1

Non Exempt Application Security Engineer Jobs (NOW HIRING)

Application Security Engineer

Scottsdale, AZ ยท Hybrid

$59.25 - $79/hr

In this role, you will embed application security expertise directly into the engineering ... and non-technical audiences. * Experience in project estimation, requirements gathering, system ...

Application Security Engineer

Scottsdale, AZ ยท On-site

$59.25 - $79/hr

In this role, you will embed application security expertise directly into the engineering ... and non-technical audiences. * Experience in project estimation, requirements gathering, system ...

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven ... non-technical audiences PREFERRED SKILLS AND EXPERIENCE: * Experience with cloud platforms (e.g ...

Application Security Engineer

Reading, PA ยท Remote

$117K - $146K/yr

We are looking for an Application Security Engineer to strengthen secure software delivery and partner closely with engineering teams in Reading, Pennsylvania. This role focuses on embedding security ...

New

AI-Application Security Engineer

Saint Louis, MO ยท On-site

$57 - $76.25/hr

What You'll Be Doing The AI-Application Security Engineer is responsible for implementing and ... Ability to effectively communicate technical topics to technical and non-technical audiences.

Application Security Engineer

Phoenix, AZ

$58.25 - $78/hr

The Application Security Engineer is responsible for supporting the security and privacy of the SmartRent platform through the management of information security risk, system resilience, and ...

$45.25 - $60.50/hr

We are currently looking for a Application Security Engineer in Netherlands. This role sits at the intersection of software engineering and cybersecurity, focusing on strengthening the security ...

Application Security Engineer

$60.25 - $80.25/hr

Responsibilities The Application Security Engineer plays a crucial role in securing our growing portfolio of applications. This role will focus on integrating security best practices into the ...

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven ... non-technical audiences PREFERRED SKILLS AND EXPERIENCE: * Experience with cloud platforms (e.g ...

OR

$58.75 - $78.50/hr

Fragomen is seeking a Security Engineer - Application Security to join our talented Cyber Security team in our Technology Innovation Lab in Pittsburgh. Our industry-leading, immigration specific ...

Application Security Engineer

Salt Lake City, UT ยท On-site +1

$56.75 - $76/hr

Application Security Engineer About the Role Packsize is seeking an experienced Application Security Engineer to champion secure software development across our technology stack. You will collaborate ...

AI-Application Security Engineer

Saint Louis, MO ยท On-site

$57 - $76.25/hr

The AI-Application Security Engineer is responsible for implementing and scaling technical security ... Ability to effectively communicate technical topics to technical and non-technical audiences.

Application Security Engineer

Herndon, VA ยท On-site

$60.25 - $80.75/hr

They are seeking a highly skilled and innovative Application Security Engineer to define security strategies, lead threat modeling, and manage application vulnerabilities for the Army National Guard.

Application Security Engineer

San Francisco, CA ยท On-site

$69.25 - $92.50/hr

We're hiring an Application Security Engineer to own security across Opal's product and platform - and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly ...

next page

Showing results 1-20

Non Exempt Application Security Engineer information

See salary details

$29

$66

$96

How much do non exempt application security engineer jobs pay per hour?

As of Jun 8, 2026, the average hourly pay for non exempt application security engineer in the United States is $66.40, according to ZipRecruiter salary data. Most workers in this role earn between $56.49 and $75.48 per hour, depending on experience, location, and employer.

What is a Non Exempt Application Security Engineer?

A Non Exempt Application Security Engineer is a professional who focuses on identifying and addressing security vulnerabilities in software applications, but whose role is classified as 'non-exempt' under labor laws, meaning they are typically eligible for overtime pay. Their primary responsibilities include conducting security assessments, developing secure coding practices, and collaborating with development teams to ensure applications are built and maintained securely. They may use various tools to test for vulnerabilities and help implement security improvements throughout the software development lifecycle. The 'non-exempt' designation usually relates to hourly wage or overtime eligibility rather than the technical nature of their security work.

What are the key skills and qualifications needed to thrive as a Non Exempt Application Security Engineer, and why are they important?

To thrive as a Non Exempt Application Security Engineer, you need a solid background in software development, security best practices, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools like static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and certifications such as CEH or CISSP is common. Strong analytical thinking, attention to detail, and effective communication skills help you collaborate with development teams and articulate security risks. These skills are vital for identifying, mitigating, and preventing security vulnerabilities in software applications, ensuring the organization's data and assets remain protected.

How does a Non Exempt Application Security Engineer typically collaborate with development teams to ensure secure software delivery?

A Non Exempt Application Security Engineer works closely with development teams by conducting security reviews, providing guidance on secure coding practices, and participating in code and design reviews. They often help identify vulnerabilities early in the software development lifecycle and recommend remediation strategies. Regular communication and collaboration with developers, QA, and operations teams ensure that security is integrated throughout the process, making it a team effort to deliver secure applications.
What cities are hiring for Non Exempt Application Security Engineer jobs? Cities with the most Non Exempt Application Security Engineer job openings:
What states have the most Non Exempt Application Security Engineer jobs? States with the most job openings for Non Exempt Application Security Engineer jobs include:

Application Security Engineer

XceedSearch.com

Scottsdale, AZ โ€ข Hybrid

$59.25 - $79/hr

Full-time

Posted 25 days ago


Job description

Company Description

Insurance Company

Job Description

Company is seeking aย Lead Application Security Engineerย to play a critical dual role at the intersection of secure software development and handsโ€‘on engineering leadership. This position is ideal for a technologist who is passionate about building modern applicationsย andย ensuring they are secure by design.

In this role, you will embed application security expertise directly into the engineering organization. Approximately half of your focus will be on application security, identifying vulnerabilities, guiding remediation efforts, and providing meaningful security metrics and reporting. The other half will be spent leading and contributing to the design, development, and delivery of applications built withย Java and Angular.

The ideal candidate naturally bridges security and engineering, influencing architecture decisions, mentoring development teams, and championing best practices that balance strong security with scalability, performance, and delivery speed.

This position is based in our Scottsdale, AZ office. After completing an initial training period, the role offers a hybrid schedule with four days in the office and one remote day per week.

Responsibilities

Application Security

  • Conduct application security assessments and vulnerability scans using Veracode (SAST, DAST, and SCA) across Java, Spring Boot REST services, AngularJS, and Angular applications.
  • Analyze, prioritize, and track security findings through their full remediation lifecycle, ensuring timely resolution and appropriate escalation.
  • Hands-on remediate security vulnerabilities directly in Java, Spring Boot, AngularJS, and Angular codebases, while also guiding developers on secure coding practices and mitigation techniques specific to the Java and JavaScript ecosystem.
  • Review, assess, and implement REST API security controls hands-on, including coding authentication, authorization, input validation, and data protection solutions directly within Spring Boot services.
  • Produce clear, well-structured vulnerability reports and executive summaries for both technical teams and leadership.
  • Establish and maintain application security policies, standards, and guidelines aligned with OWASP and industry best practices.
  • Participate in Architecture Review Board discussions to identify and address security risks in proposed designs.
  • Evaluate AI-generated code from tools such as GitHub Copilot for security risks and guide developers on safe AI-assisted development practices.
  • Leverage AI-assisted security tooling to accelerate vulnerability detection, triage, and remediation workflows.
  • Support compliance and audit activities related to application security controls.

Lead Software Engineering

  • Take full ownership of team deliverables, ensuring quality, stability, and resilience of applications.
  • Establish and enforce coding standards and development practices for high-quality, secure software delivery.
  • Serve as the technical lead for major system components, guiding architecture and technical decisions while remaining an active, hands-on contributor to the codebase.
  • Actively design, write, review, and maintain code for scalable user interfaces and services, contributing directly to efficient, responsive applications built on Java, Spring Boot, Angular, and microservices architectures.
  • Understand data flows and system integrations to support solution design, and write code directly to facilitate defect resolution and system improvements.
  • Identify and resolve performance issues, defects, and system inefficiencies through direct, hands-on code contributions or delegating fixes to others as needed.
  • Act as the primary technical liaison with stakeholders, translating requirements into scalable solutions and managing expectations.
  • Foster a culture of accountability, security awareness, and continuous improvement through coaching and mentoring.

Qualifications

  • Bachelorโ€™s degree in Computer Science, Information Technology, or equivalent experience.
  • 5+ years of hands-on application security engineering experience, including vulnerability assessment and remediation.
  • 7+ years of software development experience with Java and Angular/AngularJS.
  • 3+ years of experience in a technical leadership or lead engineering capacity.
  • Proficient in: Java, Spring Boot, Spring Security, REST Web Services, Microservices, JavaScript, TypeScript, AngularJS, Angular, HTML, CSS, JUnit, Mockito, Git, Maven, and SQL.
  • Hands-on experience with enterprise application security scanning platforms such as Veracode, Checkmarx, Fortify, or similar tools, including SAST, DAST, and SCA scan configuration, results interpretation, and developer-facing remediation guidance.
  • Strong understanding of the OWASP Top 10 and how vulnerabilities manifest in enterprise Java and JavaScript applications.
  • Experience securing REST APIs, including OAuth2, JWT, and Spring Security implementations.
  • Demonstrated ability to produce clear vulnerability reports with severity ratings, impact assessments, and recommended mitigations for both technical and non-technical audiences.
  • Experience in project estimation, requirements gathering, system design, agile story creation, release support, and agile methodologies.
  • Preferred knowledge in: GitHub Copilot, AI-assisted security tooling, AWS, GCP, Drupal, Jasmine, Karma, IntelliJ, Eclipse, STS, WebStorm, Rancher, Jira, PL/SQL, Checkmarx, Fortify, or Burp Suite.
  • Security certifications such as CSSLP, CEH, GWAPT, or equivalent application security credentials are a plus.
  • Strong written and verbal communication skills with the ability to engage both development teams and IT leadership effectively.
  • Excellent analytical and problem-solving abilities with strong attention to detail.
  • Team-oriented, adaptable, and motivated to support both engineering excellence and organizational security goals.
Additional Information

All your information will be kept confidential according to EEO guidelines.

Thank You
Arnold Avila
Xceed Search
(480) 419-1311
http://www.xceedsearch.com