Senior Application Security Engineer
$180k - $210kQualia
At Qualia, we've built the leading B2B real estate technology that transforms the home buying and selling experience into a simple, secure, and enjoyable process. Our SMB and Enterprise products bring together users from across the real estate ecosystem---homebuyers and sellers, lenders, title and escrow agents, and real estate agents---onto a single shared digital closing platform, providing greater clarity and transparency to real estate transactions. Today, through our business customers across the country, millions of consumers use Qualia to close on homes every year.
WHAT YOU'LL WORK ON
We're hiring a Senior Application Security Engineer to join a small, high-leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: you'll set the technical direction and own delivery on how we find, fix, and prevent vulnerabilities across Qualia's products and cloud infrastructure, and you'll be the person other engineers want in the room when an architecture decision has a security dimension.
You'll partner daily with product engineering, infrastructure, and platform teams, and you'll work closely alongside our existing AppSec engineers - raising the technical bar of the team while staying deeply hands-on with code, tooling, and adversarial testing. This is the right role for someone who is as comfortable writing a Burp extension or a Semgrep rule as they are pairing with a product engineer to land a fix.
RESPONSIBILITIES
Run offensive assessments against Qualia's applications and infrastructure: manual penetration testing, exploit development, authenticated web/API testing, and adversarial review of new designs before they ship
Lead threat modeling and secure design review for the highest-risk initiatives across the company, and mentor engineers to do the same for their own work
Own and evolve our AppSec tooling stack end-to-end - SAST, DAST, SCA, secret scanning, IaC scanning, and the CI/CD gates that tie them together. Build the custom rules, detections, and automation that generic tooling doesn't give us
Harden our cloud posture: review AWS configurations, IAM policies, Kubernetes/EKS workloads, and networking boundaries; build automation and guardrails that prevent the same class of issue from recurring
Reduce toil for the team - write the tools, scripts, and integrations that turn a day of triage into a few minutes
Partner with Infrastructure and Platform on detection engineering, incident response support, and cross-cutting programs (secrets management, supply chain, runtime security)
Set the technical bar for the AppSec team: raise the quality of reviews, establish patterns others can reuse, and mentor peers across seniority levels
Represent AppSec in architectural reviews, vendor evaluations, and compliance efforts
YOUR BACKGROUND THAT LIKELY MAKES YOU A MATCH
8+ years of hands-on experience in application security, offensive security, or security engineering, with demonstrable depth in at least two of: offensive testing, security tooling/automation, and cloud/infra security
Strong offensive skills - you can manually exploit real web and API vulnerabilities beyond what a scanner will find, and you can teach others to do the same
Deep familiarity with building and operating security tooling in a modern engineering org: SAST/DAST/SCA pipelines, custom detection rules, secrets scanning, and CI/CD security gates. You've written tooling, not just configured it
Production experience with AWS (IAM, VPC, networking, data services), containerized workloads (Docker, Kubernetes/EKS), and infrastructure-as-code (Terraform or similar)
Comfort reading, reviewing, and contributing code in at least one language common to modern web stacks (Python, Go, Ruby, TypeScript, or similar)
Clear, direct communication style. You can make a sharp technical argument to senior engineers, translate risk into business terms for leadership, and write a bug report an engineer actually wants to fix
Strong partnership instincts - you get leverage by making other teams faster, not by blocking them
NICE TO HAVE
Experience in fintech, proptech, healthcare, or another regulated industry where data sensitivity is high
Background meaningfully contributing to a bug bounty program
Experience with identity and access systems (OIDC, SAML, federation, fine-grained authorization)
Detection engineering, DFIR, or red-team experience
Open source contributions to security tooling, published research, or CVE credits
Relevant certifications (OSCP, OSWE, GWAPT, GPEN, etc.) - valued but not required
While this role is remote work eligible, we have three office locations: San Francisco, California; Concord, New Hampshire; and Austin, Texas.
This role has a base annual salary of $180,000-$210,000 plus a competitive equity and benefits package. (Salary to be determined by relevant experience, location, knowledge, and skills of the applicant, internal equity, and alignment with market data.)
WHY QUALIA
Qualia is made up of incredibly bright, mission-driven coworkers who are passionate about using technology to solve real-world problems---and we're growing quickly. In order to continue building an engaging and dynamic organization, we're committed to giving everyone the support they need to do great work.
Our benefits package is designed to allow our team members to be their best selves, both in and out of the workplace. In addition to comprehensive health plans, a 401k program, and commuter benefits, we prioritize family and personal well-being through professional development, parental leave, and a flexible time off policy. Qualia offers a robust online onboarding program to train new hires, biweekly all hands meetings, and a variety of internal virtual events to keep employees connected.
We believe diverse perspectives and backgrounds are critical to building great technology, and our goal is to cultivate an environment where people feel equally valued and respected. Qualia is proud to be an equal-opportunity workplace, and we welcome applicants from all backgrounds regardless of race, color, ancestry, religion, gender identity or expression, sexual orientation, marital status, age, citizenship, socioeconomic status, disability, or veteran status.
By submitting your application, you acknowledge and agree to the collection, processing, and use of your personal information as described in our Employee Data Privacy Notice .
#LI-Remote
- ...Written Premium and maintain $1.21 billion in surplus.Amerisure is hiring!! This role can sit remote. We’re looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape our strategy, and partner closely with engineering teams to...SeniorFull timeLocal areaRemote workFlexible hoursShift work
$134.6k - $175k
...a lower cost through early diagnosis and longitudinal care management of chronic conditions. We are looking for a Senior Application Security Engineer to break Counterpart Assistant before anyone else does. This is a hands-on offensive security role on our Eng Core team...SeniorFull timeWork experience placementWork at officeRemote workFlexible hours$160.3k - $240.5k
...architecture, retail, energy, and government. Our Product Security team keeps that platform, and the software built on top... ...millions of creators and their users.We are seeking a Senior Application Security Engineer with profound expertise in application security. In this...SeniorFull timeWork at officeRemote workWorldwide$111k - $144.4k
Remote - US / Reno, NVAdministration - Enterprise Information Security /Full-Time /RemoteThe Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security...SeniorFull timeTemporary workWork experience placementRemote work$60 - $62 per hour
...experience — talk with your recruiter to learn more. Base pay range $60.00/hr - $62.00/hr Hello We are looking for Senior Application Security Engineers Locations: Hybrid Roles in Charlotte, NC, Westlake, TX, Chandler, AZ and Minneapolis, MN – 3 days Onsite and 2 days...SeniorContract workH1bRemote work- ...As a Sr. Application Security Engineer at vCluster Labs, you are the architect of trust in our diverse ecosystem. In this role, you will be responsible for the end-to-end security of our product, ensuring that vCluster remains the de facto standard for secure Kubernetes...SeniorRemote workFlexible hoursShift work
$140k - $200k
...wide range of simple, reliable, and secure crypto products and services to... ...reach, and impact. The Department: Application Security Gemini operates at the... ...and too expensive. The Role: Senior Application Security Engineer As a Senior Application Security...SeniorWork at officeRemote workFlexible hours$130k - $218k
...million monthly active users as a decentralized application development platform, an aggregator of... ...importance to us that we keep our users as safe and secure as possible. We are looking for a Senior Application Security Engineer to join our rapidly growing security team...SeniorContract workRemote workWorldwideShift work$140k - $190k
DescriptionSenior Field Security Applications EngineerLocation: Campbell CA or Austin TXArteris connects innovation.Our technology... ...of semiconductor technology.Arteris is seeking a Senior Field Security Applications Engineer to drive customer adoption of the industry-leading...SeniorContract workRemote workNight shift$192k - $240k
Role Description As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will: ~Perform code reviews, design reviews, penetration testing, and vulnerability management...SeniorFull timeWork experience placement$100k - $130k
Role Description As a Senior Application Security Engineer at Bonterra, you will be embedded across the Engineering organization, partnering directly with development teams to drive vulnerability remediation, build security ownership, and close the gap between identified...SeniorFull timeLocal areaImmediate start- Role Description We are looking for a Senior Application Security Engineer to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration within a large...SeniorFull timeLocal areaRemote workFlexible hours
- Role Description As a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll work effectively and efficiently in a small, high-impact team, bringing a sense of ownership and community. You’ll have the opportunity to learn quickly...SeniorFull timeFlexible hours
$325k - $405k
A leading AI research firm in San Francisco is seeking a Security Engineer for Application Security. The role involves identifying and mitigating security vulnerabilities, conducting assessments, and developing security tools. Ideal candidates will have extensive experience...SeniorRemote job$157k - $216k
...investing in the next generation of our Application Security capability, a continuous, AI-augmented... ...defense program built for a SaaS engineering organization where AI agents and human... ...code side by side at high velocity. As a Senior AI Application Security Engineer, you...SeniorFull timeRemote work- Role Description BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering...SeniorFull timeRemote work
$190k - $273k
Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends...SeniorFull timeFlexible hours$112.13k - $140.17k
...in support of active investigations, which requires that security be embedded throughout our engineering practices rather than addressed at the end of the development cycle. We are seeking a Senior Application Security Engineer to define and own our holistic approach...SeniorFull timeLocal area$180k - $215k
Role Description Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering...SeniorFull timeWork at officeRemote workWeekend work$180k - $205.5k
Role Description Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established...SeniorFull timeWork experience placementRemote workSleeping nights- ...Job Description Job Description Senior Application Security Engineer Canopy, South Jordan, UT About Us Canopy is a fast-growing SaaS company in Draper, Utah building simple, powerful software for accounting firms. We're on a mission to help accountants...SeniorRemote work
- ...needs of businesses today; we are building the nervous system for a borderless global economy. Your Challenge As a Senior Application Security Engineer, you’ll be a hands-on technical expert responsible for improving the security of Unlimit’s applications, APIs, and...SeniorFull timeLocal area
$140k - $200k
...need at least 5 years of experience in application security or a closely related field. We are... ...repetitive security work. We partner with engineering teams to fix vulnerabilities and drive... ...through implementation. In this Senior Application Security Engineer role, we...SeniorFull timeWork at officeRemote workFlexible hours$218k - $273k
...more, and counts the former President and COO of Hubspot, JD Sherman, among its board members. Role Overview The Senior Application Security Engineer is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and...SeniorFull timeWorldwideFlexible hours- ...leading tech company in Plano, TX is seeking an experienced Application Security Analyst to enhance security within DevOps practices. This... ...candidate has over 8 years of experience in DevOps and security engineering, holds a degree in Computer Science or Cybersecurity, and...SeniorRemote work
$100.63k - $167.79k
...your success while helping clients pursue their financial goals. Job Overview:As a member of the Information Security team, the Sr. Application Security Engineer will be responsible for helping to develop, mature, and sustain the Application Security program for the...SeniorFull timeWork from home$135k - $150k
...while our focus on creativity and innovative solutions empowers our customer communities to thrive.We are seeking a Senior Application Security Engineer to lead hands-on application security testing, secure code review, and secure SDLC enablement across moder application...SeniorFull timeTemporary workWork at officeLocal areaRemote work3 days per week- Role Description The primary responsibility of the Senior Application Security Engineer (AI-First Development) is to design, orchestrate, and validate the offensive security tooling and adversary-emulation capabilities used to find, prove, and help remediate exploitable...SeniorFull timeFlexible hours
$130k - $190k
...be the company's technical authority on the security of its software products. Bridges Information Security and Engineering — embedding security into the SDLC for a ~50... ...this role now: The company is maturing its application security function from a position of strength...SeniorFull timeHome office- ...vision to protect consumers and help them grow, manage and secure their digital and financial lives. We’re always looking... ...love you to be part of Gen. About The Role: As a Senior Application Security Engineer, you will help strengthen and scale secure development...SeniorFull timeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!
- application security engineer Remote
- hydraulic application engineer Remote
- technical application engineer Remote
- cnc applications engineer Remote
- application system engineer Remote
- junior application support engineer Remote
- application performance engineer Remote
- application support engineer Remote
- network applications engineer Remote
- application operations engineer Remote









