, OSCP, or GWEB

Compensation and Benefits:

  • Fair and competitive salary based on skills and experience, and annual performance bonus
  • Equity may be awarded in the form of Restricted Stock Units (RSUs)
  • Medical, Dental, Vision and Life Insurance, matching 401k, short-term & long-term disability and parental leave
  • Unlimited Paid Time Off including vacation, sick days & public holidays
  • Flexible scheduling and work from home policy depending on role and responsibilities

Base Salary Range

  • The base salary range for this position is: $130,600 to $163,300. This range is specifically for Cambridge, MA

Additional Perks:

  • Work on a mission with real impact: crashes prevented, injuries avoided, lives protected around the world
  • Join an industry leader - 65 million drivers protected, powering 140+ programs across 25 countries
  • Recognized innovator in mobility AI, earning top honors including the TIME Industry Leader in AI, a Gold Edison Award, and the Artificial Intelligence Excellence Award for AI for Social Good. CMT is also Great Place to Work Certified
  • Be part of the team inventing the future of mobility and road safety
  • Move fast, own outcomes, do work that matters
  • High ownership, small teams, and direct access to leadership - no layers between your work and its impact
  • Unlimited PTO, flexible scheduling, competitive salary, annual performance bonus, RSUs, and full benefits including medical, dental, vision, and 401k match
  • Summer Fridays provide team members with half days to recharge
  • Join one of our employee resource groups: Black, AAPI, LGBTQIA+, Women, Book Club, and Health & Wellness
  • Comprehensive wellness, education, and employee assistance programs

Commitment to Diversity and Inclusion:

At CMT, we believe the best ideas come from a mix of backgrounds and perspectives. 

We are an equal-opportunity employer committed to creating a workplace and culture where everyone feels valued, respected, and empowered to bring their unique talents and perspectives. Diversity is essential to our success, and we actively seek candidates from all backgrounds to join our growing team. 

We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status or disability state. CMT is headquartered in Cambridge, MA. To learn more, visit www.cmtelematics.com and follow us on Instagram @cmt.ai

About Cambridge Mobile Telematics:

Cambridge Mobile Telematics (CMT) is the world's largest telematics and AI company for safer mobility. Its mission is to make the world's roads and drivers safer. The company's AI-driven platform, DriveWell Fusion, proactively identifies and reduces driving risk, leading to fewer crashes and injuries. To date, CMT's technology has helped prevent over 126,000 crashes worldwide. CMT enables partners to measure risk, detect crashes, provide life-saving assistance, and streamline claims. Headquartered in Cambridge, MA, CMT operates globally with offices in Budapest, Hungary; Chennai, India; Seattle, Washington; Tokyo, Japan; and Zagreb, Croatia. Learn more at www.cmt.ai.