Senior Application Security Engineer
$180k - $210kQualia
At Qualia, we've built the leading B2B real estate technology that transforms the home buying and selling experience into a simple, secure, and enjoyable process. Our SMB and Enterprise products bring together users from across the real estate ecosystem---homebuyers and sellers, lenders, title and escrow agents, and real estate agents---onto a single shared digital closing platform, providing greater clarity and transparency to real estate transactions. Today, through our business customers across the country, millions of consumers use Qualia to close on homes every year.
WHAT YOU'LL WORK ON
We're hiring a Senior Application Security Engineer to join a small, high-leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: you'll set the technical direction and own delivery on how we find, fix, and prevent vulnerabilities across Qualia's products and cloud infrastructure, and you'll be the person other engineers want in the room when an architecture decision has a security dimension.
You'll partner daily with product engineering, infrastructure, and platform teams, and you'll work closely alongside our existing AppSec engineers - raising the technical bar of the team while staying deeply hands-on with code, tooling, and adversarial testing. This is the right role for someone who is as comfortable writing a Burp extension or a Semgrep rule as they are pairing with a product engineer to land a fix.
RESPONSIBILITIES
Run offensive assessments against Qualia's applications and infrastructure: manual penetration testing, exploit development, authenticated web/API testing, and adversarial review of new designs before they ship
Lead threat modeling and secure design review for the highest-risk initiatives across the company, and mentor engineers to do the same for their own work
Own and evolve our AppSec tooling stack end-to-end - SAST, DAST, SCA, secret scanning, IaC scanning, and the CI/CD gates that tie them together. Build the custom rules, detections, and automation that generic tooling doesn't give us
Harden our cloud posture: review AWS configurations, IAM policies, Kubernetes/EKS workloads, and networking boundaries; build automation and guardrails that prevent the same class of issue from recurring
Reduce toil for the team - write the tools, scripts, and integrations that turn a day of triage into a few minutes
Partner with Infrastructure and Platform on detection engineering, incident response support, and cross-cutting programs (secrets management, supply chain, runtime security)
Set the technical bar for the AppSec team: raise the quality of reviews, establish patterns others can reuse, and mentor peers across seniority levels
Represent AppSec in architectural reviews, vendor evaluations, and compliance efforts
YOUR BACKGROUND THAT LIKELY MAKES YOU A MATCH
8+ years of hands-on experience in application security, offensive security, or security engineering, with demonstrable depth in at least two of: offensive testing, security tooling/automation, and cloud/infra security
Strong offensive skills - you can manually exploit real web and API vulnerabilities beyond what a scanner will find, and you can teach others to do the same
Deep familiarity with building and operating security tooling in a modern engineering org: SAST/DAST/SCA pipelines, custom detection rules, secrets scanning, and CI/CD security gates. You've written tooling, not just configured it
Production experience with AWS (IAM, VPC, networking, data services), containerized workloads (Docker, Kubernetes/EKS), and infrastructure-as-code (Terraform or similar)
Comfort reading, reviewing, and contributing code in at least one language common to modern web stacks (Python, Go, Ruby, TypeScript, or similar)
Clear, direct communication style. You can make a sharp technical argument to senior engineers, translate risk into business terms for leadership, and write a bug report an engineer actually wants to fix
Strong partnership instincts - you get leverage by making other teams faster, not by blocking them
NICE TO HAVE
Experience in fintech, proptech, healthcare, or another regulated industry where data sensitivity is high
Background meaningfully contributing to a bug bounty program
Experience with identity and access systems (OIDC, SAML, federation, fine-grained authorization)
Detection engineering, DFIR, or red-team experience
Open source contributions to security tooling, published research, or CVE credits
Relevant certifications (OSCP, OSWE, GWAPT, GPEN, etc.) - valued but not required
While this role is remote work eligible, we have three office locations: San Francisco, California; Concord, New Hampshire; and Austin, Texas.
This role has a base annual salary of $180,000-$210,000 plus a competitive equity and benefits package. (Salary to be determined by relevant experience, location, knowledge, and skills of the applicant, internal equity, and alignment with market data.)
WHY QUALIA
Qualia is made up of incredibly bright, mission-driven coworkers who are passionate about using technology to solve real-world problems---and we're growing quickly. In order to continue building an engaging and dynamic organization, we're committed to giving everyone the support they need to do great work.
Our benefits package is designed to allow our team members to be their best selves, both in and out of the workplace. In addition to comprehensive health plans, a 401k program, and commuter benefits, we prioritize family and personal well-being through professional development, parental leave, and a flexible time off policy. Qualia offers a robust online onboarding program to train new hires, biweekly all hands meetings, and a variety of internal virtual events to keep employees connected.
We believe diverse perspectives and backgrounds are critical to building great technology, and our goal is to cultivate an environment where people feel equally valued and respected. Qualia is proud to be an equal-opportunity workplace, and we welcome applicants from all backgrounds regardless of race, color, ancestry, religion, gender identity or expression, sexual orientation, marital status, age, citizenship, socioeconomic status, disability, or veteran status.
By submitting your application, you acknowledge and agree to the collection, processing, and use of your personal information as described in our Employee Data Privacy Notice .
#LI-Remote
$150k - $196k
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States. This role offers the opportunity to strengthen application security across...SeniorTemporary workRemote work$140k - $200k
...wide range of simple, reliable, and secure crypto products and services to... ...reach, and impact. The Department: Application Security Gemini operates at the... ...late and too expensive. The Role: Senior Application Security Engineer As a Senior Application Security...SeniorFull timeWork at officeRemote workFlexible hours$157k - $216k
...investing in the next generation of our Application Security capability, a continuous, AI-augmented... ...defense program built for a SaaS engineering organization where AI agents and human... ...code side by side at high velocity. As a Senior AI Application Security Engineer, you...SeniorFull timeContract workLocal areaRemote work$125k - $165k
...economic inclusion. Find out how TripleLift raises up the programmatic ecosystem at triplelift.com. Overview The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift's Engineering...SeniorFull timeFlexible hours$192k - $240k
Role Description As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will: ~Perform code reviews, design reviews, penetration testing, and vulnerability management...SeniorFull timeWork experience placement$100k - $130k
Role Description As a Senior Application Security Engineer at Bonterra, you will be embedded across the Engineering organization, partnering directly with development teams to drive vulnerability remediation, build security ownership, and close the gap between identified...SeniorFull timeLocal areaImmediate start$157k - $216k
...investing in the next generation of our Application Security capability, a continuous, AI-augmented... ...defense program built for a SaaS engineering organization where AI agents and human... ...code side by side at high velocity. As a Senior AI Application Security Engineer, you...SeniorFull timeRemote work$150k - $196k
Role Description The Senior Application Security Engineer joins the Information Security team and plays a key role in securing the OneStream platform throughout the software development lifecycle. This role is responsible for: ~Defining and enforcing secure coding and...SeniorFull timeTemporary work$190k - $273k
Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends...SeniorFull timeFlexible hours- Role Description BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering...SeniorFull timeRemote work
$180k - $210k
Role Description We're hiring a Senior Application Security Engineer to join a small, high-leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: ~Set the technical direction and own delivery on how we find, fix, and prevent vulnerabilities...SeniorFull timeFlexible hours- Role Description Our team is growing and we're hiring a Senior Application Security Engineer to join our engineering team and enable our next phase of growth. Canary's engineering team is fully remote! This role focuses on embedding security into the software development...SeniorFull timeRemote work
- Role Description As a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll work effectively and efficiently in a small, high-impact team, bringing a sense of ownership and community. You’ll have the opportunity to learn quickly...SeniorFull timeFlexible hours
$180k - $215k
Role Description Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering...SeniorFull timeWork at officeRemote workWeekend work$130k - $160k
...information at scale across 75+ health systems and millions of patient encounters. Security is not a layer we add at the end; it is built into how we work. As a Senior Application Security Engineer, you will own the application security practice at Fabric, partnering...SeniorFull time- Role Description GuidePoint Security offers an inclusive set of Application Security services helping clients implement, fine tune and run their Application Security SAST, DAST and SCA tools. Many clients need assistance with either supplementing their Application Security...SeniorFull timeRemote workFlexible hours
$120k - $258.5k
...Description Nordstrom is building a new Application Security team, built on a simple idea: teams shouldn... ...we build with AI. You’ll report to the Senior Manager of Application Security and partner closely with product engineering and DevOps, alongside our security peers...SeniorFull time$180k - $205.5k
Role Description Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established...SeniorFull timeWork experience placementRemote workSleeping nights$111k - $144.4k
Role Description The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected...SeniorFull timeTemporary workWork experience placement- ...Joining the Information Security team, the full-time Senior Application Security Engineer will secure the platform throughout the software development lifecycle by defining secure coding practices, performing application security testing, and collaborating with engineering...SeniorFull timeRemote work
$60 - $62 per hour
...experience — talk with your recruiter to learn more. Base pay range $60.00/hr - $62.00/hr Hello We are looking for Senior Application Security Engineers Locations: Hybrid Roles in Charlotte, NC, Westlake, TX, Chandler, AZ and Minneapolis, MN – 3 days Onsite and 2 days...SeniorContract workH1bRemote work- Role Description The primary responsibility of the Senior Application Security Engineer (AI-First Development) is to design, orchestrate, and validate the offensive security tooling and adversary-emulation capabilities used to find, prove, and help remediate exploitable...SeniorFull timeFlexible hours
$130k - $190k
...be the company's technical authority on the security of its software products. Bridges Information Security and Engineering — embedding security into the SDLC for a ~50... ...this role now: The company is maturing its application security function from a position of strength...SeniorFull timeHome office- ...Job Description Job Description Senior Application Security Engineer Canopy, South Jordan, UT About Us Canopy is a fast-growing SaaS company in South Jordan, Utah building simple, powerful software for accounting firms. We're on a mission to help accountants...SeniorRemote work
$150k - $196k
...This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in United States. This role offers the opportunity to strengthen application security across...SeniorRemote jobFull timeTemporary workWorldwide$143k - $224k
...platform, Agility Arc , which allows businesses to deploy, monitor, and scale robot fleets. About The Role As a Senior Application Security Engineer, you will be crucial in integrating security controls directly into our software development lifecycle (SDLC). This...SeniorRemote jobFull timeTemporary workRelocation packageFlexible hours$85k - $105k
...Application Security Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States. This is a fantastic opportunity to join an established and...Full timeH1bLocal areaImmediate startRemote workVisa sponsorship$218k - $235k
Role Description We're seeking a Senior Product Security Engineer who is passionate about building and scaling robust security programs in an AI-... ...development. Qualifications ~8+ years of experience in application or product security roles, with demonstrated expertise...SeniorFull timeRemote work- ...A global technology leader is seeking an experienced Applications Engineer based in San Diego, CA. You will engage with top-tier customers and lead the delivery of innovative solutions in electronic design automation. The role offers flexible hours and a chance to work...SeniorFull timeRemote workFlexible hours
$160k - $250k
...Description Our team is growing, and we’re looking for a Senior Product Security Engineer to dig deep into our endpoint products, find design and... ...problems and ship secure code. If you like to rip apart Linux applications to see how they work and find security flaws; if you...SeniorFull timeWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!
- network applications engineer Remote
- hydraulic application engineer Remote
- application engineering manager Remote
- project application engineer Remote
- application security engineer Remote
- senior application security engineer Remote
- application operations engineer Remote
- application system engineer Remote
- technical application engineer Remote
- senior application support engineer Remote












