Senior Application Security Engineer
$218k - $273kApollo.io
Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world's largest enterprises. Founded in 2015, the company is one of the fastest growing companies in SaaS, raising approximately $250 million to date and valued at $1.6 billion. Apollo.io provides sales and marketing teams with easy access to verified contact data for over 210 million B2B contacts and 35 million companies worldwide, along with tools to engage and convert these contacts in one unified platform. By helping revenue professionals find the most accurate contact information and automating the outreach process, Apollo.io turns prospects into customers. Apollo raised a series D in 2023 and is backed by top-tier investors, including Sequoia Capital, Bain Capital Ventures, and more, and counts the former President and COO of Hubspot, JD Sherman, among its board members. Role Overview The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends deep code-level application security work with strong cross-functional partnership. It includes application security reviews, threat modeling, AppSec tooling, findings triage and remediation follow-through, external testing intake, and developer enablement. This role is calibrated at the L6 senior-IC level: owning semi-annual or annual goals, solving ambiguous problems with sound judgment, improving operational processes, and driving meaningful cross-team collaboration and influence. Key Responsibilities Secure SDLC, design review, and threat modeling Own and continuously improve the secure software development lifecycle for Apollo applications so security is embedded into design, implementation, and deployment. Perform application security reviews, threat modeling, and deep code-level analysis for high-impact product, platform, and AI features before launch. Provide practical security architecture guidance to Engineering, Product, and IT teams. Help define and maintain application-security guardrails, secure design expectations, code review standards, and risk models for new and existing systems. Vulnerability management and hands-on remediation Drive execution-heavy vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other research signals, ensuring findings are validated, prioritized, routed clearly, and tracked through remediation and verification within SLAs. Go beyond identifying issues: read the code, explain root cause, propose the safest fix, and directly implement or support remediation when needed for complex vulnerabilities. Perform hands-on validation and offensive security testing of applications and fixes, including exploit development, bypass testing, adversarial thinking, and focused red-team-style exercises, to confirm remediations address the underlying issue rather than only the initial symptom. Work across the kinds of application security issues common in modern SaaS environments, including authentication and authorization weaknesses, access control risks, OAuth and CSRF design flaws, SSRF, cryptographic and verification issues, information disclosure and data exposure risks, unsafe execution and deserialization patterns, and dependency or runtime vulnerabilities. Apply clear, risk-based severity decisions using exploitability, data sensitivity, customer impact, and blast radius. Tooling, automation, and AI Configure and improve AppSec tooling and integrations, including SAST configuration, ignore lists, dashboards, and other controls that maintain useful coverage without excessive noise. Select, build, or refine security tooling, small automations, and workflow enrichments that reduce manual effort and scale AppSec operations responsibly. Use AI to automate, transform, and scale security and engineering-adjacent processes where it materially improves speed, consistency, or signal quality, while still validating outputs with strong engineering judgment. Embed AI-specific security checks into SSDLC reviews and code analysis, including input and output handling, AI-exposed APIs, prompt and response guardrails, and abuse or data-exfiltration paths. Partner cross-functionally on AI security requirements and controls so AI systems and AI-powered features are designed, deployed, and operated securely. Engineering enablement and partnership Support and scale security enablement for engineers and security champions, including secure coding, AppSec, and AI-safety content. Provide actionable remediation guidance, secure patterns, and examples that help engineering teams fix issues quickly and correctly. Partner closely with Engineering, Product, Platform, Data, Legal, and other security teams to keep AppSec priorities aligned with business risk and product velocity. Produce clear documentation, metrics, and written narratives that improve AppSec visibility, observability, and decision-making. What Good Looks Like at L6 Owns meaningful AppSec goals over a semi-annual or annual horizon and independently identifies the right solutions to ambiguous, open-ended problems. Drives cross-team collaboration and operational improvements beyond isolated tickets or one-off reviews. Makes informed decisions by balancing technical detail, business context, customer trust, and long-term risk. Sets a high bar for ownership, communication, mentoring, and technical judgment, and helps raise the effectiveness of peers and partner teams. Required Skills & Experience 5+ years of software engineering or application security experience, with meaningful hands-on AppSec depth in modern SaaS environments. Strong software development skills and the ability to read, write, and ship production code; Ruby experience is highly valuable, and Python or similar scripting ability is a plus. Strong Linux and cloud fundamentals, ideally with experience in GCP-backed environments. Deep familiarity with common AppSec issues, secure design, secure authentication and authorization patterns, vulnerability management, and developer security tooling. Demonstrated ability to perform deep code review, penetration testing, and exploit-oriented validation, and to either fix vulnerabilities directly or work closely with engineers to land durable remediations that hold up against bypass attempts and variant analysis. Experience handling findings from bug bounty, pentests, internal reviews, or automated security tooling through closure and verification. Experience using AI-assisted tools, automations, APIs, or structured workflows to improve engineering or security processes at scale. Experience securing AI-powered systems or features, including AI API exposure, prompt and response handling, data protection, misuse scenarios, and monitoring expectations. Strong written and verbal communication, stakeholder management, and influencing skills across technical and non-technical partners. Preferred Qualifications Experience supporting or leading security reviews for AI-native products, internal agents, or AI-assisted engineering workflows. Experience improving secure-by-design practices and AppSec observability in a fast-moving engineering organization. Experience with security training, developer enablement, or security champions programs. Relevant security certifications are a plus. Example Success Outcomes Improve the health and flow of AppSec findings by keeping prioritization, remediation, and verification moving within defined SLAs. Complete recurring application reviews or threat models for important systems and features. Increase engineering adoption of secure patterns, AppSec tooling, and security training. Reduce manual toil and improve AppSec signal quality through targeted automation and responsible use of AI-assisted workflows. The listed Pay Range reflects the total cash compensation inclusive of annual base salary and annual bonus as applicable. For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonus target and annual base salary for the role. This salary range may be inclusive of several career levels at Apollo and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location. Applicants interested in this role who are not located in the US may request the annual salary range for their location during the interview process. Additional benefits for this role may include: equity; company bonus or sales commissions/bonuses; 401(k) plan; at least 10 paid holidays per year, flex PTO, and parental leave; employee assistance program and wellbeing benefits; global travel coverage; life/AD&D/STD/LTD insurance; FSA/HSA and medical, dental, and vision benefits. Tier 1 Pay Range (San Francisco, New York City, Seattle)
$218,000—$273,000 USD
Tier 2 Pay Range (All other US Locations)$190,000—$237,000 USD
We are AI Native Apollo.io is an AI-native company built on a culture of continuous improvement. We’re on the front lines of driving productivity for our customers—and we expect the same mindset from our team. If you're energized by finding smarter, faster ways to get things done using AI and automation, you'll thrive here. Why You’ll Love Working at Apollo At Apollo, we’re driven by a shared mission: to help our customers unlock their full revenue potential. That’s why we take extreme ownership of our work, move with focus and urgency, and learn voraciously to stay ahead. We invest deeply in your growth, ensuring you have the resources, support, and autonomy to own your role and make a real impact. Collaboration is at our core—we’re all for one, meaning you’ll have a team across departments ready to help you succeed. We encourage bold ideas and courageous action, giving you the freedom to experiment, take smart risks, and drive big wins. If you’re looking for a place where your work matters, where you can push boundaries, and where your career can thrive—Apollo is the place for you. Learn more here!- ...Senior Security Engineer – Secure Code Review San Francisco, California On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software...SeniorFull time
- Software Guidance & Assistance, Inc., (SGA), is searching for a Senior Application Security Engineer for a CONTRACT assignment with one of our premier Regulatory clients in Rockville, MD. The main function of senior application security engineer is to plan, coordinate...SeniorContract work
- ...available! The details are below. Beware of scams. S3 never asks for money during its onboarding process. Job Title: Senior Application Security Engineer (AI/ML) Contract Length: 6+ months Location: Iselin NJ 08830/ Charlotte, NC/ Dallas, TX/ Phoenix, AZ 3 days...SeniorContract workRemote workVisa sponsorshipShift work3 days per week
- ...7+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has... ...meet you! ABOUT THE ROLE We are looking for a Senior Application Security Engineer to develop AI-enabled secure code scanning and integrate...SeniorFlexible hours
- ...Senior Application Security Engineer Remote RegScale is a continuous controls monitoring (CCM) platform that helps organizations automate and scale their security, risk, and compliance programs. We are at an inflection point, transitioning from startup execution...SeniorRemote workAll shiftsShift work
$80 - $85 per hour
...risks specifically related to application security. ? Develop, socialize, and implement... ...vulnerabilities, to senior management. ? Perform/coordinate application... ...Requirements Senior Application Security Engineer Mandatory Skills/Experience...SeniorContract workFlexible hours- ...Senior Application Security Engineer We are seeking a highly skilled and proactive Senior Application Security Engineer to join our growing security team. You will be responsible for securing our applications throughout the software development lifecycle (SDLC). This...SeniorRemote work
$97.1k - $161.8k
...capturing and refining information security requirements and ensures... ...the areas of secure coding, application authentication, encryption,... ...Develop and implement engineering's technical security policies... ...Technology, and occasionally senior leaders within Cybersecurity...SeniorWork experience placementWorldwide- ...Senior Application Security Engineer Become a founding member of the Application Security team at CookUnity. You'll work closely with disparate groups inside of CookUnity's engineering organization, ranging from our Infrastructure and Software Engineering teams to...SeniorRemote workFlexible hours
$151k - $226.25k
...Title: Senior Application Security Engineer Location: San Jose, CA / Morristown, NJ (hybrid) Reports To: Sr. Manager, Cybersecurity About Hippo Hippo was built on a promise: make homeownership effortless. Nearly a decade later, that mission still drives...SeniorTemporary workFlexible hours$130k - $180k
...physicians, providing critical information about the right treatments for the right patients, at the right time. Senior Application Security Engineer Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing to join our...Senior$160k - $240k
..., and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before... ...and integrity of our customers' data. As our first Application Security Engineer , you will take on a dynamic and high impact role. You will...SeniorHome officeFlexible hours- ...Senior Application Security Engineer Poland The Tripadvisor Group connects people to experiences worth sharing, and aims to be the world's most trusted source for travel and experiences. We leverage our brands, technology, and capabilities to connect our global...SeniorPermanent employmentContract workRemote workWorldwideFlexible hours
- ...Application Security Engineer Position will be hybrid (4 days in office and 1 day remote (remote day can be flexible). 10+ years of experience Strong experience designing and implementing AppSec programs within DevSecOps, including integration of SAST, SCA, DAST, and...SeniorWork at officeRemote workFlexible hoursShift work
$120k - $150k
...Our cybersecurity and information security teams at IDEXX contribute to a more resilient, adaptable, and security-aware... ...delivering high quality patient care. IDEXX is seeking a Senior Application Security Engineer to join our Product & Application Security team...SeniorLocal areaRemote workWorldwideFlexible hours$165k - $190k
...Senior Application Security Engineer Los Angeles, California, United States Tatari is on a mission to revolutionize TV advertising. Founded in 2016 to help transform the antiquated world of TV advertising through the intelligent application of AI and machine learning...SeniorWork at office2 days per week$165k - $225k
...Senior Application Security Engineer Denver, CO or Long Beach, CA or SF Bay Area, CA Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it. True Anomaly delivers decisive capabilities for...SeniorShift work- A leading software company in San Francisco is looking for an Application Security Engineer. This hybrid role requires strong experience in automated vulnerability scanning and penetration testing. Responsibilities include developing secure coding practices, conducting...Senior
- ...Job Description Senior Application Security Engineer - Threat Modeling & AI Security *]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height...SeniorContract workRemote work
- A leading logistics and transportation services company in Atlanta is looking for a highly motivated Application Security Engineer to bolster their security team. This role involves conducting security assessments, collaborating with development teams, and ensuring security...Senior
- ...Senior Application Security Engineer At CertiPath, you'll join a fast-moving team with a meaningful mission, delivering high-assurance identity and trust solutions that matter. We are seeking a Senior Application Security (AppSec) Engineer to strengthen our security...SeniorWork at officeLocal area2 days per week3 days per week
$180k - $220k
...Senior Application Security Engineer, AI and Machine Learning San Francisco, California, United States; Seattle, Washington, United States Who We Are Lightning AI is the company behind PyTorch Lightning. Founded in 2019, we build an end-to-end platform for developing...SeniorWork at officeWork from homeFlexible hours2 days per week$325k - $405k
A leading AI research firm in San Francisco is seeking a Security Engineer for Application Security. The role involves identifying and mitigating security vulnerabilities, conducting assessments, and developing security tools. Ideal candidates will have extensive experience...SeniorRemote job$128k - $181.25k
...Senior Application Security Engineer (Offensive / Red Team) At Shutterfly, we make life's experiences unforgettable. We believe there is extraordinary power in the self-expression. That's why our family of brands helps customers create products and capture moments...SeniorRemote work$110k - $130k
A logistics services company located in Boston is seeking an experienced Application Security Engineer to enhance security across its applications. The ideal candidate will possess a strong technical background in software development, secure coding, and vulnerability assessments...Senior$110k - $130k
A leading logistics company is looking for an Application Security Engineer to join their security team in Raleigh, North Carolina. The ideal candidate will ensure the security of applications and data throughout the software development lifecycle, conducting assessments...Senior- ...Senior Application Security Engineer This role has been designed as ‘Hybrid’ with an expectation that you will work on average 2 days per week from an HPE office. Who We Are: Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people...SeniorWork experience placementWork at office2 days per week
- A leading AI research firm is seeking a Security Engineer, Application Security. In this role, you will identify and mitigate security vulnerabilities through assessments and collaboration with development teams. The ideal candidate has extensive experience in cybersecurity...SeniorRemote job
$62k - $141k
Phase2 Technology is looking for an Application Security Engineer to work with clients on maintaining application security. This role involves remediating security flaws, leading discussions on best practices, and conducting dynamic and static testing using tools like Burp...SeniorRemote job$130k - $218k
A leading blockchain company is seeking a Senior Application Security Engineer to join their growing security team. The role involves embedding security throughout the software development lifecycle for MetaMask products, ensuring they meet high-security standards. Applicants...SeniorRemote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!
- application system engineer United States
- junior application support engineer United States
- hydraulic application engineer United States
- senior application security engineer United States
- application performance engineer United States
- application engineer United States
- application engineering manager United States
- network applications engineer United States
- cnc applications engineer United States
- field applications engineer United States


