> Markdown version of [/jobs/ext/618504-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/618504-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Jobot - **Location:** San Francisco, CA, United States - **Experience:** Experienced - **Salary:** $104,000.0 - $166,400.0 - **Contract:** Temporary to permanent - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, User Authentication, Microsoft Azure, Burp Suite, Cloud Computing Security, Cloud Engineering, Code Review, Continuous Integration, Github, Python (Programming Language), OAuth, Open Source Technology, Open Web Application Security, JSON Web Token, Security Assertion Markup Language (SAML), Secure Coding, Software Engineering, TypeScript, Large Language Models, Software Security, Git, GWAPT, Containerization, Gitlab-ci, Software Coding, Jenkins, Static Application Security Testing, Golang, Programming Languages, Dynamic Application Security Testing - **Published:** June 19, 2026 - **Apply:** https://jobot.com/details/application-security-engineer/950315a301 ## About the Role * 3 to 5 years of experience in application security, penetration testing, or secure software development. * Strong knowledge of OWASP Top 10, CWE, and common web and API vulnerability classes. * Hands-on experience with at least two of the following: SAST, DAST, SCA, or IAST tools in real CI/CD environments. * Proficiency in one or more programming languages (Python, Go, JavaScript/TypeScript, or Java) for automation, tooling, and integration work. * Familiarity with modern development workflows including Git, CI/CD pipelines, and containerized environments. * Solid understanding of authentication and authorization frameworks (OAuth 2.0, SAML, JWT). * Excellent communication skills with the ability to translate security findings into actionable engineering tasks. * Must be located in the SF Bay Area or willing to travel to our San Francisco office on a regular cadence. NICE TO HAVE * Relevant certifications such as OSCP, GWAPT, CEH, or CSSLP. * Experience with bug bounty programs or responsible disclosure processes. * Familiarity with cloud-native security (AWS, GCP, or Azure) and cloud-native workload protection. * Prior contributions to open-source security tooling. ## Description * Perform application security assessments including manual code review, SAST, DAST, SCA, and targeted penetration testing. * Lead threat modeling sessions for new features, architectural changes, and AI/LLM-backed workflows with customer product and engineering teams. * Integrate security tooling (Semgrep, Snyk, CodeQL, GitHub Advanced Security, Burp Suite) into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) with minimal developer friction. * Triage, track, and drive remediation of findings across web, mobile, and API surfaces with developer-friendly workflows and SLAs. * Design and maintain secure coding standards, authentication and authorization patterns (OAuth 2.0, SAML, JWT), and training materials for customer development teams. * Evaluate third-party libraries, vendor integrations, and open-source dependencies for supply chain and security risk. * Support incident response activities and contribute to post-incident analysis with a focus on application-layer root cause. * Write and maintain documentation, runbooks, and architecture decision records (ADRs) for AppSec tooling, coding standards, and remediation playbooks. ## Related Videos - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)