1

Web Application Security Engineer Jobs in California

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud ...

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud ...

Application Security Engineer

Palo Alto, CA · On-site

$69.25 - $92.50/hr

They are seeking an innovative Application Security Engineer responsible for ensuring the security and integrity of cloud-native applications throughout the software development lifecycle, with a ...

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud ...

Become a key player in our Information Security team as a Senior Application Security Engineer, where you will leverage your expertise in application security, security engineering, and software ...

Senior Application Security Engineer

Irvine, CA · On-site

$63 - $84.25/hr

Become a key player in our Information Security team as a Senior Application Security Engineer, where you will leverage your expertise in application security, security engineering, and software ...

We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC). In this role, you'll have ...

Staff Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

The Staff Application Security Engineer will partner with the Engineering, DevOps, Product, and ... Hands-on experience with web technologies such as Java, Java Spring Boot, JavaScript, Node.js, C# ...

Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

* Partner with the engineering team to provide hands-on technical guidance to software developers ... Application Security * Vulnerability Remediation * Threat Modeling * Security Standards * AI ...

We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC). In this role, you'll have ...

Senior Security Engineer

Los Angeles, CA

$123K - $169K/yr

Position Summary We are seeking a hands-on Application Security Engineer to join our Security ... Own and execute internal security testing requests (tickets), including web/mobile application ...

Showing results 21-40

Web Application Security Engineer information

See California salary details

$29

$65

$95

How much do web application security engineer jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for web application security engineer in California is $65.53, according to ZipRecruiter salary data. Most workers in this role earn between $55.77 and $74.47 per hour, depending on experience, location, and employer.

What is a web application security engineer?

A Web Application Security Engineer is a specialist responsible for protecting web applications from security threats and vulnerabilities. They analyze code, perform security testing, and implement measures to safeguard applications against attacks like SQL injection, cross-site scripting (XSS), and data breaches. Their work involves collaborating with developers to design secure systems, monitoring for security incidents, and staying updated on the latest cybersecurity trends and threats. Ultimately, they help ensure the confidentiality, integrity, and availability of web-based applications.

How does a web application security engineer typically collaborate with development teams to ensure secure coding practices?

Web Application Security Engineers work closely with software developers throughout the software development lifecycle, often participating in design reviews, code audits, and threat modeling sessions. They provide guidance on secure coding standards, identify potential vulnerabilities early, and recommend remediation strategies. Regular communication and knowledge sharing, such as conducting security training or workshops, help foster a security-first mindset across the team. This collaborative approach ensures that security is integrated from the outset rather than added as an afterthought.

What are the key skills and qualifications needed to thrive as a web application security engineer, and why are they important?

To thrive as a Web Application Security Engineer, you need a solid understanding of web technologies, application vulnerabilities (such as OWASP Top 10), and a background in computer science or cybersecurity. Familiarity with security testing tools like Burp Suite, Nessus, and proficiency in secure coding practices or relevant certifications such as CEH or OSCP are typically required. Outstanding problem-solving skills, attention to detail, and effective communication help in identifying, mitigating, and explaining security risks. These skills and qualities are essential to protect applications from cyber threats and ensure the integrity and confidentiality of sensitive data.

What cities in California are hiring for Web Application Security Engineer jobs?

Cities in California with the most Web Application Security Engineer job openings:

Infographic showing various Web Application Security Engineer job openings in California as of August 2026, with employment types broken down into 73% Full Time, 21% Part Time, and 6% Contract. Highlights an 89% Physical, 3% Hybrid, and 8% Remote job distribution, with an average salary of $136,308 per year, or $65.5 per hour.

Azure Web Application Firewall & Cyber Security Tools Engineer

Sacramento, CA • On-site

JS Consulting
Custom Software Development Services • 1 - 10 employees

Contractor

Re-posted 9 days ago


Job description

Job Title- Azure Web Application Firewall & Cyber Security Tools Engineer

Project Location – Remote

Duration- 12+ months contract

Visa- USC/ GC/ GCEAD/ H1B

Job Description-: Need candidates with below exp.

70% Azure Web Application Firewall expert.

·    IaaC – Terraform experience needed. Should be able to configure the firewall with Terraform.

Need very senior profile. 

Key Responsibilities

Azure WAF Operations

  • Administer and maintain Azure Front Door WAF and Azure Application Gateway WAF policies, rulesets, exclusions, and custom signatures to protect web applications against OWASP Top 10 and emerging threats.
  • Coordinate with application teams to design protection profiles per app and/or per path, align rules with business requirements, and ensure safe rollouts.
  • Monitor WAF efficacy, coverage, and performance; analyze events and false positives; tune policies to reduce friction while maintaining strong protection.

Automation, Deployments & Configuration-as-Code

  • Build and maintain Terraform modules for Azure Front Door and Application Gateway WAF resources, ensuring version-controlled deployments.
  • Operate CI/CD pipelines for GitHub-based deployments, including branching strategies, environment promotion, and rollback procedures.
  • Use Terraform code to define, validate, and deploy WAF configurations.

Stakeholder Support & Incident Response

  • Respond to WAF-related tickets and inquiries using established TSSO processes; assist teams in interpreting WAF logs, diagnosing blocks, and resolving configuration challenges.
  • Provide clear guidance during incidents/outages, including rapid policy tuning, targeted rule adjustments, and coordination with application owners and Infrastructure & Operations.
  • Document operational standards, deployment runbooks, troubleshooting guides, and best practices.

Security Tools Support

  • Provide operational support for additional security tools, including Proofpoint, Digital Guardian, Windows Certificate Services, Silverfort, Calico, F5 ASM, Rapid7 Nexpose, and Qualys.
  • Assist in troubleshooting, performance tuning, and implementing updates or enhancements across supported platforms.

Required Skills & Experience

  • Hands-on administration of Azure Front Door WAF and Azure Application Gateway WAF (policy authoring, tuning, exclusions, custom rules).
  • Terraform expertise for Azure resources and GitHub deployments.
  • Proven ability to use code to configure Azure firewalls/WAFs.
  • Scripting skills to automate configuration, validations, and operational tasks (PowerShell, Bash, or Python).
  • Strong understanding of web application security (OWASP Top 10, bot protection, API protection, TLS, header-based controls) and secure DevOps practices.

Desired Skills

  • Experience with F5 ASM Web application Firewall and ASM policy tuning.
  • Exposure to Calico, Proofpoint email security, Netskope, Digital Guardian, Silverfort, and vulnerability management tools.
  • PKI fundamentals and certificate lifecycle management (Windows Certificate Services, CA hierarchies).
  • Agile delivery experience (scrum/kanban, backlog grooming, story writing).
  • Practical DevSecOps experience integrating security controls into CI/CD, policy-as-code, and automated testing.

Qualifications

  • 5+ years in application security, cloud security, or network security engineering roles.
  • Demonstrated success operating Azure WAF(Azure Front Door and/or Application Gateway).
  • Track record of building infrastructure-as-code for security controls and running Git-based deployment pipelines.
  • Excellent documentation, communication, and stakeholder collaboration skills.
  • Ability to manage shifting priorities and deliver secure, reliable outcomes in a dynamic environment.