1

Non Exempt Application Security Engineer Jobs (NOW HIRING)

We are looking for an Application Security Engineer to work with our engineering team to ensure ... to technical and non-technical audiences. Experience leading training, speaking internally ...

What You'll Be Doing The AI-Application Security Engineer is responsible for implementing and ... Ability to effectively communicate technical topics to technical and non-technical audiences.

Application Security Engineer

Palo Alto, CA ยท On-site

$200K - $340K/yr

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven ... non-technical audiences PREFERRED SKILLS AND EXPERIENCE: * Experience with cloud platforms (e.g ...

Application Security Engineer

Phoenix, AZ

$58.25 - $78/hr

The Application Security Engineer is responsible for supporting the security and privacy of the SmartRent platform through the management of information security risk, system resilience, and ...

Application Security Engineer

Palo Alto, CA ยท On-site

$69.25 - $92.50/hr

... non-technical audiences Preferred : โ€ข Experience with cloud platforms (e.g., GCP, AWS, Azure) and their security features โ€ข Relevant security certifications (e.g., CSSLP, OSWE) โ€ข Background in ...

Application Security Engineer

OR ยท Remote

$58.75 - $78.50/hr

Application Security Engineer Location: Remote (United States) | Employment Type: Full-Time About the Role We are looking for an Application Security Engineer to join our product engineering team.

Application Security Engineer

Phoenix, AZ ยท On-site

$58.25 - $78/hr

The Application Security Engineer is responsible for supporting the security and privacy of the SmartRent platform through the management of information security risk, system resilience, and ...

Application Security Engineer

Washington, DC ยท On-site

$66.50 - $89/hr

Application Security Engineer Location: Washington, DC * Support PeopleSoft HCM/FSCM/ELM/CRM/EPM application security. * Implement specifically SSO for Oracle ELM, HCM and Finance PeopleSoft Modules ...

Application Security Engineer

Herndon, VA ยท On-site

$60.50 - $80.75/hr

The Application Security Engineer will be responsible for the end-to-end administration of Burp Suite and Veracode, managing Integrated Development Environment (IDE) plugins and ensuring all ...

Application Security Engineer

Herndon, VA

$60.50 - $80.75/hr

The Application Security Engineer will be responsible for the end-to-end administration of Burp Suite and Veracode, managing Integrated Development Environment (IDE) plugins and ensuring all ...

We are looking for an Application Security Engineer to partner with Engineering, Product, and ... Strong communication skills and ability to explain security tradeoffs to both technical and non ...

Application Security Engineer

Boulder, CO ยท On-site

$61 - $81.50/hr

SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense ... We are seeking an Application Security Engineer to help secure mission-critical software systems by ...

Application Security Engineer

Manhattan, NY ยท On-site

$64.75 - $86.50/hr

Application Security Engineer NYC / Charlotte NC- 3 Days Onsite W2 Position Overview: This role will be an integral component of the application security program end-to-end -- from discovery and ...

Define application security strategy, standards, and SDLC integration points; champion secure-by-design practices across engineering and DevSecOps teams. * Lead threat modeling and secure ...

Application Security Engineer

Boulder, CO

$61 - $81.50/hr

SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense ... We are seeking an Application Security Engineer to help secure mission-critical software systems by ...

Application Security Engineer

Boulder, CO ยท On-site

$61 - $81.50/hr

SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense ... We are seeking an Application Security Engineer to help secure mission-critical software systems by ...

next page

Showing results 1-20

Non Exempt Application Security Engineer information

See salary details

$29

$66

$96

How much do non exempt application security engineer jobs pay per hour?

As of Jun 8, 2026, the average hourly pay for non exempt application security engineer in the United States is $66.40, according to ZipRecruiter salary data. Most workers in this role earn between $56.49 and $75.48 per hour, depending on experience, location, and employer.

What is a Non Exempt Application Security Engineer?

A Non Exempt Application Security Engineer is a professional who focuses on identifying and addressing security vulnerabilities in software applications, but whose role is classified as 'non-exempt' under labor laws, meaning they are typically eligible for overtime pay. Their primary responsibilities include conducting security assessments, developing secure coding practices, and collaborating with development teams to ensure applications are built and maintained securely. They may use various tools to test for vulnerabilities and help implement security improvements throughout the software development lifecycle. The 'non-exempt' designation usually relates to hourly wage or overtime eligibility rather than the technical nature of their security work.

What are the key skills and qualifications needed to thrive as a Non Exempt Application Security Engineer, and why are they important?

To thrive as a Non Exempt Application Security Engineer, you need a solid background in software development, security best practices, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools like static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and certifications such as CEH or CISSP is common. Strong analytical thinking, attention to detail, and effective communication skills help you collaborate with development teams and articulate security risks. These skills are vital for identifying, mitigating, and preventing security vulnerabilities in software applications, ensuring the organization's data and assets remain protected.

How does a Non Exempt Application Security Engineer typically collaborate with development teams to ensure secure software delivery?

A Non Exempt Application Security Engineer works closely with development teams by conducting security reviews, providing guidance on secure coding practices, and participating in code and design reviews. They often help identify vulnerabilities early in the software development lifecycle and recommend remediation strategies. Regular communication and collaboration with developers, QA, and operations teams ensure that security is integrated throughout the process, making it a team effort to deliver secure applications.
What cities are hiring for Non Exempt Application Security Engineer jobs? Cities with the most Non Exempt Application Security Engineer job openings:
What states have the most Non Exempt Application Security Engineer jobs? States with the most job openings for Non Exempt Application Security Engineer jobs include:
Application Security Engineer

Application Security Engineer

Heartflow

San Francisco, CA โ€ข Hybrid

$145K - $180K/yr

Other

Posted 3 days ago


Job description

We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC). In this role, you'll have the chance to use your security and software development background to protect patients as we build products that leverage AI to improve healthcare. If you enjoy working with talented engineers to solve complex technical challenges and want to see your work make a direct difference in patient outcomes, we encourage you to apply. This role is a hybrid, requiring three days a week in our San Francisco office.

What You'll Do:

  • Partner with the engineering team to provide hands-on technical guidance to software developers throughout the vulnerability remediation lifecycle. Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
  • Drive vulnerability identification using SAST, DAST, SCA and in-house AI tooling and manage external penetration testing.
  • Support engineering team on vulnerability management, including risk assessment, remediation, improving identification of vulnerabilities and translate security and privacy requirements into technical requirements.
  • Build security awareness through training on secure coding practices, security standards and latest security threats.

What You Bring:

  • Security Communication - Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences. Experience leading training, speaking internally/externally about security projects valued.
  • Programming Skills ย - Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python). Comfortable with testing frameworks and CI/CD pipelines.
  • AI Development Tools - Experience using AI code tools such as Claude Code and Github Copilot for development and security testing.
  • Education & Experienceย  - BS in Computer Science (or related degree) or relevant certifications and equivalent experience. 5+ years of total experience with at least 1 year working in Application Security or performing security tasks in a development role.
  • Securing SDLC - Have contributed to secure SDLC activities, including threat modeling, code review, security testing and vulnerability management.
  • Knowledge of Modern AI Security Threats - Experience working with or ability to discuss current AI threats for both machine learning and generative AI.

What Helps You Stand Out:

  • Healthcare Experience - Current knowledge of HIPAA, HITRUST and the complexities of working in a regulated environment. Experience with Software as a Medical Device (SaMD) is especially valuable.
  • Infrastructure as Code & Cloud -ย Familiarity with AWS (or equivalent cloud providers) and configuration tools (Terraform, Chef, Ansible). Experience with containerization (Docker, Kubernetes) and orchestration (GitHub Actions or similar).

A reasonable estimate of the base salary compensation range is $145,000 to $180,000 per year, bonus, and equity. #LI-IB1