1

Web Application Security Engineer Jobs in California

Sr. Application Security Engineer

Redlands, CA · On-site

$59 - $79/hr

Solid understanding of common web application security standards (HTTP, OAuth, OIDC, REST, and more ... with developers to resolve them * Understanding of layer 2-7 communication protocols, common ...

Sr. Application Security Engineer

Redlands, CA · On-site

$59 - $79/hr

... common web application security standards (HTTP, OAuth, OIDC, REST, and more) • Experience ... with developers to resolve them • Understanding of layer 2-7 communication protocols, common ...

Application Security Engineer

Torrance, CA · On-site

$61.25 - $82/hr

Strong knowledge of secure development practices Deep knowledge of common web application vulnerabilities (e.g. XSS, CSRF, clickjacking) and their mitigation strategies Knowledge of system security ...

Application Security Engineer

Sunnyvale, CA · On-site

$70 - $93.50/hr

Understand common vulnerability classes and exploitation techniques across web applications, APIs ... Application Security or Security engineering background. * Securing AI/ML platforms, inference ...

New

Application Security Engineer

Sunnyvale, CA · On-site

$69 - $92.25/hr

Understand common vulnerability classes and exploitation techniques across web applications, APIs ... Application Security or Security engineering background. * Securing AI/ML platforms, inference ...

Solid foundation in web security, mobile security, or cryptography * Ability to collaborate with ... Engineering, Information Systems, or equivalent years of experience in a related technical field ...

Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

Zof AI is seeking an Application Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent ...

Sr. Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

... Application Security with 5-7 years of security experience. Experience with any of the following ... NET, J2EE, Zend Web Server configuration knowledge: Microsoft IIS, Apache HTTP Server, Apache ...

Solid foundation in web security, mobile security, or cryptography * Ability to collaborate with ... Engineering, Information Systems, or equivalent years of experience in a related technical field ...

Solid understanding of common web application security standards (HTTP, OAuth, OIDC, REST, and more ... with developers to resolve them * Understanding of layer 2-7 communication protocols, common ...

Security Engineer, Application Security

San Jose, CA · On-site

$68.75 - $92/hr

... web security, mobile security, or cryptography • Ability to collaborate with internal and ... Engineering, Information Systems, or equivalent years of experience in a related technical field ...

Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

We're hiring an Application Security Engineer to own security across Opal's product and platform - and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly ...

next page

Showing results 1-20

Web Application Security Engineer information

See California salary details

$29

$65

$95

How much do web application security engineer jobs pay per hour?

As of Sep 10, 2026, the average hourly pay for web application security engineer in California is $65.53, according to ZipRecruiter salary data. Most workers in this role earn between $55.77 and $74.47 per hour, depending on experience, location, and employer.

What is a web application security engineer?

A Web Application Security Engineer is a specialist responsible for protecting web applications from security threats and vulnerabilities. They analyze code, perform security testing, and implement measures to safeguard applications against attacks like SQL injection, cross-site scripting (XSS), and data breaches. Their work involves collaborating with developers to design secure systems, monitoring for security incidents, and staying updated on the latest cybersecurity trends and threats. Ultimately, they help ensure the confidentiality, integrity, and availability of web-based applications.

How does a web application security engineer typically collaborate with development teams to ensure secure coding practices?

Web Application Security Engineers work closely with software developers throughout the software development lifecycle, often participating in design reviews, code audits, and threat modeling sessions. They provide guidance on secure coding standards, identify potential vulnerabilities early, and recommend remediation strategies. Regular communication and knowledge sharing, such as conducting security training or workshops, help foster a security-first mindset across the team. This collaborative approach ensures that security is integrated from the outset rather than added as an afterthought.

What are the key skills and qualifications needed to thrive as a web application security engineer, and why are they important?

To thrive as a Web Application Security Engineer, you need a solid understanding of web technologies, application vulnerabilities (such as OWASP Top 10), and a background in computer science or cybersecurity. Familiarity with security testing tools like Burp Suite, Nessus, and proficiency in secure coding practices or relevant certifications such as CEH or OSCP are typically required. Outstanding problem-solving skills, attention to detail, and effective communication help in identifying, mitigating, and explaining security risks. These skills and qualities are essential to protect applications from cyber threats and ensure the integrity and confidentiality of sensitive data.

What cities in California are hiring for Web Application Security Engineer jobs?

Cities in California with the most Web Application Security Engineer job openings:

Infographic showing various Web Application Security Engineer job openings in California as of August 2026, with employment types broken down into 73% Full Time, 21% Part Time, and 6% Contract. Highlights an 89% Physical, 3% Hybrid, and 8% Remote job distribution, with an average salary of $136,308 per year, or $65.5 per hour.

Cloud & Application Security Engineer

Burbank, CA • On-site

$130K - $155K/yr

Full-time

Posted 15 days ago


Job description

Who are we hiring?   

The Cloud & Application Security Engineer will design, implement, validate, and operate security controls across our cloud infrastructure, applications, and software delivery pipelines. This role will partner with DevOps, various Engineering, and Security teams to build secure-by-default platforms that enable developers while reducing organizational risk. 

This is a hands-on role requiring strong experience in cloud security architecture, application security testing, CI/CD pipeline hardening, and infrastructure-as-code security. 

 What will you do? 

  • Design, implement, and mature secure cloud architectures across AWS, Azure, and GCP, with a primary focus on GCP. 
  • Develop, audit, and harden cloud infrastructure, including IAM, networking, organization policies, logging, and Terraform-based Infrastructure-as-Code. 
  • Provide security architecture reviews and guidance for cloud applications, APIs, infrastructure, DevOps, and AI-assisted development. 
  • Perform application security assessments, secure code reviews, and hands-on testing of web applications, APIs, and cloud services using automated and manual techniques to identify vulnerabilities and drive remediation. 
  • Identify, prioritize, and remediate cloud and application vulnerabilities, including critical and zero-day threats. 
  • Lead evaluations, proof-of-concepts, and implementation of cloud and application security technologies. 
  • Secure AI platforms and AI-assisted development by implementing appropriate security controls and reviewing AI-assisted applications for security risks. 
  • Partner with Security Operations to improve cloud detection, monitoring, incident response, and security visibility. 
  • Provide exceptional experiences for our guests, partners, and team members, including by adhering to our appearance and presentation guidelines while on-site.  

What do you need to succeed?  

  • 4-6 years of related experience. 
  • Bachelor's degree, or equivalent combination of education and experience.  
  • Experience securing enterprise cloud environments across AWS, Azure, and/or GCP, including Kubernetes. 
  • Strong understanding of cloud architecture, IAM, networking, cloud security controls, and Infrastructure-as-Code. 
  • Experience integrating security into CI/CD pipelines using Terraform and modern DevOps platforms. 
  • Proficiency in Python, PowerShell, Bash, Go, or a similar language, or demonstrated ability to leverage AI-assisted engineering tools to develop automation and security solutions. 
  • Hands-on experience with Wiz or a comparable CSPM/CNAPP platform. 
  • Experience with application security, including secure SDLC, threat modeling, secure code reviews, SAST, DAST, SCA, secret scanning, vulnerability management, remediation, and web application security testing. 
  • Strong understanding of web application security, REST APIs, authentication (OAuth/OIDC/JWT), and OWASP Top 10. 
  • Familiarity with AI security concepts and securing enterprise AI platforms or AI-assisted applications. 
  • Security certifications (e.g., CISSP, CCSP, AWS Security Specialty, Google Professional Cloud Security Engineer, AZ-500, CSSLP, or GWAPT) are a plus. 
Pay Range (Burbank):  $130,000-$155,000
Pay Range (Las Vegas):  $120,000-$140,000

#LI-Onsite