Applied Methods
~The MetaSecurityApplication Security Engineer

Application Security Engineer

This role conducts comprehensive security reviews and threat modeling across AI-native platforms and data infrastructure, identifying vulnerabilities in applications that power enterprise AI agents, LLM systems, and knowledge graphs. What distinguishes Application Security Engineers from broader security roles is their focus on embedding security into the development lifecycle itself—through code reviews, secure design practices, and CI/CD integration—rather than conducting external assessments alone. These engineers typically sit within dedicated product or application security teams that partner closely with engineering organizations, translating security requirements into developer-friendly practices and tooling that enable teams to ship secure code at scale.

$ titles --canonical
Application Security EngineerStaff Product Security Engineer
Open Jobs29
Companies Hiring18
$02

Skills

What companies are looking for in this role.

$ skills --core

Conducting threat modeling and security architecture reviews to identify and mitigate design-level risks

95%

Performing comprehensive code reviews and static analysis to identify security vulnerabilities

92%

Designing and implementing security controls and tooling integrated into CI/CD pipelines

90%

Managing vulnerability lifecycle including intake, triage, validation, and remediation coordination

88%

Establishing and maintaining secure coding standards and best practices across engineering teams

85%

Conducting dynamic and static application security testing and analysis

85%

Designing secure defaults and patterns to reduce security issues at the architectural level

82%

Securing cloud-native architectures and containerized deployments

80%

Writing and deploying exploit code and proof-of-concepts to validate vulnerabilities

78%

Developing security features and products that improve customer security posture

75%

Securing APIs and web applications against common attack vectors

75%

Assessing exploitability and prioritizing security findings based on risk rather than CVE scores alone

75%

Managing security incident response and coordinating with operations teams

72%

Operating bug bounty programs and coordinated vulnerability disclosure processes

70%

Establishing and tracking vulnerability remediation SLAs and security metrics

70%

Conducting offensive security assessments including penetration testing and red team exercises

68%

Implementing and maintaining fuzzing and dynamic testing frameworks to discover vulnerabilities

65%
$ skills --emerging

Building developer-focused security tooling and guardrails that integrate into modern workflows

78%

Securing AI and machine learning systems including model protection and training data pipelines

75%

Securing AI agents and agentic systems in development and deployment

70%

Implementing software supply chain security controls including artifact signing and provenance tracking

65%

Generating and maintaining Software Bills of Materials for supply chain transparency

60%
$ skills --soft

Collaborating with cross-functional teams including engineering, infrastructure, and product to embed security in development workflows

90%

Communicating security risks and remediation guidance to non-security technical teams

85%

Mentoring and educating developers on secure coding practices and security architecture

80%
$03

Technology

The tools and technologies that define this role.

$ tech --language
Pythonhigh
TypeScripthigh
$ tech --platform
AWShigh
Kuberneteshigh
Dockermoderate
GCPmoderate
GitHubmoderate
$ tech --tool
Terraformhigh
GPGmoderate
HackerOnemoderate
in-totolow
$ tech --concept
CI/CDvery high
SASTvery high
DASThigh
LLMhigh
IASTmoderate
ISO 27001moderate
Machine Learningmoderate
OAuthmoderate
OIDCmoderate
OWASPmoderate
SBOMmoderate
SCAmoderate
SOC 2moderate
FedRamplow
HIPAAlow
PCI DSSlow
$04

Open Jobs

29 open Application Security Engineer jobs across 18 companies.

Abnormal Security5d
Application Security Engineer II
Remote - USA·Security
Replit6d
Security Engineer - Vuln Management (Code)
Foster City, CA·Security
Lovable1w
Application Security Engineer
Stockholm·Security
Writer2w
Security engineer, application security
New York City, NY·Security
Writer2w
Security engineer, application security (UK)
London, UK·Security
Harvey4w
Senior Product Security Engineer
San Francisco·Security
Replit1mo
Product Security Engineer (PSIRT - Product Security Incident Response Team)
Foster City, CA·Security
Glean1mo
Application Security Engineer
Mountain View, CA·Security
Glean1mo
Application Security Engineer
Bangalore, India·Security
MongoDB1mo
Senior Product Security Engineer, Server
Dublin·Security
Databricks2mo
Product Security Engineer
United States·Security
xAI2mo
Application Security Engineer
Palo Alto, CA·Security
Anthropic2mo
Staff+ Application Security Engineer
Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NY·Security
Palantir2mo
Product Infrastructure Security Engineer
New York, NY·Security
Skild AI2mo
Embedded Security Engineer
San Mateo·Security
Databricks2mo
Senior Manager, Product Security
Remote - United Kingdom·Security
Databricks2mo
Senior Manager, Product Security
Remote - Netherlands·Security
Databricks3mo
Staff Product Security Engineer
United States·Security
Thinking Machines Lab3mo
Software Engineer, Security
San Francisco·Security
Notion3mo
Application Security Engineer, AI Security
San Francisco, California·Security