Application Security Engineer
$231.9k - $318.25kRetool Inc.
About Retool Nearly every company in the world runs on custom software for critical operations like tracking performance metrics, handling customer support workflows, building admin dashboards, and countless other processes you might not have even thought of. But most companies don’t have adequate resources to properly invest in these tools, leading to a lot of old and clunky internal software or, even worse, users still stuck in manual and spreadsheet flows. At Retool, we’re building the first enterprise AppGen platform: software that transforms natural language into production‑ready code, integrates directly with business data, and meets the highest standards of security and governance. AI is redefining what it means to build software—and who gets to build it. The definition of “developer” now includes analysts, operators, and domain experts creating solutions directly. As the pool of builders widens, so does the complexity of what they need to build. The opportunity is enormous, but so is the challenge of enabling this larger community to build production‑grade software safely. That means AI that understands real business data, enforces enterprise policies automatically, and empowers teams to create once and reuse everywhere with shared, trusted components. Over 100 million hours of work has been automated by developers and domain experts using our platform, freeing them to focus on creative problem‑solving and strategic initiatives that drive real business value. The people closest to knowing what needs to be built can now safely create custom solutions within enterprise guardrails. And that’s a mission worth striving for. Let’s build the future together! Why We’re Looking For You Retool handles our customers’ most sensitive data and provides a platform where they write and execute arbitrary code. The security surface that comes with that is large, nuanced, and genuinely interesting. As the platform grows and our customers’ trust in it deepens, the scope and ambition of our security program have grown with it. We’re looking for an Application Security Engineer who combines deep security fundamentals with real engineering execution. This is not a role for someone who audits from a distance or advises without getting their hands dirty. You’ll be in the code, spotting systemic patterns, and building the tooling and solutions that address them at scale. You’ll recognize when a one‑off fix isn’t enough, synthesize what you’re seeing in the codebase, and work with engineering teams to make secure outcomes the default rather than the exception. You’ll need to understand the product deeply to secure it well: what customers build on Retool, where code executes, and how data flows. The security problems worth solving here live at the intersection of platform capability and customer trust, and your first team is the business, not just security. We’re also actively thinking about what AI‑accelerated development means for application security, from how to use AI to enhance and scale our own security work to managing the risk that comes with developers shipping more code, faster, with different review patterns than ever before. We’re already running experiments in this space, including using AI to find and fix vulnerabilities at scale, automating dependency management, and rethinking what security teams can actually accomplish with the right tooling and ambition. If you want to work out what AI genuinely changes about security engineering practice— in real conditions, not in theory— this role is for you. In This Role, You Will Identify systemic security gaps in our codebase and engineering workflows, and work with engineering teams to design and ship durable solutions; you’ll drive solutions, not just surface problems Build security tooling, automation, and code‑level controls that address classes of vulnerabilities, including custom linters, static analysis rules, and automated checks, shifting the cost of catching issues left rather than handling them one at a time or after they’ve reached production Conduct in‑depth code reviews and security design reviews for significant product initiatives, with the technical depth to engage meaningfully with architectural tradeoffs rather than just flag issues for others to resolve Drive threat modeling and security assessments for new features, and translate security requirements into practical engineering guidance that developers can actually act on Contribute to the team’s evolving approach to security as AI‑assisted development scales internally, including how faster and higher‑volume code production changes how we find, prioritize, and fix risks Triage, track, and drive remediation of vulnerabilities with product engineering teams, and contribute to our penetration testing and bug bounty programs The Skillset You’ll Bring 5+ years of hands‑on experience in application security and security engineering: you’ve built things, not only assessed them, and your background is not mainly consulting, audit, or compliance work The ability to operate independently with good judgment in a fast‑moving environment: you prioritize well by understanding the needs of the business and our shared objectives, make calls with incomplete information, and know when to move fast versus when to slow down and get it right, or elevate and ask for help Communication that earns trust: you can make security legible to engineers without being preachy, and you measure your impact by how well you’ve supported the business, not by how many issues you catalogued A track record of shipping security tooling or automation that improved things for more than one team Genuine engineering depth: you can read, reason about, and review code at the level needed to find real bugs and understand their root causes, not just pattern‑match to a checklist Comfort working in TypeScript and Python: Retool’s platform is built in TypeScript and our security tooling leans on Python, you’ll need to be productive in both and not just conversant Strong AppSec fundamentals: threat modeling, secure code review, a working understanding of common vulnerability classes and, importantly, how to address them durably rather than symptomatically A pragmatic, signal‑oriented relationship with AI tooling: you reach for it where it genuinely sharpens your work, you’re skeptical where it doesn’t, and you’re thinking about what developer‑side AI adoption means for how security risk compounds at scale Nice To Have Offensive security experience like bug bounty, CTF participation, red‑team, or pentesting work Experience building or contributing to SAST pipelines, custom static analysis rules, or automated security testing infrastructure Prior experience at a startup or high‑growth scale‑up, where security programs aren’t fully pre‑defined and priorities shift Compensation and Benefits For candidates based in the United States, the pay range for this role is $231,900 – $318,250 per year. The base range may be narrowed during the interview process based on scope, responsibilities, experience, and location. Additional compensation in equity and/or commission is dependent on the position offered. Retool provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay and benefits are subject to change at any time. Retool offers generous benefits to all employees and hybrid work location. For more information, please visit the benefits and perks section of our careers page! Retool is currently set up to employ all roles in the US and specific roles in the UK. To find roles that can be employed in the UK, please refer to our careers page and review the indicated locations. #J-18808-Ljbffr Retool Inc.
$160k - $220k
...driving incredible value for our customers. Join us! The Security team at Zip is responsible for protecting the confidentiality and integrity of our customers’ data. As our first Application Security Engineer, you will take on a dynamic and high impact role. You will...SuggestedHome officeFlexible hours- ...Senior Security Engineer – Secure Code Review San Francisco, California On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software...SuggestedFull time
$165k - $225k
...Senior Application Security Engineer Denver, CO or Long Beach, CA or SF Bay Area, CA Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it. True Anomaly delivers decisive capabilities for space...SuggestedShift work$170k - $190k
...collaboration and connection. There may be additional in-office days for team or company events. Ironclad is seeking a skilled Application Security Engineer with a passion for securing modern software platforms and protecting sensitive data. We are looking for someone with...SuggestedFull timeContract workWork at office$237.8k
...their data and AI are fully understood, secured, and resilient to enable the acceleration... ...We are looking for a Senior Security Engineer who thinks like a product architect and... ...processing. By submitting your application, you confirm that the information provided...SuggestedBase plus commissionLocal areaWorldwideShift work- ...Find out more about our hiring culture: Dream Team Culture Job Description At ZetaChain, we are seeking a dedicated Protocol Security Engineer to play a pivotal role in fortifying the security of our cutting-edge protocol. You will be deeply involved in the development...Remote jobContract workHome office
- A leading procurement technology firm in San Francisco is seeking its first Application Security Engineer to build security guardrails and enhance product security across their platforms. The successful candidate will lead security initiatives, collaborate on product launches...
$200k - $245k
...founding in 2013, we have focused on enabling our clients to securely navigate the digital asset space. With a global presence... ...and innovative problem-solving. We are seeking a Senior Application Security Engineer to lead the technical execution of our product security...Full timeWork at officeWorldwide- ...within a Vulnerability Management Program that understands Application Security with 5-7 years of security experience. Experience with any... ...code review experience using automated toolsets Software Engineering career experience Following Certifications: CISSP, CEH, GWAPT...
- Opal Security is looking for an Application Security Engineer to take charge of security across its product and platform. You will work closely with engineers to integrate security into the design and development process, ensuring that the systems are robust and secure...
- ...and catch regressions — turning production data into better AI with every release. About the role We're looking for an Application Security Engineer who lives in the code. Braintrust is a real-time, high-availability data platform that runs in both SaaS and self-hosted...Flexible hours
- About Opal Security: At Opal, we’re building modern identity governance for the AI era—... ...down innovation. The Role: Most security engineers spend their careers bolting locks onto... ...This is not that job. We're hiring an Application Security Engineer to own security...
- We are seeking a Sr. Application Security or DevSecOps Engineer with broad set of experiences to have an early and formative impact in many areas of the ZetaChain security program. The ideal candidate will be responsible for ensuring the security of our applications throughout...Remote jobContract workFlexible hours
- A leading software company in San Francisco is looking for an Application Security Engineer. This hybrid role requires strong experience in automated vulnerability scanning and penetration testing. Responsibilities include developing secure coding practices, conducting...
$170k - $190k
A leading software security company is hiring an Application Security Engineer in San Francisco. This hybrid role involves conducting security assessments, implementing best practices, and addressing vulnerabilities in the software. Candidates should have a BA/BS in Computer...$325k - $405k
A leading AI research firm in San Francisco is seeking a Security Engineer for Application Security. The role involves identifying and mitigating security vulnerabilities, conducting assessments, and developing security tools. Ideal candidates will have extensive experience...Remote job- Retool Inc. in San Francisco is seeking an Application Security Engineer to enhance our security posture by identifying and addressing systemic security gaps in our codebase. This role is crucial as you will work closely with engineering teams to ensure secure practices...
$230k - $255k
...Full time Location Type Hybrid Department Security About Us: Notion helps you build... ...path forward to the future. The Notion application is flexible, powerful and always evolving... ...customers. Notion is looking for security engineers that have a passion for making it as...Full timeWork at officeLocal areaRemote workFlexible hours- Braintrust, based in San Francisco, is seeking an Application Security Engineer to ensure security in their high-availability data platform. This role involves reviewing code, leading security initiatives related to AI models, and managing vulnerabilities. The ideal candidate...Flexible hours
- ...including Patrick Collison and Andrej Karpathy. We are building AI applications for the world's most important institutions, delivering... ..., NVIDIA, and Databricks About the Role As our Security Engineer, Application & AI, you will own the security of our products...Contract work
- A mission-driven software company in San Francisco seeks a Principal Security Engineer to enhance security measures in their applications. The role includes conducting assessments, responding to incidents, and improving security architecture while maintaining a collaborative...
$160k - $220k
A leading procurement platform company in San Francisco is looking for an Application Security Engineer to join their team. This role involves designing and implementing security measures, mentoring staff, and ensuring the security of the company's products. The ideal candidate...Flexible hours- ...scientists, PhDs, creatives, technologists, and engineers working together to empower people and... ...The Role Want to work on building out security from the ground up at the leading edge... ...and highly motivated Senior or Staff Application Security Engineer to join our team as...Hourly payFull timeFlexible hours
$225k - $400k
...Pinterest, Canva, and CDW. We grew 6x in 2025 and are continuing to scale fast. The Role We're hiring our first dedicated Lead Application Security Engineer to own the security of the Ivo platform end to end. You'll partner directly with our Head of IT & Security and embed...Contract workWork at officeVisa sponsorshipRelocation package- Ivo Inc. in San Francisco is seeking a Lead Application Security Engineer to own the security of its platform, ensuring the protection of sensitive contracts for enterprise clients. This hands-on role involves vulnerability testing, threat modeling, and mentoring engineering...Work at office
$160k - $215k
We are seeking a highly skilled and experienced individual to join our Security & Privacy team at SPAN as a Staff Application Security Engineer. Responsibilities Lead and execute application security assessments, including static application security testing (SAST),...Work at officeFlexible hours$230k - $255k
A leading software company located in San Francisco is actively seeking an experienced Application Security Engineer. In this role, you will define the direction of the application security program and support product teams in mitigating vulnerabilities. The ideal candidate...- A leading AI development company in New York seeks an experienced Application Security Engineer. You will own the application security domain, embedding security in the development lifecycle, integrating tools into CI/CD, and managing vulnerabilities. The ideal candidate...
$176k - $220k
Location San Francisco, CA Employment Type Full time Department Engineering Compensation $176K - $220K For cash compensation, we set... ..., and may vary from the amounts listed above. Senior Application Security Engineer At Handshake, we believe security should be built...Full timeWork at officeLocal areaRemote workFlexible hours- ...performance, and low-ego team members to join us on our exciting journey towards that vision. As Binti's first Principal Security Engineer (Applications focused), reporting to our CTO, you will play a critical role in ensuring the security and integrity of our software...Work at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!
- application system engineer San Francisco, CA
- junior application support engineer San Francisco, CA
- hydraulic application engineer San Francisco, CA
- senior application security engineer San Francisco, CA
- application performance engineer San Francisco, CA
- application engineer San Francisco, CA
- application engineering manager San Francisco, CA
- network applications engineer San Francisco, CA
- cnc applications engineer San Francisco, CA
- field applications engineer San Francisco, CA



