1

Lead Application Security Engineer Jobs (NOW HIRING)

Your Team & Role As a Lead, Application Security on the Attack Surface Management team, you will ... Act as a bridge between AppSec, DevOps, Cloud, and business teams, ensuring security requirements ...

Application Security Engineer

Nashville, TN

$56.75 - $75.75/hr

How we LEAD: We are currently seeking an Application Security Engineer to join UMG's global Tech Security & Identity organization. Reporting to the Manager, Security Engineering and Vulnerability ...

Application Security Engineer

$60.25 - $80.25/hr

... Lead or support cloud security incident response • Document cloud security standards and ... application security engineering • Docker and Kubernetes security • Infrastructure as Code ...

APPLICATION SECURITY ENGINEER

Fairfax, VA · On-site

$60 - $80.25/hr

Application Security Engineer Location: Onsite in Fairfax, VA 3 days and in Washington, DC 2 days ... Lead security architecture reviews for mission-critical systems, ensuring secure-by-design ...

Application Security Engineer

Philadelphia, PA · On-site

$59.25 - $79.25/hr

Application Security Engineer Location: Philadelphia, PA 19103 (Hybrid) Type: 6-Month Contract-to ... Lead threat modeling exercises (STRIDE/PASTA) for monolith-to-microservices re-architecture ...

Application Security Engineer

Washington, DC · On-site

$66.50 - $89/hr

We are seeking an experienced IT Security Engineer for a lead role within our Security Team in our ... Work with application developers ensure adoption of security principals and best practices. 6. ...

Application Security Engineer

$60.25 - $80.25/hr

Application security engineer - threat & vulnerability management (ai focus) Us remote, cst zone ... Lead threat modeling for agents against the owasp llm top-10 and agentic top-10. * Define and ...

Application Security Engineer

Washington, DC · On-site

$66.50 - $89/hr

We are seeking an experienced IT Security Engineer for a lead role within our Security Team in our ... Work with application developers ensure adoption of security principals and best practices. 6. ...

Showing results 21-40

Lead Application Security Engineer information

See salary details

$9

$46

$100

How much do lead application security engineer jobs pay per hour?

As of Sep 10, 2026, the average hourly pay for lead application security engineer in the United States is $46.53, according to ZipRecruiter salary data. Most workers in this role earn between $17.31 and $65.38 per hour, depending on experience, location, and employer.

What does a lead application security engineer do?

A Lead Application Security Engineer is responsible for ensuring the security of software applications throughout their development lifecycle. They design, implement, and oversee security measures to protect applications from threats and vulnerabilities. This role typically involves leading security reviews, performing risk assessments, guiding development teams on secure coding practices, and responding to security incidents. They also stay updated on emerging threats and help shape security policies and protocols within the organization.

How does a lead application security engineer typically collaborate with software development teams to ensure secure application design?

As a Lead Application Security Engineer, you will regularly partner with software developers throughout the software development lifecycle. This collaboration includes conducting security reviews of architecture and code, recommending best practices, providing secure coding training, and integrating security tools into development pipelines. Building strong relationships with developers and fostering a security-first mindset are key to ensuring vulnerabilities are addressed early, and secure design principles are consistently applied. Expect to participate in design meetings, threat modeling sessions, and code reviews, acting as both a consultant and a technical leader.

What are the key skills and qualifications needed to thrive as a lead application security engineer, and why are they important?

A Lead Application Security Engineer requires deep expertise in secure software development, vulnerability assessment, and threat modeling, often backed by a computer science degree and relevant certifications such as CISSP or CSSLP. Familiarity with security testing tools (like Burp Suite, OWASP ZAP, and SAST/DAST platforms), as well as experience with CI/CD pipelines and cloud environments, is typically expected. Strong leadership, problem-solving, and communication skills help drive security initiatives and effectively collaborate with development teams. These skills are crucial to proactively identify and mitigate security risks, ensuring robust protection of applications in dynamic development environments.

What is the difference between Lead Application Security Engineer vs Application Security Engineer?

AspectLead Application Security EngineerApplication Security Engineer
CertificationsOSCP, CISSP, CEHOSCP, CISSP, CEH
Work EnvironmentLeads security initiatives, manages teamsExecutes security assessments, implements security measures
Industry UsageUsed in organizations with mature security teamsCommon in growing security teams

The Lead Application Security Engineer typically oversees security projects, manages teams, and sets strategic security goals. In contrast, the Application Security Engineer focuses on hands-on security assessments and implementing security controls. Both roles require similar certifications and are vital in organizations prioritizing application security, but the lead role involves more leadership and strategic responsibilities.

What cities are hiring for Lead Application Security Engineer jobs?

Cities with the most Lead Application Security Engineer job openings:

What states have the most Lead Application Security Engineer jobs?

States with the most job openings for Lead Application Security Engineer jobs include:

What are popular job titles related to Lead Application Security Engineer jobs?

For Lead Application Security Engineer jobs, the most frequently searched job titles are:

Infographic showing various Lead Application Security Engineer job openings in the United States as of September 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution, with an average salary of $96,776 per year, or $46.5 per hour.

Lead, Application Security

Newark, NJ • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 18 days ago


Prudential rating

8.7

Company rating: 8.7 out of 10

Based on 49 frontline employees who took The Breakroom Quiz

72nd of 315 rated insurance


Job description

Job Classification:
Technology - Information Security
Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability, and efficiency? The Global Technology team takes great pride in our culture where digital transformation is built into our DNA. When you join Prudential, you'll unlock an exciting and impactful career-while growing your skills and advancing your profession at one of the world's leading financial services institutions.
Your Team & Role
As a Lead, Application Security on the Attack Surface Management team, you will play a critical technical and strategic leadership role in advancing Prudential's enterprise application security program. You will partner closely with senior security leaders, the Information Security Office, the Chief Technology Office, and global engineering teams to drive secure-by-design outcomes and measurable risk reduction across Prudential's digital ecosystem.
In this role, you will be accountable for shaping, governing, and maturing application security capabilities for modern, cloud-native, and DevOps-driven environments. You will lead complex initiatives that secure applications at scale, influence future architecture and engineering practices, and embed security controls into CI/CD pipelines through automation and self-service enablement.
You will operate as a senior escalation point, trusted advisor, and technical authority, working on highly complex and ambiguous problems where judgment, experience, and influence are required. Your work will have a direct impact on Prudential's products, platforms, and customer trust.
The ideal candidate brings deep expertise in modern application architecture, cloud security, and DevSecOps, along with a forward-looking mindset focused on scaling security through automation, policy-as-code, and engineering-first solutions.
Here is What You Can Expect on a Typical Day
  • Serve as the technical lead and escalation point for complex operational and project work across the Application Security and Attack Surface Management domains.
  • Provide expert-level technical leadership for application security tools, platforms, and assessment methodologies.
  • Lead the design, evolution, and execution of application security assessment, response, and risk governance processes.
  • Leverage deep AppSec and DevSecOps expertise to solve complex technical, process, and organizational challenges impacting risk reduction.
  • Act as a bridge between AppSec, DevOps, Cloud, and business teams, ensuring security requirements are understood, actionable, and aligned to delivery objectives.
  • Partner with senior leadership to define the future-state vision for Prudential's application security program, informed by hands-on operational insight.
  • Lead the maturation of vulnerability and configuration monitoring across first-party, third-party, and open-source software.
  • Drive the integration of security controls into CI/CD pipelines, enabling automated enforcement, monitoring, and reporting.
  • Design and evolve security policies, standards, and alerting mechanisms aligned to SOX, NIST, PCI DSS, and other regulatory frameworks.
  • Evaluate and vet new security technologies, providing strategic recommendations and technical due diligence.
  • Apply qualitative and quantitative analysis to improve developer experience, security outcomes, and adoption of secure-by-design practices.
  • Champion secure-by-design principles across the SDLC through guidance, standards, tooling, and hands-on engagement.
  • Validate and document compensating controls and mitigations to manage risk until remediation is complete.
  • Ensure risk and performance metrics accurately represent application security posture for executive and regulatory audiences.
  • Author and maintain technical documentation, standards, and SOPs that continuously improve program maturity.
  • Develop proof-of-concept exploits in lab environments to demonstrate exploitability and validate remediation effectiveness.
  • Provide mentorship and technical guidance to junior team members, raising overall team capability and consistency.
  • Define requirements for workflow orchestration and automation to manage application security posture at enterprise scale.

The Skills & Expertise You Bring
  • Bachelor of Computer Science/Engineering or formal experience in related fields
  • Deep familiarity with vulnerability and security frameworks and data sources (CVE, CVSS, EPSS, CWE)
  • Proven experience leading and maturing application security and vulnerability management programs
  • Strong ability to partner with engineering teams to validate findings, reduce false positives, and drive effective remediation
  • Engineering mindset with strong systems thinking and problem-solving skills
  • Excellent written and verbal communication, with the ability to articulate technical and business risk to varied audiences
  • Experience working in agile and DevSecOps environments
  • Hands-on experience with industry frameworks (OWASP Top 10, OWASP WSTG, PTES, MITRE ATT&CK)
  • Deep experience with SAST, SCA, DAST, and ASPM tooling
  • Strong understanding of software composition analysis (SCA), SBOMs, and supply chain risk

Preferred qualifications:
  • Scripting and automation experience (Python, PowerShell, Bash)
  • Experience performing exploit validation and web application penetration testing
  • Strong understanding of threat actors and real-world attack techniques
  • Knowledge of security standards and frameworks (NIST, CIS, PCI DSS)
  • Experience applying Agentic AI or AI-assisted approaches to security use cases
  • Advanced security certifications (e.g., OSCP, GPEN, GWAPT, CASP+, GCSA, GCFA, GCIH)
  • Cloud certifications (AWS, Azure, GCP)
  • Demonstrated ability to influence without authority and lead through expertise

You'll Love Working Here Because You Can
Join a team and culture where your voice matters; where every day, your work transforms our experiences to make lives better. As you put your skills to use, we'll help you make an even bigger impact with learning experiences that can grow your technical AND leadership capabilities. You'll be surprised by what this rock-solid organization has in store for you.
What we offer you:
Prudential is required by state specific laws to include the salary range for this role when hiring a resident in applicable locations. The salary range for this role is from $123,700.00 to $204,100.00. Specific pricing for the role may vary within the above range based on many factors including geographic location, candidate experience, and skills.
  • Market competitive base salaries, with a yearly bonus potential at every level.
  • Medical, dental, vision, life insurance, disability insurance, Paid Time Off (PTO), and leave of absences, such as parental and military leave.
  • 401(k) plan with company match (up to 4%).
  • Company-funded pension plan.
  • Wellness Programs including up to $1,600 a year for reimbursement of items purchased to support personal wellbeing needs.
  • Work/Life Resources to help support topics such as parenting, housing, senior care, finances, pets, legal matters, education, emotional and mental health, and career development.
  • Education Benefit to help finance traditional college enrollment toward obtaining an approved degree and many accredited certificate programs.
  • Employee Stock Purchase Plan: Shares can be purchased at 85% of the lower of two prices (Beginning or End of the purchase period).

Eligibility to participate in a discretionary annual incentive program is subject to the rules governing the program, whereby an award, if any, depends on various factors including, without limitation, individual and organizational performance. To find out more about our Total Rewards package, visit Work Life Balance | Prudential Careers. Some of the above benefits may not apply to part-time employees scheduled to work less than 20 hours per week.
Prudential Financial, Inc. of the United States is not affiliated with Prudential plc. which is headquartered in the United Kingdom.
Prudential is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender identity, national origin, genetics, disability, marital status, age, veteran status, domestic partner status, medical condition or any other characteristic protected by law.
If you need an accommodation to complete the application process, please email accommodations.hw@prudential.com.
If you are experiencing a technical issue with your application or an assessment, please email careers.technicalsupport@prudential.com to request assistance.

What Prudential employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom