Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Application Security Engineer

$180k - $210k

Qualia

Senior Application Security Engineer

At Qualia, we've built the leading B2B real estate technology that transforms the home buying and selling experience into a simple, secure, and enjoyable process. Our SMB and Enterprise products bring together users from across the real estate ecosystem---homebuyers and sellers, lenders, title and escrow agents, and real estate agents---onto a single shared digital closing platform, providing greater clarity and transparency to real estate transactions. Today, through our business customers across the country, millions of consumers use Qualia to close on homes every year.

What You'll Work On

We're hiring a Senior Application Security Engineer to join a small, high-leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: you'll set the technical direction and own delivery on how we find, fix, and prevent vulnerabilities across Qualia's products and cloud infrastructure, and you'll be the person other engineers want in the room when an architecture decision has a security dimension.

You'll partner daily with product engineering, infrastructure, and platform teams, and you'll work closely alongside our existing AppSec engineers - raising the technical bar of the team while staying deeply hands-on with code, tooling, and adversarial testing. This is the right role for someone who is as comfortable writing a Burp extension or a Semgrep rule as they are pairing with a product engineer to land a fix.

Responsibilities
  • Run offensive assessments against Qualia's applications and infrastructure: manual penetration testing, exploit development, authenticated web/API testing, and adversarial review of new designs before they ship
  • Lead threat modeling and secure design review for the highest-risk initiatives across the company, and mentor engineers to do the same for their own work
  • Own and evolve our AppSec tooling stack end-to-end - SAST, DAST, SCA, secret scanning, IaC scanning, and the CI/CD gates that tie them together. Build the custom rules, detections, and automation that generic tooling doesn't give us
  • Harden our cloud posture: review AWS configurations, IAM policies, Kubernetes/EKS workloads, and networking boundaries; build automation and guardrails that prevent the same class of issue from recurring
  • Reduce toil for the team - write the tools, scripts, and integrations that turn a day of triage into a few minutes
  • Partner with Infrastructure and Platform on detection engineering, incident response support, and cross-cutting programs (secrets management, supply chain, runtime security)
  • Set the technical bar for the AppSec team: raise the quality of reviews, establish patterns others can reuse, and mentor peers across seniority levels
  • Represent AppSec in architectural reviews, vendor evaluations, and compliance efforts
Your Background That Likely Makes You A Match
  • 8+ years of hands-on experience in application security, offensive security, or security engineering, with demonstrable depth in at least two of: offensive testing, security tooling/automation, and cloud/infra security
  • Strong offensive skills - you can manually exploit real web and API vulnerabilities beyond what a scanner will find, and you can teach others to do the same
  • Deep familiarity with building and operating security tooling in a modern engineering org: SAST/DAST/SCA pipelines, custom detection rules, secrets scanning, and CI/CD security gates. You've written tooling, not just configured it
  • Production experience with AWS (IAM, VPC, networking, data services), containerized workloads (Docker, Kubernetes/EKS), and infrastructure-as-code (Terraform or similar)
  • Comfort reading, reviewing, and contributing code in at least one language common to modern web stacks (Python, Go, Ruby, TypeScript, or similar)
  • Clear, direct communication style. You can make a sharp technical argument to senior engineers, translate risk into business terms for leadership, and write a bug report an engineer actually wants to fix
  • Strong partnership instincts - you get leverage by making other teams faster, not by blocking them

Nice to have:

  • Experience in fintech, proptech, healthcare, or another regulated industry where data sensitivity is high
  • Background meaningfully contributing to a bug bounty program
  • Experience with identity and access systems (OIDC, SAML, federation, fine-grained authorization)
  • Detection engineering, DFIR, or red-team experience
  • Open source contributions to security tooling, published research, or CVE credits
  • Relevant certifications (OSCP, OSWE, GWAPT, GPEN, etc.) - valued but not required

While this role is remote work eligible, we have three office locations: San Francisco, California; Concord, New Hampshire; and Austin, Texas.

This role has a base annual salary of $180,000-$210,000 plus a competitive equity and benefits package. (Salary to be determined by relevant experience, location, knowledge, and skills of the applicant, internal equity, and alignment with market data.)

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Senior Application Security Engineer in United States vacancy
  •  ...Senior Security Engineer – Secure Code Review San Francisco, California On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software... 
    Senior
    Full time

    AGS

    San Francisco, CA
    11 hours ago
  • Software Guidance & Assistance, Inc., (SGA), is searching for a Senior Application Security Engineer for a CONTRACT assignment with one of our premier Regulatory clients in Rockville, MD. The main function of senior application security engineer is to plan, coordinate... 
    Senior
    Contract work

    Software Guidance & Assistance, Inc. (SGA, Inc.)

    Rockville, MD
    1 day ago
  •  ...available! The details are below. Beware of scams. S3 never asks for money during its onboarding process. Job Title: Senior Application Security Engineer (AI/ML) Contract Length: 6+ months Location: Iselin NJ 08830/ Charlotte, NC/ Dallas, TX/ Phoenix, AZ 3 days... 
    Senior
    Contract work
    Remote work
    Visa sponsorship
    Shift work
    3 days per week

    Leading Utilities Organization

    Iselin, NJ
    3 days ago
  •  ...7+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has...  ...meet you! ABOUT THE ROLE We are looking for a Senior Application Security Engineer to develop AI-enabled secure code scanning and integrate... 
    Senior
    Flexible hours

    AgileEngine

    Jersey City, NJ
    3 days ago
  •  ...Senior Application Security Engineer Become a founding member of the Application Security team at CookUnity. You'll work closely with disparate groups inside of CookUnity's engineering organization, ranging from our Infrastructure and Software Engineering teams to... 
    Senior
    Remote work
    Flexible hours

    CookUnity

    United States
    2 days ago
  •  ...Senior Application Security Engineer We are seeking a highly skilled and proactive Senior Application Security Engineer to join our growing security team. You will be responsible for securing our applications throughout the software development lifecycle (SDLC). This... 
    Senior
    Remote work

    e.l.f Cosmetics

    United States
    11 hours ago
  • $80 - $85 per hour

     ...risks specifically related to application security. ? Develop, socialize, and implement...  ...vulnerabilities, to senior management. ? Perform/coordinate application...  ...Requirements Senior Application Security Engineer Mandatory Skills/Experience... 
    Senior
    Contract work
    Flexible hours

    Network Temp Inc

    New York, NY
    1 day ago
  •  ...Senior Application Security Engineer Remote RegScale is a continuous controls monitoring (CCM) platform that helps organizations automate and scale their security, risk, and compliance programs. We are at an inflection point, transitioning from startup execution... 
    Senior
    Remote work
    All shifts
    Shift work

    RegScale

    United States
    12 days ago
  • $130k - $180k

     ...physicians, providing critical information about the right treatments for the right patients, at the right time. Senior Application Security Engineer Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing to join our... 
    Senior

    Tempus

    Chicago, IL
    11 hours ago
  •  ...Senior Application Security Engineer – Threat Modeling & AI Security Locations: Charlotte, NC (Brevard), Irving/Las Colinas, TX, or Chandler, AZ Schedule: Hybrid (3 Days Onsite / 2 Days Remote Duration: Contract Overview We are seeking a Senior Application Security... 
    Senior
    Contract work
    Remote work

    Leading Utilities Organization

    Chandler, AZ
    6 hours ago
  •  ...against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed...  ....      Envision yourself at Barracuda   As a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You... 
    Senior
    Remote work
    Worldwide
    Flexible hours

    Barracuda Networks Inc

    Ann Arbor, MI
    6 hours ago
  • $97.1k - $161.8k

     ...capturing and refining information security requirements and ensures...  ...the areas of secure coding, application authentication, encryption,...  ...Develop and implement engineering's technical security policies...  ...Technology, and occasionally senior leaders within Cybersecurity... 
    Senior
    Work experience placement
    Worldwide

    M&T Bank

    United States
    1 day ago
  • $165k - $190k

     ...Senior Application Security Engineer Los Angeles, California, United States Tatari is on a mission to revolutionize TV advertising. Founded in 2016 to help transform the antiquated world of TV advertising through the intelligent application of AI and machine learning... 
    Senior
    Work at office
    2 days per week

    Tatari

    Los Angeles, CA
    4 days ago
  • $160k - $240k

     ..., and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before...  ...and integrity of our customers' data. As our first Application Security Engineer , you will take on a dynamic and high impact role. You will... 
    Senior
    Home office
    Flexible hours

    ZIP

    San Francisco, CA
    1 day ago
  • $120k - $150k

     ...Our cybersecurity and information security teams at IDEXX contribute to a more resilient, adaptable, and security-aware...  ...delivering high quality patient care. IDEXX is seeking a Senior Application Security Engineer to join our Product & Application Security team... 
    Senior
    Local area
    Remote work
    Worldwide
    Flexible hours

    IDEXX Laboratories

    United States
    1 day ago
  • $151k - $226.25k

     ...Title: Senior Application Security Engineer Location: San Jose, CA / Morristown, NJ (hybrid) Reports To: Sr. Manager, Cybersecurity About Hippo Hippo was built on a promise: make homeownership effortless. Nearly a decade later, that mission still drives... 
    Senior
    Temporary work
    Flexible hours

    Hippo Insurance

    Morristown, NJ
    4 days ago
  • A leading logistics and transportation services company in Atlanta is looking for a highly motivated Application Security Engineer to bolster their security team. This role involves conducting security assessments, collaborating with development teams, and ensuring security... 
    Senior

    Ryder System, Inc.

    Atlanta, GA
    2 days ago
  • A leading software company in San Francisco is looking for an Application Security Engineer. This hybrid role requires strong experience in automated vulnerability scanning and penetration testing. Responsibilities include developing secure coding practices, conducting... 
    Senior

    Ironclad Inc.

    San Francisco, CA
    4 days ago
  • $128k - $181.25k

     ...Senior Application Security Engineer (Offensive / Red Team) At Shutterfly, we make life's experiences unforgettable. We believe there is extraordinary power in the self-expression. That's why our family of brands helps customers create products and capture moments... 
    Senior
    Remote work

    Shutterfly

    United States
    3 days ago
  •  ...Senior Application Security Engineer Poland The Tripadvisor Group connects people to experiences worth sharing, and aims to be the world's most trusted source for travel and experiences. We leverage our brands, technology, and capabilities to connect our global... 
    Senior
    Permanent employment
    Contract work
    Remote work
    Worldwide
    Flexible hours

    TripAdvisor

    United States
    3 days ago
  • $110k - $130k

    A logistics services company located in Boston is seeking an experienced Application Security Engineer to enhance security across its applications. The ideal candidate will possess a strong technical background in software development, secure coding, and vulnerability assessments... 
    Senior

    Ryder System, Inc.

    Boston, MA
    2 days ago
  • $165k - $225k

     ...Senior Application Security Engineer Denver, CO or Long Beach, CA or SF Bay Area, CA Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it. True Anomaly delivers decisive capabilities for... 
    Senior
    Shift work

    True Anomaly

    San Francisco, CA
    2 days ago
  • $110k - $130k

    A leading logistics company is looking for an Application Security Engineer to join their security team in Raleigh, North Carolina. The ideal candidate will ensure the security of applications and data throughout the software development lifecycle, conducting assessments... 
    Senior

    Ryder System, Inc.

    Raleigh, NC
    2 days ago
  •  ...with a meaningful mission, delivering high-assurance identity and trust solutions that matter. We are seeking a Senior Application Security (AppSec) Engineer to strengthen our security posture across our TrustSuite products, driving positive customer impact and rapidly... 
    Senior
    Work at office
    Local area
    2 days per week
    3 days per week

    CertiPath

    Reston, VA
    1 day ago
  • $180k - $220k

     ...Senior Application Security Engineer, AI and Machine Learning San Francisco, California, United States; Seattle, Washington, United States Who We Are Lightning AI is the company behind PyTorch Lightning. Founded in 2019, we build an end-to-end platform for developing... 
    Senior
    Work at office
    Work from home
    Flexible hours
    2 days per week

    Lightning AI

    Seattle, WA
    3 days ago
  • A leading AI research firm is seeking a Security Engineer, Application Security. In this role, you will identify and mitigate security vulnerabilities through assessments and collaboration with development teams. The ideal candidate has extensive experience in cybersecurity... 
    Senior
    Remote job

    OpenAI

    Los Angeles, CA
    4 days ago
  • $62k - $141k

    Phase2 Technology is looking for an Application Security Engineer to work with clients on maintaining application security. This role involves remediating security flaws, leading discussions on best practices, and conducting dynamic and static testing using tools like Burp... 
    Senior
    Remote job

    Phase2 Technology

    Washington DC
    11 hours ago
  • $325k - $405k

    A leading AI research firm in San Francisco is seeking a Security Engineer for Application Security. The role involves identifying and mitigating security vulnerabilities, conducting assessments, and developing security tools. Ideal candidates will have extensive experience... 
    Senior
    Remote job

    OpenAI

    San Francisco, CA
    11 hours ago
  • $130k - $218k

    A leading blockchain company is seeking a Senior Application Security Engineer to join their growing security team. The role involves embedding security throughout the software development lifecycle for MetaMask products, ensuring they meet high-security standards. Applicants... 
    Senior
    Remote job

    Consensys

    New York, NY
    4 days ago
  •  ...Key Responsibilities:- Secure Software Development Lifecycle...  ...Define and continuously improve application security quality gates and...  ...in alignment with Modern Engineering SDLC practices. Lead the...  ...consistent with expectations for senior Bank engineers. dvocate... 
    Senior

    Javen Technologies

    Chicago, IL
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!