Partner with AppSec Champions to embed secure development practices and improve security adoption. * Define and manage tiered security control strategy (Tier 1-3) with quarterly migration goals.
Partner with AppSec Champions to embed secure development practices and improve security adoption. * Define and manage tiered security control strategy (Tier 1-3) with quarterly migration goals.
Cyber Security Engineer
Boston, MA · On-site
Implement AppSec practices across SDLC * Experience with SAST| DAST| SCA tools * Perform threat modeling and secure design reviews * Conduct secure code reviews * Analyze vulnerabilities for ...
Cyber Security Engineer
Boston, MA · On-site
Implement AppSec practices across SDLC * Experience with SAST| DAST| SCA tools * Perform threat modeling and secure design reviews * Conduct secure code reviews * Analyze vulnerabilities for ...
Senior Security Engineer AppSec
Dallas, TX · On-site
$130K/yr
Lead bi-weekly AppSec Management Update & Post-Finding Review Training meetings * May perform other duties as assigned Qualifications * 3+ years of experience in application security, DevSecOps, or ...
Senior Security Engineer AppSec
Dallas, TX · On-site
$130K/yr
Lead bi-weekly AppSec Management Update & Post-Finding Review Training meetings * May perform other duties as assigned Qualifications * 3+ years of experience in application security, DevSecOps, or ...
AppSec & DevSecOps Engineer
$60.25 - $80.25/hr
Job Summary We are seeking an experienced and proactive Application Security (AppSec) and DevSecOps Engineer to embed security throughout the software development lifecycle and CI/CD pipelines. You ...
AppSec & DevSecOps Engineer
$60.25 - $80.25/hr
Job Summary We are seeking an experienced and proactive Application Security (AppSec) and DevSecOps Engineer to embed security throughout the software development lifecycle and CI/CD pipelines. You ...
Senior Security Engineer AppSec
$130K - $220K/yr
Lead bi-weekly AppSec Management Update & Post-Finding Review Training meetings * May perform other duties as assigned * 3+ years of experience in application security, DevSecOps, or related fields.
Senior Security Engineer AppSec
$130K - $220K/yr
Lead bi-weekly AppSec Management Update & Post-Finding Review Training meetings * May perform other duties as assigned * 3+ years of experience in application security, DevSecOps, or related fields.
Web Application Security Engineer (AppSec / DevSecOps)
Washington, DC · On-site
$66.50 - $89/hr
Experience in Application Security (AppSec), Web Application Security, or Product Security. * Strong knowledge of secure software development practices and Secure SDLC. * Experience performing ...
Quick apply
Web Application Security Engineer (AppSec / DevSecOps)
Washington, DC · On-site
$66.50 - $89/hr
Experience in Application Security (AppSec), Web Application Security, or Product Security. * Strong knowledge of secure software development practices and Secure SDLC. * Experience performing ...
Technical Marketing Manager, AppSec, Research and AI Security
$60.25 - $80.25/hr
You need to understand the AppSec and/or AI/ML Security ecosystems, know where these communities spend their time, and bring enough technical fluency that your work holds up to scrutiny. This is a ...
Technical Marketing Manager, AppSec, Research and AI Security
$60.25 - $80.25/hr
You need to understand the AppSec and/or AI/ML Security ecosystems, know where these communities spend their time, and bring enough technical fluency that your work holds up to scrutiny. This is a ...
AI AppSec Engineer Lead
Irvine, CA · On-site
$63 - $84.25/hr
Access on-demand professional development resources that allow you to hone existing skills and learn new ones "I can succeed as a AI AppSec Engineer Lead at Capital Group" As a LeadAIAppSecEngineer ...
AI AppSec Engineer Lead
Irvine, CA · On-site
$63 - $84.25/hr
Access on-demand professional development resources that allow you to hone existing skills and learn new ones "I can succeed as a AI AppSec Engineer Lead at Capital Group" As a LeadAIAppSecEngineer ...
AI AppSec Engineer Lead
Charlotte, NC · On-site
$57.50 - $76.75/hr
Access on-demand professional development resources that allow you to hone existing skills and learn new ones "I can succeed as a AI AppSec Engineer Lead at Capital Group" As a LeadAIAppSecEngineer ...
AI AppSec Engineer Lead
Charlotte, NC · On-site
$57.50 - $76.75/hr
Access on-demand professional development resources that allow you to hone existing skills and learn new ones "I can succeed as a AI AppSec Engineer Lead at Capital Group" As a LeadAIAppSecEngineer ...
Application Security Engineer
New York, NY · On-site
$68 - $72/hr
Standing up and operating the AppSec tooling stack - SAST, SCA, secrets scanning, and container/IaC scanning - integrated into business unit CI/CD pipelines. Designing and implementing AI-assisted ...
Application Security Engineer
New York, NY · On-site
$68 - $72/hr
Standing up and operating the AppSec tooling stack - SAST, SCA, secrets scanning, and container/IaC scanning - integrated into business unit CI/CD pipelines. Designing and implementing AI-assisted ...
Web Application Security Engineer (AppSec / DevSecOps)
Washington, DC · On-site
$66.50 - $89/hr
Experience in Application Security (AppSec), Web Application Security, or Product Security. * Strong knowledge of secure software development practices and Secure SDLC. * Experience performing ...
Web Application Security Engineer (AppSec / DevSecOps)
Washington, DC · On-site
$66.50 - $89/hr
Experience in Application Security (AppSec), Web Application Security, or Product Security. * Strong knowledge of secure software development practices and Secure SDLC. * Experience performing ...
Web Application Security Engineer (AppSec / DevSecOps)
Washington, DC · On-site
$66.50 - $89/hr
Experience in Application Security (AppSec), Web Application Security, or Product Security. * Strong knowledge of secure software development practices and Secure SDLC. * Experience performing ...
Web Application Security Engineer (AppSec / DevSecOps)
Washington, DC · On-site
$66.50 - $89/hr
Experience in Application Security (AppSec), Web Application Security, or Product Security. * Strong knowledge of secure software development practices and Secure SDLC. * Experience performing ...
Application Security Engineer
Manhattan, NY · On-site
$64.75 - $86.50/hr
What You'll Do • Application discovery and inventory across all business units, including ownership mapping, technology stack profiling, and risk tiering. • Standing up and operating the AppSec ...
Application Security Engineer
Manhattan, NY · On-site
$64.75 - $86.50/hr
What You'll Do • Application discovery and inventory across all business units, including ownership mapping, technology stack profiling, and risk tiering. • Standing up and operating the AppSec ...
Senior Application Security Engineer Vulnerability Operations - New jersey
Jersey City, NJ · On-site
$61.75 - $82.50/hr
Expertise in advanced AppSec concepts: secure design patterns, threat modeling, exploit analysis, and remediation strategy for modern architectures (microservices, APIs, cloud-native). * Proven ...
Senior Application Security Engineer Vulnerability Operations - New jersey
Jersey City, NJ · On-site
$61.75 - $82.50/hr
Expertise in advanced AppSec concepts: secure design patterns, threat modeling, exploit analysis, and remediation strategy for modern architectures (microservices, APIs, cloud-native). * Proven ...
AI AppSec Engineer Lead
Los Angeles, CA · On-site
$63.25 - $84.50/hr
Access on-demand professional development resources that allow you to hone existing skills and learn new ones "I can succeed as a AI AppSec Engineer Lead at Capital Group" As a LeadAIAppSecEngineer ...
AI AppSec Engineer Lead
Los Angeles, CA · On-site
$63.25 - $84.50/hr
Access on-demand professional development resources that allow you to hone existing skills and learn new ones "I can succeed as a AI AppSec Engineer Lead at Capital Group" As a LeadAIAppSecEngineer ...
Mid-level Vulnerability Assessments & Infrastructure Specialist - Vulnerability & Attack Surface ...
Mesa, AZ · On-site
$141K/yr
Operate and optimize enterprise vulnerability assessment platforms and AppSec integrations to identify, validate, and prioritize security findings across infrastructure and applications * Perform ...
Mid-level Vulnerability Assessments & Infrastructure Specialist - Vulnerability & Attack Surface ...
Mesa, AZ · On-site
$141K/yr
Operate and optimize enterprise vulnerability assessment platforms and AppSec integrations to identify, validate, and prioritize security findings across infrastructure and applications * Perform ...
Enable AppSec teams by recommending, evaluating, and architecting MLSecOps capabilities that improves security posture of ADLC (Agentic Application Development LIfecylce) * Partner with engineering ...
New
Enable AppSec teams by recommending, evaluating, and architecting MLSecOps capabilities that improves security posture of ADLC (Agentic Application Development LIfecylce) * Partner with engineering ...
New
Mid-level Vulnerability Assessments & Infrastructure Specialist - Vulnerability & Attack Surface ...
Hazelwood, MO · On-site
$134K/yr
Operate and optimize enterprise vulnerability assessment platforms and AppSec integrations to identify, validate, and prioritize security findings across infrastructure and applications * Perform ...
Mid-level Vulnerability Assessments & Infrastructure Specialist - Vulnerability & Attack Surface ...
Hazelwood, MO · On-site
$134K/yr
Operate and optimize enterprise vulnerability assessment platforms and AppSec integrations to identify, validate, and prioritize security findings across infrastructure and applications * Perform ...
Application Offensive Security Lead (Associate Director)
Jersey City, NJ · Hybrid
$64.25 - $85.75/hr
Lead a robust team of AppSec Consultants and AppSec Specialists and coordinate with various partners and vendors as part of AppSec ecosystem. * Generate reports on assessment findings and summarizes ...
Application Offensive Security Lead (Associate Director)
Jersey City, NJ · Hybrid
$64.25 - $85.75/hr
Lead a robust team of AppSec Consultants and AppSec Specialists and coordinate with various partners and vendors as part of AppSec ecosystem. * Generate reports on assessment findings and summarizes ...
Mid-level Vulnerability Assessments & Infrastructure Specialist - Vulnerability & Attack Surface ...
Plano, TX · On-site
$136K/yr
Operate and optimize enterprise vulnerability assessment platforms and AppSec integrations to identify, validate, and prioritize security findings across infrastructure and applications * Perform ...
Mid-level Vulnerability Assessments & Infrastructure Specialist - Vulnerability & Attack Surface ...
Plano, TX · On-site
$136K/yr
Operate and optimize enterprise vulnerability assessment platforms and AppSec integrations to identify, validate, and prioritize security findings across infrastructure and applications * Perform ...
Appsec information
Can you make $500,000 a year in cyber security?
What job makes $10,000 a month without a degree?
What does an AppSec team do?
Will AI replace AppSec engineers?
What is the difference between Appsec vs Security Analyst?
| Aspect | Appsec | Security Analyst |
|---|---|---|
| Required Credentials | Certifications like CISSP, CEH, OSCP; knowledge of secure coding | Certifications such as Security+, CISSP; threat analysis skills |
| Work Environment | Development teams, secure coding practices, application testing | Monitoring security systems, incident response, risk assessment |
| Employer & Industry Usage | Tech companies, software firms, organizations with application security needs | All industries, including finance, healthcare, government, focusing on security monitoring |
Appsec professionals focus on securing applications through secure coding, testing, and vulnerability management, while Security Analysts monitor and respond to security threats across systems. Both roles require security certifications and work in overlapping environments, but their core responsibilities differ in scope and focus.

$61.25 - $82/hr
Full-time
Posted 17 days ago
Job description
1. Strategic AppSec Leadership
- Drive enterprise-wide implementation of Application Security controls across CI/CD pipelines.
- Partner with AppSec Champions to embed secure development practices and improve security adoption.
- Define and manage tiered security control strategy (Tier 1–3) with quarterly migration goals.
- Enable decentralized security ownership across engineering teams.
2. Vulnerability & Threat Management
- Lead triage, analysis, and remediation of complex and high-risk vulnerabilities.
- Serve as SME for modern threat classes including cloud-native risks, APIs, supply chain, containers, serverless, and emerging OWASP categories.
- Perform threat modeling and security design reviews for critical applications.
- Provide escalation support for advanced AppSec issues.
3. CI/CD Security & Automation
- Architect and enhance CI/CD security integrations (SAST, DAST, SCA, secrets, IaC scanning).
- Implement policy-as-code and automated security gating (merge/build prevention).
- Develop reusable security automation frameworks and pipeline modules.
4. Governance & Reporting
- Build dashboards, KPIs, and risk scorecards using tools like Power BI or Grafana.
- Lead vulnerability governance forums and executive reporting on security posture and trends.
- Manage risk registers, remediation tracking, and quarterly program alignment.
5. Enablement & Continuous Improvement
- Mentor AppSec engineers and support security champion enablement programs.
- Evaluate scanning outputs, reduce false positives, and improve detection quality.
- Continuously enhance AppSec processes, tools, and onboarding workflows.
- Stay current with emerging threats and security trends.
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or related field.
- 7+ years of experience in Application Security, Vulnerability Management, or Secure SDLC.
- Strong expertise in secure design, threat modeling, exploit analysis, and remediation strategies.
- Hands-on experience with CI/CD security tooling (SAST, DAST, SCA, secrets, IaC scanning).
- Proven experience working with engineering teams to drive AppSec adoption and governance.
- Ability to analyze vulnerability trends and emerging/zero-day threats.
- Cloud security experience across AWS, Azure, or GCP.
- Certifications such as CISSP, CSSLP, OSCP, OSWE, GWAPT, or equivalent.
- Experience with policy enforcement tools (OPA/Gatekeeper).
- Knowledge of software supply chain security (SLSA, SBOM).
- Experience building AppSec Champion or federated security models.