1

Lead Application Security Engineer Jobs in California

Lead Application Security Engineer

San Francisco, CA ยท On-site

$69.25 - $92.50/hr

About the Role We're seeking a Lead Application Security Engineer to help advance Zeta Global's application and platform security posture through AI-native security practices, intelligent automation ...

Lead Application Security Engineer

San Francisco, CA ยท On-site

$69.25 - $92.50/hr

About the Role We're seeking a Lead Application Security Engineer to help advance Zeta Global's application and platform security posture through AI-native security practices, intelligent automation ...

Application Security Engineer

San Francisco, CA ยท On-site

$69.25 - $92.50/hr

Zof AI is seeking an Application Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent ...

Application Security Engineer

Sunnyvale, CA ยท On-site

$70 - $93.50/hr

We are looking for an Application Security Engineer with a strong focus on Vulnerability Management to help secure Cerebras software, infrastructure, and AI platforms. You will own and evolve key ...

Application Security Engineer

Sunnyvale, CA ยท On-site

$69 - $92.25/hr

About the Role We are looking for an Application Security Engineer with a strong focus on Vulnerability Management to help secure Cerebras software, infrastructure, and AI platforms. You will own and ...

Application Security Engineer

San Francisco, CA ยท On-site

$69.25 - $92.50/hr

We're hiring an Application Security Engineer to own security across Opal's product and platform - and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly ...

Staff Application Security Engineer

San Francisco, CA ยท On-site

$69.25 - $92.50/hr

The Staff Application Security Engineer will partner with the Engineering, DevOps, Product, and ... Lead threat modeling sessions for complex, high-impact systems to identify and mitigate security ...

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud ...

Application Security Engineer

Palo Alto, CA ยท On-site

$69.25 - $92.50/hr

They are seeking an innovative Application Security Engineer responsible for ensuring the security and integrity of cloud-native applications throughout the software development lifecycle, with a ...

Application Security Engineer

Palo Alto, CA ยท On-site

$100K - $258K/yr

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud ...

Senior Application Security Engineer

Irvine, CA ยท On-site

$63 - $84.25/hr

Become a key player in our Information Security team as a Senior Application Security Engineer, where you will leverage your expertise in application security, security engineering, and software ...

Application Security Engineer

Palo Alto, CA ยท On-site

$100K - $258K/yr

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud ...

Application Security Engineer

Palo Alto, CA ยท On-site

$100K - $258K/yr

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our ...

Become a key player in our Information Security team as a Senior Application Security Engineer, where you will leverage your expertise in application security, security engineering, and software ...

... Engineering, Information Systems, or equivalent years of experience in a related technical field * 3+ years of experience in the field of application security or related security role * Passion for ...

next page

Showing results 1-20

Lead Application Security Engineer information

What does a lead application security engineer do?

A Lead Application Security Engineer is responsible for ensuring the security of software applications throughout their development lifecycle. They design, implement, and oversee security measures to protect applications from threats and vulnerabilities. This role typically involves leading security reviews, performing risk assessments, guiding development teams on secure coding practices, and responding to security incidents. They also stay updated on emerging threats and help shape security policies and protocols within the organization.

How does a lead application security engineer typically collaborate with software development teams to ensure secure application design?

As a Lead Application Security Engineer, you will regularly partner with software developers throughout the software development lifecycle. This collaboration includes conducting security reviews of architecture and code, recommending best practices, providing secure coding training, and integrating security tools into development pipelines. Building strong relationships with developers and fostering a security-first mindset are key to ensuring vulnerabilities are addressed early, and secure design principles are consistently applied. Expect to participate in design meetings, threat modeling sessions, and code reviews, acting as both a consultant and a technical leader.

What are the key skills and qualifications needed to thrive as a lead application security engineer, and why are they important?

A Lead Application Security Engineer requires deep expertise in secure software development, vulnerability assessment, and threat modeling, often backed by a computer science degree and relevant certifications such as CISSP or CSSLP. Familiarity with security testing tools (like Burp Suite, OWASP ZAP, and SAST/DAST platforms), as well as experience with CI/CD pipelines and cloud environments, is typically expected. Strong leadership, problem-solving, and communication skills help drive security initiatives and effectively collaborate with development teams. These skills are crucial to proactively identify and mitigate security risks, ensuring robust protection of applications in dynamic development environments.

What is the difference between Lead Application Security Engineer vs Application Security Engineer?

AspectLead Application Security EngineerApplication Security Engineer
CertificationsOSCP, CISSP, CEHOSCP, CISSP, CEH
Work EnvironmentLeads security initiatives, manages teamsExecutes security assessments, implements security measures
Industry UsageUsed in organizations with mature security teamsCommon in growing security teams

The Lead Application Security Engineer typically oversees security projects, manages teams, and sets strategic security goals. In contrast, the Application Security Engineer focuses on hands-on security assessments and implementing security controls. Both roles require similar certifications and are vital in organizations prioritizing application security, but the lead role involves more leadership and strategic responsibilities.

What cities in California are hiring for Lead Application Security Engineer jobs?

Cities in California with the most Lead Application Security Engineer job openings:

Infographic showing various Lead Application Security Engineer job openings in California as of August 2026, with employment types broken down into 82% Full Time, 14% Part Time, and 4% Contract. Highlights an 89% Physical, 3% Hybrid, and 8% Remote job distribution.

Lead Application Security Engineer

San Francisco, CA โ€ข On-site

Zeta Global
Marketingย โ€ขย 1 - 5K employees

$69.25 - $92.50/hr

Full-time

Medical, Dental, Vision, PTO

Re-posted 27 days ago


Job description

WHO WE ARE
Zeta Global (NYSE: ZETA) is the AI-Powered Marketing Cloud that leverages advanced artificial intelligence (AI) and trillions of consumer signals to make it easier for marketers to acquire, grow, and retain customers more efficiently. Through the Zeta Marketing Platform (ZMP), our vision is to make sophisticated marketing simple by unifying identity, intelligence, and omnichannel activation into a single platform - powered by one of the industry's largest proprietary databases and AI. Our enterprise customers across multiple verticals are empowered to personalize experiences with consumers at an individual level across every channel, delivering better results for marketing programs. Zeta was founded in 2007 by David A. Steinberg and John Sculley and is headquartered in New York City with offices around the world. To learn more, go to www.zetaglobal.com.
About the Role
We're seeking a Lead Application Security Engineer to help advance Zeta Global's application and platform security posture through AI-native security practices, intelligent automation, and scalable security engineering. You'll play a critical role in embedding security throughout the software development lifecycle by using AI-driven tools, automated controls, and data-informed risk prioritization to ensure our systems, applications, and AI-powered platforms are built securely from the ground up.
Zeta operates at massive scale, powering billions of consumer profiles and petabytes of data across real-time, AI-powered marketing platforms. In this role, you'll collaborate with Engineering, Product, QA, DevOps, and AI platform teams to identify risks, design secure-by-default patterns, and build automated security capabilities that enable secure innovation at speed.
This position offers significant technical scope, cross-functional visibility, and the opportunity to directly influence the company's security maturity through AI-enabled threat modeling, automated validation, intelligent vulnerability management, and proactive defense.
Key Responsibilities
AI-Driven Threat Modeling & Security Validation
  • Use AI-assisted threat modeling capabilities to identify application, platform, API, cloud, data, and AI/ML security risks early in the design and development process.
  • Leverage automated security review tools to evaluate architecture, design documents, code changes, APIs, and data flows for security gaps and control weaknesses.
  • Drive AI-assisted code security reviews using SAST, DAST, SCA, secrets detection, IaC scanning, container scanning, and contextual risk analysis.
  • Use automation and intelligent correlation to assess third-party libraries, APIs, vendor integrations, and open-source dependencies for security, compliance, and supply-chain risk.
  • Support AI-enabled red team, blue team, and incident response simulations to validate detection, prevention, and response capabilities.

Embedding AI-Native Security into the SDLC
  • Partner with developers and QA engineers to embed AI-driven security testing and automated risk detection into CI/CD pipelines.
  • Build and improve security automation that provides real-time feedback to developers during design, coding, testing, release, and deployment.
  • Use AI-assisted analysis to review architecture and design artifacts, identify risks earlier, and recommend secure implementation patterns.
  • Contribute to intelligent security checkpoints that reduce manual review effort while improving consistency, traceability, and developer velocity.
  • Help design scalable guardrails, reusable security controls, and policy-as-code capabilities across application and platform teams.

Emerging Threat Monitoring & Proactive Defense
  • Monitor evolving application, cloud, API, AI/ML, and data security risks using AI-assisted threat intelligence, vulnerability intelligence, and attack-pattern analysis.
  • Identify and evaluate AI-specific threats such as prompt injection, data poisoning, model abuse, model leakage, insecure tool use, and sensitive data exposure.
  • Assist in designing and deploying proactive defense mechanisms across applications, APIs, data platforms, and AI-powered systems.
  • Use automated signals, telemetry, and risk scoring to support investigations, post-incident analysis, and continuous improvement of prevention and detection capabilities.
  • Translate recurring vulnerabilities and incidents into feedback loops that improve threat models, secure design patterns, and SDLC controls.

Security Awareness, Standards & Scalable Enablement
  • Promote secure coding and secure design practices through AI-assisted guidance, reusable playbooks, automated recommendations, and developer-friendly documentation.
  • Contribute to internal security standards, secure engineering patterns, and AI-native security playbooks.
  • Help teams adopt security self-service capabilities that reduce dependency on manual AppSec review.
  • Collaborate closely with Engineering, DevOps, QA, Product, and AI platform teams to foster a security-first and automation-first culture.
  • Use metrics and insights to measure control effectiveness, remediation trends, developer adoption, and overall security maturity.

What You Need to Succeed
  • Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience.
  • 5+ years of experience in Application Security, DevSecOps, Secure Software Development, or Security Engineering.
  • Strong understanding of OWASP Top 10, SANS CWE Top 25, secure design principles, and application threat modeling.
  • Familiarity with AI/ML security concepts such as prompt injection, data poisoning, adversarial testing, model integrity, model abuse, and AI supply-chain risks.
  • Experience building or integrating AI-assisted security workflows, security bots, automated triage systems, or risk scoring models.
  • Experience using AI-assisted or automation-driven approaches to improve security testing, vulnerability analysis, code review, or risk prioritization.
  • Experience with modern application frameworks and architectures such as React, Node.js, Django, FastAPI, or similar technologies.
  • Knowledge of securing APIs, microservices, authentication, and authorization mechanisms such as OAuth2, OIDC, JWT, and service-to-service authentication.
  • Experience with cloud platforms such as AWS, GCP, or Azure, and containerized environments such as Docker and Kubernetes.
  • Working knowledge of security testing and automation tools such as Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security, or similar tools.
  • Ability to analyze security findings, correlate risk context, and drive practical remediation guidance for engineering teams.
  • Strong collaboration and communication skills with the ability to work across Engineering, Product, QA, DevOps, and Security teams.

Nice to Have
  • Experience with policy-as-code, infrastructure-as-code security, CI/CD security controls, and automated governance.
  • Experience with automation frameworks and scripting for security testing, vulnerability validation, and remediation workflows.
  • Relevant certifications such as OSCP, GWAPT, CSSLP, cloud security certifications, or AI/ML-specific security certifications.

BENEFITS & PERKS
  • Unlimited PTO
  • Excellent medical, dental, and vision coverage
  • Employee Equity
  • Employee Discounts, Virtual Wellness Classes, and Pet Insurance And more!!

SALARY RANGE
The salary range for this role is $220,000-$250,000 TC, depending on location and experience.
PEOPLE & CULTURE AT ZETA
Zeta considers applicants for employment without regard to, and does not discriminate on the basis of an individual's sex, race, color, religion, age, disability, status as a veteran, or national or ethnic origin; nor does Zeta discriminate on the basis of sexual orientation, gender identity or expression.
We're committed to building a workplace culture of trust and belonging, so everyone feels invited to bring their whole selves to work. We provide a forum for employees to celebrate, support and advocate for one another. Learn more about our commitment to diversity, equity and inclusion here: https://zetaglobal.com/blog/a-look-into-zetas-ergs/
ZETA IN THE NEWS!
https://zetaglobal.com/press/?cat=press-releases
#LI-TS1