1

Lead Application Security Engineer Jobs in Arizona

Application Security Engineer

Phoenix, AZ · On-site

$58.25 - $78/hr

Lead the investigation and mitigation of application-level security incidents, collaborating with the SOC and engineering teams to ensure rapid remediation and stakeholder communication. * Provide ...

Application Security Engineer

Phoenix, AZ · On-site

$58.25 - $78/hr

Lead the investigation and mitigation of application-level security incidents, collaborating with the SOC and engineering teams to ensure rapid remediation and stakeholder communication. * Provide ...

Application Security Engineer

Phoenix, AZ · On-site

$58.25 - $78/hr

Lead the investigation and mitigation of application-level security incidents, collaborating with the SOC and engineering teams to ensure rapid remediation and stakeholder communication. * Provide ...

As a member of the Information Security team, the Sr. Application Security Engineer will be responsible for helping to develop, mature, and sustain the Application Security program for the company.

Security Engineer Location: Phoenix, AZ Job Type: Contract (Long-Term) Experience: 3-8+ years Job ... Review application architecture, integrations, APIs, and data flows to identify security risks

Lead cybersecurity efforts supporting SOC 2 Type II compliance and ongoing certification activities ... Manage application dependency scanning, vulnerability assessments, and remediation activities.

You will report to the EVP of IT and Security and CIO and lead the App and AI Security team of ... Hands-on experience building security into CI/CD as guardrails-as-code (Azure DevOps, GitHub ...

Security Engineer Location: Phoenix AZ Duration: Long term Key Responsibilities • Conduct data ... application architecture, integrations, APIs, and data flows to identify security risks. • Assess ...

Manager of Application & AI Security

Scottsdale, AZ · On-site

$59.25 - $79/hr

Lead AI Red-Teaming: Conduct proactive prompt-injection, jailbreak testing, and LLM red-teaming ... developer workflow. Who You Are * An Experienced Leader: You possess a Bachelor's degree in ...

... application security, secure software development, or security engineering, including a senior or ... lead role. * Proven experience leading threat modeling and secure design/architecture reviews for ...

... application security, secure software development, or security engineering, including a senior or ... lead role. * Proven experience leading threat modeling and secure design/architecture reviews for ...

Manager of Application & AI Security

Scottsdale, AZ · On-site

$59.25 - $79/hr

Lead AI Red-Teaming: Conduct proactive prompt-injection, jailbreak testing, and LLM red-teaming ... developer workflow. Who You Are * An Experienced Leader: You possess a Bachelor's degree in ...

next page

Showing results 1-20

Lead Application Security Engineer information

What does a lead application security engineer do?

A Lead Application Security Engineer is responsible for ensuring the security of software applications throughout their development lifecycle. They design, implement, and oversee security measures to protect applications from threats and vulnerabilities. This role typically involves leading security reviews, performing risk assessments, guiding development teams on secure coding practices, and responding to security incidents. They also stay updated on emerging threats and help shape security policies and protocols within the organization.

How does a lead application security engineer typically collaborate with software development teams to ensure secure application design?

As a Lead Application Security Engineer, you will regularly partner with software developers throughout the software development lifecycle. This collaboration includes conducting security reviews of architecture and code, recommending best practices, providing secure coding training, and integrating security tools into development pipelines. Building strong relationships with developers and fostering a security-first mindset are key to ensuring vulnerabilities are addressed early, and secure design principles are consistently applied. Expect to participate in design meetings, threat modeling sessions, and code reviews, acting as both a consultant and a technical leader.

What are the key skills and qualifications needed to thrive as a lead application security engineer, and why are they important?

A Lead Application Security Engineer requires deep expertise in secure software development, vulnerability assessment, and threat modeling, often backed by a computer science degree and relevant certifications such as CISSP or CSSLP. Familiarity with security testing tools (like Burp Suite, OWASP ZAP, and SAST/DAST platforms), as well as experience with CI/CD pipelines and cloud environments, is typically expected. Strong leadership, problem-solving, and communication skills help drive security initiatives and effectively collaborate with development teams. These skills are crucial to proactively identify and mitigate security risks, ensuring robust protection of applications in dynamic development environments.

What is the difference between Lead Application Security Engineer vs Application Security Engineer?

AspectLead Application Security EngineerApplication Security Engineer
CertificationsOSCP, CISSP, CEHOSCP, CISSP, CEH
Work EnvironmentLeads security initiatives, manages teamsExecutes security assessments, implements security measures
Industry UsageUsed in organizations with mature security teamsCommon in growing security teams

The Lead Application Security Engineer typically oversees security projects, manages teams, and sets strategic security goals. In contrast, the Application Security Engineer focuses on hands-on security assessments and implementing security controls. Both roles require similar certifications and are vital in organizations prioritizing application security, but the lead role involves more leadership and strategic responsibilities.

What cities in Arizona are hiring for Lead Application Security Engineer jobs?

Cities in Arizona with the most Lead Application Security Engineer job openings:

Infographic showing various Lead Application Security Engineer job openings in Arizona as of August 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution.

Application Security Engineer

Phoenix, AZ • On-site

SmartRent
IT Services • 51 - 200 employees

$58.25 - $78/hr

Full-time

Re-posted 9 days ago


Job description

Job Description

The Application Security Engineer is responsible for supporting the security and privacy of the SmartRent platform through the management of information security risk, system resilience, and compliance activities. This role uses cloud-native and third-party security tools to protect company assets and data across multiple platforms.

This role partners with engineering, development, and external stakeholders to implement and maintain security policies, processes, and standards, including secure software development lifecycle (SDLC) practices. Success in this role requires strong communication skills, the ability to coordinate across multiple technical teams, and the ability to support consistent security practices across the organization.

Open to candidates outside of Arizona

Responsibilities

  • Develop and execute a comprehensive application security strategy aligned with business objectives and industry standards.
  • Maintain and advise on secure coding standards, security documentation, and application security processes.
  • Deliver application security and privacy training for development teams.
  • Review source code to identify security vulnerabilities, insecure patterns, secrets exposure, and risks associated with AI-generated code.
  • Triage, reproduce, and support remediation of application vulnerabilities (e.g., SQL injection, XSS, access control weaknesses) identified through automated tools (SAST, DAST, SCA) or manual analysis.
  • Manage application security workflows, including task prioritization, ticket tracking, and coordination with development and DevOps teams.
  • Maintain and enhance SmartRent's responsible disclosure and vulnerability reporting program.
  • Partner with developers to implement encryption, hashing, and secure key management practices.
  • Collaborate with developers and engineering teams to perform threat modeling, identify attack paths, and assess weaknesses.
  • Lead the investigation and mitigation of application-level security incidents, collaborating with the SOC and engineering teams to ensure rapid remediation and stakeholder communication.
  • Provide guidance on security and privacy controls for cloud infrastructure (AWS), application development, and IoT hardware.
  • Conduct regular application risk assessments to identify vulnerabilities and emerging threats.
  • Research emerging cybersecurity risks and recommend mitigation strategies as appropriate.
  • Perform adversarial testing and security validation of applications, including internal AI models and services.
  • Use cloud-native security tools to identify and secure large language model (LLM) integrations and implement appropriate security guardrails.

Required Qualifications

  • 4-6 years of experience in application security, including development and maintenance of security policies and collaboration with engineering and release teams.
  • Experience identifying and remediating application vulnerabilities across modern programming languages, including Elixir, JavaScript, Ruby, Python, or similar languages.
  • Strong knowledge of OWASP Top 10, OWASP API Top 10, and modern authentication mechanisms, including JWT and OAuth.
  • Hands-on experience with application security tools, including SAST, DAST, and SCA platforms (e.g., GHAS, Burp Suite, Fortra, or similar tools).
  • Experience working with cloud security controls, including AWS-native tools, web application firewalls (WAF), or similar technologies.
  • Experience managing or supporting vulnerability disclosure or bug bounty programs.
  • Strong written and verbal communication skills, with the ability to clearly communicate security requirements to technical teams.
  • Demonstrated problem-solving and analytical skills in identifying and mitigating application security risks.

Preferred Qualifications

  • Industry certifications such as CSSLP, GIAC GWAPT, CEH, or equivalent security certifications.
  • Experience working with CloudFlare, AWS security services, or similar cloud-native security tools.
  • Experience integrating security practices into SDLC processes.
  • Experience supporting threat modeling or application security architecture reviews.