Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Application Security Engineer

$20k

ServiceTitan

Ready to be a Titan?

At ServiceTitan, we are transforming product security into a core part of how engineering delivers software. We are looking for an exceptional Staff Application Security Engineer to help us build a "Secure Paved Road"-an automated, self-service ecosystem that enables our 80+ R&D squads to build securely by default.

This role will define and scale how secure software is built at ServiceTitan by embedding security directly into the development lifecycle, from code to production. It will reduce organizational risk by automating detection and remediation of vulnerabilities, standardizing secure architecture patterns, and eliminating entire classes of security issues at their source. By partnering closely with engineering, this role will drive a shift toward secure by default development while continuously validating defenses through testing, threat modeling, and proactive simulation.

What you'll do:
Build the Secure Paved Road (Pipeline and Code)
  • Pipeline Automation: Deeply integrate GitHub Advanced Security into the CI/CD pipeline to act as automated checkpoints, providing fast feedback to engineers without manual intervention.
  • Secure by Default Code: Collaborate with Engineering to develop and maintain secure microservice templates and libraries with embedded security controls.
  • Secrets and Supply Chain: Lead hardcoded secrets mitigation efforts by automating detection and building workflows to validate compromised credentials via API.
  • Secure SDLC Practices: Drive cross functional initiatives to establish and continuously improve secure software development lifecycle practices across the organization.
Continuous Security Testing and Validation
  • Penetration Testing: Lead onboarding and operation of continuous penetration testing capabilities across web applications and services.
  • Security Assessments: Participate in and help scale internal security assessments, penetration testing, and bug bounty programs.
  • Tooling Ownership: Evaluate, prototype, implement, and operate security tools including DAST, SAST, and SCA.
  • Simulation and Validation: Run proactive simulations based on emerging threats to validate defenses and identify gaps.
Architecture and Threat Modeling
  • Security Design Reviews: Lead security design reviews and threat modeling for new and existing services.
  • Secure Architecture: Develop and maintain secure architecture standards, frameworks, and reusable patterns across multiple layers of the stack.
  • Emerging Threat Analysis: Continuously analyze evolving security threats, determine relevance, and implement centralized mitigations.
Operational Support and Engineering Partnership
  • Technical Leadership: Act as the AppSec technical expert for the Security Champions Program, guiding engineers on vulnerability remediation and secure coding practices.
  • Contextual Training: Implement just in time training mechanisms that help engineers remediate vulnerabilities as they are introduced.
  • Triage to Automate: Own initial triage of vulnerability findings, identify patterns, and drive automation and guardrails to reduce recurring issues.
  • Incident Response: Participate in security incident response and support post incident analysis and remediation efforts.
Continuous Improvement and Expertise
  • Maintain strong knowledge of current security threats, vulnerabilities, and operational best practices, applying that knowledge to continuously improve the organization's security posture.
What you'll bring:
  • Experience: 7-10+ years of experience in Product/Application Security, with a strong background in software engineering.
  • Coding Expertise: Proficiency in C#/.NET (preferred) or Go/Java. You must be able to read code to find vulnerabilities and write code to fix them.
  • Modern AppSec: Experience moving security "left" using tools like GitHub Advanced Security (GHAS), dependency scanners, and secret detectors.
  • Automation Mindset: Proven ability to script (Python, Go, PowerShell) and automate security tasks. You prefer building a tool to solve a problem over fixing it manually.
  • AI Forward: Interest in the intersection of AI and Security, specifically in securing AI workloads, leveraging AI capabilities to embed security throughout the SDLC, and using AI agents for defense.
Why this role?

Own Outcomes, Not Activity: Your success will be measured by real risk reduction. You will directly influence vulnerability backlog reduction, remediation velocity, and the overall security posture of the organization.

Operate at the Intersection of Engineering and Security: You will work side by side with engineering teams to shape how software is built, secured, and deployed. This role gives you the platform to influence architecture, development practices, and platform level controls.

Lead the Next Evolution of AppSec: You will help define how modern security teams leverage automation and intelligent systems to scale. From secure by design patterns to autonomous testing and remediation, you will be pushing the boundaries of how security is done.

High Ownership, High Leverage: You will have the autonomy to identify problems, design solutions, and implement them end to end. The work you do will scale across teams and services, amplifying your impact well beyond a single application or domain.

Be Human With Us:
Being human isn't about checking every box on a list. It's about the experiences we have, people we meet, and the perspectives we share. So, if you have the skills but are hesitant to apply because of your background, apply anyway. We need amazing people like you to help us challenge the conventional and think differently about the problems that we're solving. We're in this together. Come be human, with us.


Use of AI Technology:

We use technology, including automated and AI-assisted tools, to support certain aspects of our recruitment process. These tools are designed to improve efficiency and enhance the candidate experience. AI tools are not used to make hiring decisions; all hiring decisions are made by our hiring teams.

What We Offer:

When you join our team, you're not just accepting a job. You're making a career move. Here's how we'll support you in doing some of the most impactful work of your career:
  • Flextime, recognition, and support for autonomous work : Flexible time off with ample learning and development opportunities to continue growing your career. We offer a comprehensive onboarding program, leadership training for Titans at all levels, and other programs and events. Great work is rewarded through Bonusly, peer-nominated awards, and more.
  • Holistic health and wellness benefits: Company-paid medical, dental, and vision (with 100% employer paid options and 90% coverage for dependents), FSA and HSA, 401k match, and telehealth options including memberships to One Medical.
  • Support for Titans at all stages of life: Parental leave and support, up to $20k in fertility services (i.e. IUI and IVF), surrogacy, and adoption reimbursement, on demand maternity support through Maven Maternity, free breast milk shipping through Maven Milk, pet insurance, legal advisory services, financial planning tools, and more.

At ServiceTitan, we celebrate individuality and uniqueness. We believe that the convergence of fresh perspectives and experiences from all walks of life is what makes our product and culture so great. We strongly encourage people from underrepresented groups to apply. We do not discriminate against employees based on race, color, religion, sex, national origin, gender identity or expression, age, disability, pregnancy (including childbirth, breastfeeding, or related medical condition), genetic information, protected military or veteran status, sexual orientation, or any other characteristic protected by applicable federal, state or local laws.
ServiceTitan is committed to fair and equitable compensation for all of our employees. We thoughtfully consider a wide range of factors when determining individual compensation, which may change over time. We comply with all applicable minimum wage laws.For candidates in the United States, the good faith salary ranges estimate for this role isZone 1: $179,900 USD - $269,900 USD Applicable for: CA, CT, DC, MD, MA, NJ, NY, VA, and WAZone 2: $168,200 USD - $252,200 USD Applicable for: All other US locations.International Compensation for candidates residing outside the United States will vary by location and will be discussed during the hiring process. Actual compensation within a range is determined by factors including relevant experience, skill set, qualifications, and performance. In addition to base salary, our total compensation package includes an annual bonus, equity, and a holistic suite of benefits.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Staff Application Security Engineer in United States vacancy
  • $96k - $146k

     ...technologies in support of U.S. National Security and Defense. For the past forty-five...  ...require U.S. citizenship for all employees. Applicants that do not meet this requirement will...  ...an immediate opportunity for a talented engineer to support our programs delivering Next-... 
    Suggested
    Temporary work
    For contractors
    Work experience placement
    Immediate start
    Remote work
    Flexible hours

    SciTec

    Princeton, NJ
    4 days ago
  • $120.25k - $181.25k

     ...This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Senior Application Security Engineer (Offensive / Red Team) in United States. This is a unique opportunity for an experienced offensive security professional to play... 
    Suggested
    Remote job
    Full time
    Flexible hours

    jobgether

    United States
    1 day ago
  •  ...Senior Security Engineer – Secure Code Review New York, NY On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software development... 
    Suggested
    Full time

    AGS

    New York, NY
    3 days ago
  •  ...Application Security Engineer One of our large financial clients is looking for an experienced Application Security Engineer to join their team. If the below requirements fit your skillset, feel free to apply. Duration: Long Term/Multi Year Contract Location:... 
    Suggested
    Long term contract
    Remote work

    Software Technology Inc

    United States
    1 day ago
  • $40 per hour

     ...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback...  ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some... 
    Suggested
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Honolulu, HI
    4 days ago
  • $215k - $230k

     ...A leading blockchain intelligence firm is looking for an Application Security Engineer to secure mission-critical infrastructure. The role involves leading security reviews, developing testing methodologies, and managing vulnerability assessment processes. Candidates should... 

    Crypto Pro Network

    New York, NY
    2 days ago
  • $175k

     ...Overview: Corporate Tools is hiring an Security Engineer for $175,000/year. You will be a traditional company employee. This is a...  ...understanding of security knowledge of testing mobile, native applications, web applications, distributed and database systems ~... 
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours
    Weekend work

    Corporate Tools

    United States
    3 days ago
  • $100k - $150k

     ...edge technologies to create scalable, secure, and user-friendly applications. As we continue to grow, we're...  ...for a skilled Application Security Engineer to join our dynamic team and contribute...  ...onboarding content for engineering staff. Respond to security incidents involving... 
    Full time
    H1b
    Local area
    Immediate start
    Remote work
    Visa sponsorship
    Work visa

    Bright Vision Technologies

    United States
    9 hours ago
  • $89.3k - $130k

     ...Description American Specialty Health Incorporated (ASH) is seeking an Application Security Engineer II to join our Information Security department. The primary purpose of this position is to protect and defend the information security posture and information assets... 
    Full time
    Work experience placement
    Local area
    Remote work
    Work from home

    American Specialty Health Incorporated

    United States
    9 hours ago
  •  ...A venture-backed tech startup is seeking a Sr. Application Security Engineer to oversee the security of their innovative product. This role focuses on ensuring secure multi-tenancy within Kubernetes, leading threat modeling initiatives, and managing vulnerability lifecycles... 
    Remote work
    Flexible hours

    vCluster

    Saint Louis, MO
    1 day ago
  • Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation...  ...innovative security tools and a team of dedicated security engineers to protect our products throughout their lifecycle. Job... 

    Bloomberg Industry Group

    Arlington, VA
    1 day ago
  •  ...Application Security Engineer This role is primarily focused on security administration for ERP applications such as Oracle HCM Cloud, PeopleSoft HCM and Peoplesoft Financials. Under general direction, defines, implements, and maintains application security processes... 
    Remote work

    TriOptus LLC

    United States
    2 days ago
  •  ...Senior Application Security Engineer Remote RegScale is a continuous controls monitoring (CCM) platform that helps organizations automate and scale their security, risk, and compliance programs. We are at an inflection point, transitioning from startup execution... 
    Remote work
    All shifts
    Shift work

    RegScale

    United States
    5 days ago
  • $120k - $140k

     ...Application Security Engineer Location: Fully Remote (East Coast) Clearance: Public Trust, Secret Clearance preferred Employment Type: Full-time Salary: $120,000-$140,000 Role Overview : The Application Security Engineer will support the secure development... 
    Full time
    Remote work

    Tomorrow Hire

    United States
    6 days ago
  • $160k

     ...Application Security Engineer We believe talent deserves a human touch. Your application will be read by an actual person who's excited to discover the real you. Location: Remote (United States) | Employment Type: Full-Time About the Role We are looking for... 
    Full time
    Remote work

    New Charter Technologies

    United States
    1 day ago
  • $62k - $141k

     ...Job Number: R0231845 Location: Washington,DC,US Share job via: Share Application Security Engineer The Opportunity: Work together with the client and application community to maintain a resilient security posture... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    United States
    1 day ago
  • $157k - $216k

     ...investing in the next generation of our Application Security capability, a continuous, AI-augmented...  ...defense program built for a SaaS engineering organization where AI agents and human...  ...foundational hire with a clear path to Staff / Tech Lead as the team grows. What You... 
    Contract work
    Local area
    Remote work

    AlphaSense, Inc.

    United States
    5 days ago
  •  ...users (and help the developers behind them get paid), you’ll fit right in. The role: We are looking for a Senior, proactive Application Security Engineer to work closely with engineering teams, PMs and external parties to ensure that RevenueCat's products are secure.... 
    Remote work

    RevenueCat

    New York, NY
    2 days ago
  • $158k - $238k

     ...more performant digital experiences, and scale without heavy engineering support. From independent designers and creative agencies...  ...power what’s possible on the web. We’re looking for a Senior Application Security Engineer to help us level up Webflow’s secure development... 
    Permanent employment
    Full time
    Temporary work
    Fixed term contract
    Local area
    Remote work
    Flexible hours

    Webflow

    New York, NY
    2 days ago
  • $70.3k - $101.3k

     ...Application Security Engineer The Application Security Engineer is responsible for embedding security throughout the software development lifecycle (SDLC), leading application security testing, and driving vulnerability remediation efforts. At CivicPlus, we strive... 
    Work experience placement
    Local area
    Immediate start
    Remote work
    Flexible hours

    CivicPlus

    United States
    1 day ago
  •  ...Application Security Engineer Are you looking for a company where your voice is heard? Where you can make a difference? Do you thrive in a fast-paced work environment? Do you wake every morning excited to work with great people and create success together? Then Intermedia... 
    Remote work
    Day shift

    Intermedia Intelligent Communications

    United States
    1 day ago
  •  ...Insight Global is looking for a Senior Application Security Engineer to support a government-focused vulnerability remediation program. This resource plays a critical role in helping our engineering teams design and build secure, resilient applications. In addition to... 
    Remote work

    Insight Global

    United States
    4 days ago
  •  ...I have an opportunity for "Application Security Engineer - REMOTE" and I am looking for a candidate who can join Immediately if you are interested, reply to me with your updated resume or if you could refer someone I would really appreciate it. Position : Application... 
    Immediate start
    Remote work

    Navtech

    United States
    3 days ago
  •  ...Senior Application Security Engineer Amerisure creates exceptional value for its partners, policyholders, and employees. As a property and casualty insurance company, Amerisure's promise to our partner agencies and policyholders begins with a comprehensive line of insurance... 
    Local area
    Remote work
    Shift work

    Amerisure

    United States
    5 days ago
  •  ...Security Engineer 6–8+ years of experience in Application Security, Product Security, or DevOps with a strong security focus. Extensive hands-on experience with SAST, SCA, DAST, IaC scanning, and integrating security tools into modern CI/CD pipelines. Proven ability... 
    Remote work

    Saxon Global

    United States
    4 days ago
  •  ...Primary Information Job Title: Application Security Engineer Client: Booz Allen Hamilton Govt Agency: SEC Position: Application Security Engineer Location: 100% Remote Contract Duration: 12+ months Interview Process: 2x video Onboarding Process: Must obtain SEC Public... 
    Contract work
    Remote work

    Polar IT

    Wilmington, DE
    9 days ago
  • $180k - $225k

     ...Senior Application Security Engineer United States - Remote Opportunity About Us Temporal is an open source programming model that can simplify code, make applications more reliable, and help developers focus on the important things like delivering features faster... 
    Full time
    Temporary work
    Part time
    Remote work
    Work from home
    Home office

    Temporal Technologies

    United States
    2 days ago
  •  ...Must Have:- • Seeking candidates with solid expertise in Manual web application penetration testing and Manual secure code review. • Expertise is performing Manual Test Case Scenarios is a must. • Identification of Vulnerabilities in Source Codes manually is a must... 
    Remote work

    Yochana

    United States
    1 day ago
  • $128k - $181.25k

     ...Senior Application Security Engineer (Offensive / Red Team) At Shutterfly, we make life's experiences unforgettable. We believe there is extraordinary power in the self-expression. That's why our family of brands helps customers create products and capture moments that... 
    Remote work

    Shutterfly

    United States
    9 hours ago
  •  ...Appsecops Engineer The Application Security Engineer is responsible for designing, building, and maintaining the technical infrastructure that enables scalable application security across the organization. This role bridges software engineering and security disciplines... 
    Remote work

    Diverse Lynx

    United States
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Application Security Engineer. Be the first to apply!