Application Security Engineer Jobs
Application Security Engineer jobs are open across fintech, healthtech, enterprise software, and government contracting, from junior to principal and staff levels, with specializations in penetration testing, secure code review, and cloud security. Find a role that fits from the openings below and apply directly.
Find JobsOverview
Showing 5 of 218+ Application Security Engineer jobs











Date: Jun 16, 2026
Location: Chicago, IL, US, 60606
Company: National Futures Association
NFA is purpose-driven. We safeguard the integrity of the derivatives markets, protect investors and ensure that our Members meet their regulatory obligations. We take pride in our work; maintain a conviction to do the right thing; empower each other; and support our community. Envision your career in a place where performing critical regulatory work within the financial industry is as significant as the passionate and talented individuals with whom you work.
When you join NFA as a Senior AI & Application Security Engineer, you'll play a critical role in advancing secure-by-design practices across our applications, APIs, cloud platforms, and emerging AI solutions. You will be a hands-on technical leader and subject matter expert developing, designing, and automating secure applications while partnering closely with developers, architects, data, and governance teams. Your expertise will help protect business critical systems while enabling innovation through secure development practices and modern security architecture.
Bring your analytical and innovative mindset to identify and mitigate security risks across traditional and AI-enabled applications. This role requires deep knowledge of application security principles, including OWASP Top 10, API security, threat modeling, secure coding practices, vulnerability management, and application testing tools. You will leverage your experience with Large Language Models (LLMs), Generative AI, and cloud native technologies to help establish security standards, evaluate emerging risks, and guide secure adaptation of AI capabilities across the organization.
Beginning your first day, and throughout your career at NFA, you will work closely with development and architecture teams to create secure applications, perform code reviews, assess cloud security controls, and strengthen our security posture through automation and DevSecOps practices. You will serve as a trusted advisor on Cloudflare security architecture, Web Application Firewall (WAF) technologies, secure API design, and cloud security while helping teams deliver scalable, resilient, and secure solutions that support our mission at NFA.
What you'll do:
In this role you will lead the secure design and implementation of both traditional enterprise and AI-powered applications by integrating security throughout the SDLC, performing architecture reviews, threat modeling, and application security testing across cloud and AI environments. In addition, you will:
- Lead application security architecture reviews, threat modeling exercises, vulnerability assessments, and secure design assessments for web applications, APIs, cloud native platforms, and AI-enabled solutions
- Develop the vision, roadmap, and operating model for securing applications, that illustrates how applications, integrations, cloud services, infrastructure, and network architecture work together as a cohesive ecosystem
- Partner across technology and business teams to define security standards, identify emerging risk, implement proactive controls while developing meaningful metrics that demonstrate risk reduction and program effectiveness
- Perform secure code reviews and implement remediation of application vulnerabilities
- Assess and mitigate risks associated with Large Language Models (LLMs), Generative AI, AI agents, and AI assisted development tools
- Develop, maintain, and adapt to application security standards that are aligned with OWASP Top 10, and industry best practices
- Utilize security testing tools including BURP, to identify vulnerabilities, validate security controls, and follow through with remediation
- Design, implement, and optimize Cloudflare security services including WAF, API security, DDoS protection, and Zero Trust capabilities
- Integrate security controls automated testing, and policy validation into CI/CD pipelines and DevSecOps workflows
- Collaborate with engineering teams to secure cloud environments and applications hosted in diverse cloud platforms
- Serve as a SME on application security, AI security, cloud security, and secure software development practices
- Present security assessments, risk findings, and strategic recommendations to senior leadership and key stakeholders, translating complex technical concepts into actionable outputs
What we are looking for:
We are seeking a subject matter expert across AI and traditional applications, security architecture, cloud technologies and network infrastructure with a deep understanding of how these domains work together to support secure operations. Additional qualifications include:
- Hands on experience reviewing and writing code in one or more modern programming languages
- Strong knowledge of secure coding practices, threat modeling, vulnerability management, and Secure SDLC methodologies
- Expertise with OWASP Top 10, API Security, authentication, authorization, and application layer security controls
- Experience securing and assessing cloud-native applications and architectures within various cloud platforms, as well as designing secure AI/LLM technologies
- Experience architecting, implementing, and maintaining Cloudflare-based security protections, including WAF, API security, DDoS defenses, and other web application security controls
- Strong communications skills with the ability to influence technical teams and drive security initiatives across the organization
- Demonstrated experience guiding secure applications through the full lifecycle from requirements gathering, and architecture reviews to design, development, deployment, remediation and on-going optimization
- Deep knowledge of how applications reside and interact across the cloud, network, an infrastructure environment, enabling the development of comprehensive security strategies and roadmaps
- Experience interpreting and implementing enterprise security architecture principles and governance frameworks, with practical application of NIST SP 800‑53, NIST Cybersecurity Framework (CSF) 2.0, NIST AI Risk Management Framework (AI RMF), NIST SP 800‑218 (SSDF), and NIST SP 800‑207 within application security programs
The salary range for this position is $152,950 to $272,000
Customers and market participants depend on NFA to act with integrity and impartiality as it carries out its mission of safeguarding the markets and protecting investors. Therefore, NFA employees have a responsibility to conduct themselves according to high ethical standards, and must abide by NFA's Code of Professional Conduct. Learn more about the Code of Professional Conduct.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.
Nearest Major Market: Chicago
See All 218+ Application Security Engineer Jobs
Jump back to the full list of openings and apply to any application security engineer role that fits.
Find JobsApplication Security Engineer Job Market
A snapshot from current openings nationwide, updated as new roles post.
Who's Hiring
- CVS Health52

- Ryder System44

- Anthropic7

- Google7

- GuidePoint Security5

Top Industries Hiring
- Healthcare & Medical Services53
- Technology & Software45
- Investment & Asset Management12
- Banking & Financial Services8
- Consulting & Professional Services8
What Employers Look For
The qualifications that appear most often in application security engineer jobs.
- Proficiency with SAST, DAST, and SCA tools such as Checkmarx, Veracode, or Snyk
- Experience conducting application penetration testing and vulnerability assessments
- Strong knowledge of secure coding practices across Java, Python, or similar languages
- Familiarity with OWASP Top 10, CWE, and threat modeling methodologies like STRIDE
- Relevant certification such as OSCP, CEH, GWEB, or CSSLP preferred or required
- Bachelor's degree in computer science, information security, or a related technical field
Tips for Your Application Security Engineer Job Search
Tailor your resume to each security domain
Application security covers a wide range of focuses, from SAST and DAST tooling to threat modeling and API security. Rewrite your summary and skills section to match the specific domain each job emphasizes rather than listing every tool you've touched.
Demonstrate findings, not just familiarity
Hiring managers for application security roles want evidence of real impact. Describe specific vulnerabilities you identified, the severity, and what was remediated, not just the tools you used to scan. Concrete outcomes outweigh a long list of acronyms.
Apply early to roles that fit
Migrate Mate lists application security engineer openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Filter for roles by security maturity level
An early-stage startup and a Fortune 500 company both post application security engineer titles, but the scope is completely different. Read the job description for signals like existing AppSec programs, bug bounty ownership, or SDL ownership to gauge the role's actual complexity before you apply.
Prepare a live code review for technical screens
Many application security engineer interviews include a hands-on exercise where you review a short code sample for vulnerabilities. Practice walking through real-world examples in common languages like Python, Java, or Go, narrating your reasoning clearly as you go.
Negotiate scope before you negotiate salary
After an offer, clarify whether the role owns developer enablement, tooling selection, or just reactive review. Roles that own the full secure development lifecycle carry more responsibility and career leverage, and that scope difference matters as much as base compensation when evaluating offers.
Application Security Engineer Jobs: Frequently Asked Questions
Which companies are hiring the most application security engineers?
The companies hiring the most application security engineers right now include CVS Health, Ryder System, and Anthropic, with the largest share of openings in California, New York, and Massachusetts, based on current listings on Migrate Mate as of June 2026. Financial services, cloud infrastructure providers, and large healthcare organizations consistently post a high volume of these roles.
How many application security engineer jobs are remote?
About 32% of application security engineer openings are fully remote or hybrid as of June 2026, making it one of the more remote-friendly engineering specializations. Roles focused on code review, security tooling integration, and developer training tend to be the most likely to allow fully remote arrangements, while positions requiring hands-on red team collaboration are more often on-site.
How do you become an application security engineer?
Start by building a strong foundation in software development, since application security requires reading and reasoning about code across multiple languages. Develop hands-on skills in vulnerability research, penetration testing, and secure design through labs, CTF competitions, and open-source contributions. Pursue a relevant certification such as OSCP or CSSLP, then apply to junior AppSec or security engineering roles to build professional experience.
How do you get hired as an application security engineer with little experience?
Entry points into application security often come through software development or IT security roles rather than direct AppSec hiring. Build a portfolio of vulnerability writeups, bug bounty submissions, or CTF solutions that demonstrate you can identify and explain real security flaws. Targeting companies with formal security rotation programs or junior AppSec associate titles gives you the best starting path.
What does the application security engineer interview process look like?
Most application security engineer interviews include an initial recruiter screen followed by a technical phone interview covering OWASP concepts, common vulnerability classes, and secure design principles. Later rounds typically involve a hands-on exercise where you review code for security issues or walk through a threat model, followed by a final round with security leadership or cross-functional engineering partners.
Where can I find and apply to application security engineer jobs?
You can find and apply to application security engineer jobs on Migrate Mate, which lists current openings from across the United States. Find roles that match your experience level and specialization, then apply directly to each listing from the same place.
See All 218+ Application Security Engineer Jobs
Jump back to the full list of openings and apply to any application security engineer role that fits.
Find Jobs