Senior Application Security Engineer
$180k - $210kQualia
Senior Application Security Engineer
At Qualia, we've built the leading B2B real estate technology that transforms the home buying and selling experience into a simple, secure, and enjoyable process. Our SMB and Enterprise products bring together users from across the real estate ecosystem---homebuyers and sellers, lenders, title and escrow agents, and real estate agents---onto a single shared digital closing platform, providing greater clarity and transparency to real estate transactions. Today, through our business customers across the country, millions of consumers use Qualia to close on homes every year.
What You'll Work On
We're hiring a Senior Application Security Engineer to join a small, high-leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: you'll set the technical direction and own delivery on how we find, fix, and prevent vulnerabilities across Qualia's products and cloud infrastructure, and you'll be the person other engineers want in the room when an architecture decision has a security dimension.
You'll partner daily with product engineering, infrastructure, and platform teams, and you'll work closely alongside our existing AppSec engineers - raising the technical bar of the team while staying deeply hands-on with code, tooling, and adversarial testing. This is the right role for someone who is as comfortable writing a Burp extension or a Semgrep rule as they are pairing with a product engineer to land a fix.
Responsibilities
- Run offensive assessments against Qualia's applications and infrastructure: manual penetration testing, exploit development, authenticated web/API testing, and adversarial review of new designs before they ship
- Lead threat modeling and secure design review for the highest-risk initiatives across the company, and mentor engineers to do the same for their own work
- Own and evolve our AppSec tooling stack end-to-end - SAST, DAST, SCA, secret scanning, IaC scanning, and the CI/CD gates that tie them together. Build the custom rules, detections, and automation that generic tooling doesn't give us
- Harden our cloud posture: review AWS configurations, IAM policies, Kubernetes/EKS workloads, and networking boundaries; build automation and guardrails that prevent the same class of issue from recurring
- Reduce toil for the team - write the tools, scripts, and integrations that turn a day of triage into a few minutes
- Partner with Infrastructure and Platform on detection engineering, incident response support, and cross-cutting programs (secrets management, supply chain, runtime security)
- Set the technical bar for the AppSec team: raise the quality of reviews, establish patterns others can reuse, and mentor peers across seniority levels
- Represent AppSec in architectural reviews, vendor evaluations, and compliance efforts
Your Background That Likely Makes You A Match
- 8+ years of hands-on experience in application security, offensive security, or security engineering, with demonstrable depth in at least two of: offensive testing, security tooling/automation, and cloud/infra security
- Strong offensive skills - you can manually exploit real web and API vulnerabilities beyond what a scanner will find, and you can teach others to do the same
- Deep familiarity with building and operating security tooling in a modern engineering org: SAST/DAST/SCA pipelines, custom detection rules, secrets scanning, and CI/CD security gates. You've written tooling, not just configured it
- Production experience with AWS (IAM, VPC, networking, data services), containerized workloads (Docker, Kubernetes/EKS), and infrastructure-as-code (Terraform or similar)
- Comfort reading, reviewing, and contributing code in at least one language common to modern web stacks (Python, Go, Ruby, TypeScript, or similar)
- Clear, direct communication style. You can make a sharp technical argument to senior engineers, translate risk into business terms for leadership, and write a bug report an engineer actually wants to fix
- Strong partnership instincts - you get leverage by making other teams faster, not by blocking them
Nice to have:
- Experience in fintech, proptech, healthcare, or another regulated industry where data sensitivity is high
- Background meaningfully contributing to a bug bounty program
- Experience with identity and access systems (OIDC, SAML, federation, fine-grained authorization)
- Detection engineering, DFIR, or red-team experience
- Open source contributions to security tooling, published research, or CVE credits
- Relevant certifications (OSCP, OSWE, GWAPT, GPEN, etc.) - valued but not required
While this role is remote work eligible, we have three office locations: San Francisco, California; Concord, New Hampshire; and Austin, Texas.
This role has a base annual salary of $180,000-$210,000 plus a competitive equity and benefits package. (Salary to be determined by relevant experience, location, knowledge, and skills of the applicant, internal equity, and alignment with market data.)
$150k - $196k
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in United States. This role offers the opportunity to strengthen application security across a...SeniorFull timeTemporary workRemote workWorldwide$125k - $160k
...0.00 - $160,000.00 / Year Other Compensation Annual Performance Bonus Eligible Job Category Cybersecurity, Application Security, Security Engineering Relocation Expense Covered No Employee Type FT Exempt Travel 5% Manage Others No Contact Information...SeniorRemote workRelocation- ...however, we are looking for someone with a stronger Application Security background. Certifications like DevSecOps and CISSP... .... Overall, the client is looking for a strong Senior Application Security Engineer with DevSecOps Team Lead-level experience . App Sec...Senior
- ...~6-8+ years of experience in Application Security, Product Security, or DevOps with a strong security focus. ~ Extensive hands-on experience with SAST, SCA, DAST , IaC scanning, and integrating security tools into modern CI/CD pipelines. ~ Proven ability to...SeniorRemote work
$100k - $130k
...organizations and over 50 percent of Fortune 100 companies. Learn more at bonterratech.com. About the Role As a Senior Application Security Engineer at Bonterra, you will be embedded across the Engineering organization, partnering directly with development teams to...SeniorFull timeLocal areaImmediate start- ...Joining the Information Security team, the full-time Senior Application Security Engineer will secure the platform throughout the software development lifecycle by defining secure coding practices, performing application security testing, and collaborating with engineering...SeniorFull timeRemote work
$97.1k - $161.8k
...capturing and refining information security requirements and ensures... ...the areas of secure coding, application authentication, encryption,... ...Develop and implement engineering's technical security policies... ...Technology, and occasionally senior leaders within Cybersecurity...SeniorWork experience placementRemote workWorldwide- ...Senior Application Security Engineer Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across...SeniorWork at officeRemote workWork from homeWeekend work
- ...Senior Application Security Engineer Our team is looking for a Senior Application Security Engineer with extensive product security experience and deep expertise in web security, applied cryptography, software security vulnerabilities, IAM solutions, including federation...SeniorRemote work
- ...Senior Application Security Engineer Poland The Tripadvisor Group connects people to experiences worth sharing, and aims to be the world's most trusted source for travel and experiences. We leverage our brands, technology, and capabilities to connect our global...SeniorPermanent employmentContract workRemote workWorldwideFlexible hours
- ...Senior Application Security Engineer This role has been designed as 'Hybrid' with an expectation that you will work on average 2 days per week from an HPE office. Who We Are: Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people...SeniorWork experience placementWork at office2 days per week
$157k - $216k
...investing in the next generation of our Application Security capability, a continuous, AI-augmented... ...defense program built for a SaaS engineering organization where AI agents and human... ...code side by side at high velocity. As a Senior AI Application Security Engineer, you...SeniorContract workLocal areaRemote work- ...Senior Application Security Engineer Intapp is growing our application security team and is looking for a Senior Application Security Engineer. You'll focus on a subset of our products to understand them deeply and help development teams build products that are secure...SeniorRemote workHome officeFlexible hours
$60 - $62 per hour
...experience — talk with your recruiter to learn more. Base pay range $60.00/hr - $62.00/hr Hello We are looking for Senior Application Security Engineers Locations: Hybrid Roles in Charlotte, NC, Westlake, TX, Chandler, AZ and Minneapolis, MN – 3 days Onsite and 2 days...SeniorContract workH1bRemote work$180k - $225k
...Senior Application Security Engineer United States - Remote Opportunity About Us Temporal is an open source programming model that can simplify code, make applications more reliable, and help developers focus on the important things like delivering features faster...SeniorFull timeTemporary workPart timeRemote workWork from homeHome office$130k - $190k
...This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Application Security Engineer based in United States. The Sr. Application Security Engineer will serve as the technical authority...SeniorTemporary workRemote workHome office$192k - $240k
Role Description As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will: ~Perform code reviews, design reviews, penetration testing, and vulnerability management...SeniorFull timeWork experience placement- ...prioritizing risks specifically related to application security. ? Develop, socialize, and implement... ...on application vulnerabilities, to senior management. ? Perform/coordinate... ...: Senior Application Security Engineer Mandatory Skills/Experience • 12...SeniorFlexible hours
- Role Description BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering...SeniorFull timeRemote work
$150k - $196k
Role Description The Senior Application Security Engineer joins the Information Security team and plays a key role in securing the OneStream platform throughout the software development lifecycle. This role is responsible for: ~Defining and enforcing secure coding and...SeniorFull timeTemporary work$157k - $216k
...investing in the next generation of our Application Security capability, a continuous, AI-augmented... ...defense program built for a SaaS engineering organization where AI agents and human... ...code side by side at high velocity. As a Senior AI Application Security Engineer, you...SeniorFull timeRemote work- Role Description As a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll work effectively and efficiently in a small, high-impact team, bringing a sense of ownership and community. You’ll have the opportunity to learn quickly...SeniorFull timeFlexible hours
$190k - $273k
Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends...SeniorFull timeFlexible hours- Role Description GuidePoint Security offers an inclusive set of Application Security services helping clients implement, fine tune and run their Application Security SAST, DAST and SCA tools. Many clients need assistance with either supplementing their Application Security...SeniorFull timeRemote workFlexible hours
- ...Job Description Job Description As a member of the Application Security team, you will help prevent and mitigate vulnerabilities by collaborating... ...all of these areas as needed: ● Manage the end-to-end engineering and integration of AI/ML-driven security solutions into our...SeniorFull timeTemporary workFlexible hours
$180k - $210k
Role Description We're hiring a Senior Application Security Engineer to join a small, high-leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: ~Set the technical direction and own delivery on how we find, fix, and prevent vulnerabilities...SeniorFull timeFlexible hours- Role Description Our team is growing and we're hiring a Senior Application Security Engineer to join our engineering team and enable our next phase of growth. Canary's engineering team is fully remote! This role focuses on embedding security into the software development...SeniorFull timeRemote work
$200k - $235k
...founding in 2013, we have focused on enabling our clients to securely navigate the digital asset space. With a global presence... ...and innovative problem-solving. We are seeking a Senior Application Security Engineer to lead the technical execution of our product security...SeniorFull timeWork at officeWorldwide$150k - $196k
...This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States. This role offers the opportunity to strengthen application security across...SeniorRemote jobFull timeTemporary work$143k - $224k
...platform, Agility Arc , which allows businesses to deploy, monitor, and scale robot fleets. About The Role As a Senior Application Security Engineer, you will be crucial in integrating security controls directly into our software development lifecycle (SDLC). This...SeniorRemote jobFull timeTemporary workRelocation packageFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!
- network applications engineer United States
- hydraulic application engineer United States
- application engineering manager United States
- project application engineer United States
- application security engineer United States
- senior application security engineer United States
- application operations engineer United States
- application system engineer United States
- technical application engineer United States
- senior application support engineer United States





