Application Security Engineer Jobs in California
Application Security Engineer jobs in California are among the most active in the country, with strong demand concentrated in enterprise software, cloud infrastructure, fintech, and defense contracting, and openings at every level from associate to principal. San Francisco, San Jose, and Los Angeles account for the largest share of postings, where major employers including Google, Apple, and Northrop Grumman maintain deep engineering teams with ongoing security hiring. The most sought-after specialties in California are cloud-native application security, secure software development lifecycle engineering, and penetration testing for web and mobile platforms. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 21+ Application Security Engineer jobs











INTRODUCTION
To help keep everyone safe, we encourage all applicants to pay close attention to protect themselves during their job search. When applying for a position online you are at risk of being targeted by malicious actors looking for personal data. Please be aware we will only reach out via email using the domain quanata.com. Anything that does not match those domains should be ignored and considered a security risk.
About us
Quanata is on a mission to help ensure a better world through context-based insurance solutions. We are an exceptional, customer centered team with a passion for creating innovative technologies, digital products, and brands. We blend some of the best Silicon Valley talent and cutting-edge thinking with the long-term backing of leading insurer, State Farm.
Learn more about us and our work at quanata.com.
OUR TEAM
Quanata, LLC is an insurance technology innovation company that engineers advanced risk prediction and prevention solutions, develops risk-focused acquisition capabilities, and builds/supports a full-stack, flexible, digital & increasingly AI-native insurance platform. This helps our primary clients, State Farm and HiRoad Assurance Company, adapt to evolving market needs. Quanata, LLC is wholly owned and funded by State Farm.
As a company that prioritizes an inclusive and positive culture, we believe the core of our success is in hiring talented people — across disciplines — who want to help us make a quantifiable impact.
THE ROLE
We're looking for an Application Security Engineer to help build secure-by-default products and services across Quanata's AI-native insurance technology platform. In this role, you'll partner closely with Product, Engineering, and Security teams to identify risks early, strengthen secure development practices, and ensure our applications are resilient, scalable, and compliant.
You'll play a key role in embedding security throughout the software development lifecycle while helping teams move quickly and safely.
YOUR DAY-TO-DAY
- Partner with Product and Engineering teams to integrate security into application design and development
- Lead threat modeling exercises and identify practical security solutions for complex systems
- Conduct secure code reviews, application security assessments, and vulnerability analysis
- Develop and implement automated security guardrails across the SDLC
- Investigate, prioritize, and drive remediation of application security findings
- Promote secure coding practices through training, coaching, and awareness initiatives
- Collaborate with Security, Privacy, and Business Assurance teams to support compliance and risk management objectives
- Create and maintain security standards, procedures, and best practices that scale across teams
ABOUT YOU
- Associate's degree or equivalent experience required; Bachelor's degree preferred
- 4–6+ years of experience in software engineering, including at least 2 years focused on application security
- Experience partnering directly with software development teams to improve application security
- Knowledge of secure-by-design principles and modern application security practices
- Familiarity with OWASP Top 10, ASVS, MASVS, and common application security frameworks
- Experience with threat modeling methodologies such as STRIDE, PASTA, or similar approaches
- Working knowledge of cloud platforms and modern application architectures
- Proficiency in at least one programming language and its security ecosystem
- Strong communication skills and the ability to influence technical and non-technical stakeholders
- Comfortable operating in a fast-paced environment with shifting priorities
BONUS POINTS
- Security certifications such as CSSLP, GWEB, OSWE, or similar
- Experience working in insurance, financial services, healthcare, or other regulated industries
- Advanced knowledge of cloud security and application security architecture
- Experience with mobile application security, QA testing, or penetration testing
- Familiarity with AI technologies, LLM security, or prompt engineering
- Experience building scripts or automations to streamline security processes
- Active involvement in the security community through conferences, mentoring, presentations, publications, or open-source contributions
SALARY
- Salary: $175,000 to $215,000*
Please note that the final salary offered will be determined based on the selected candidate's skills, and experience, as well as the internal salary structure at Quanata. Our aim is to offer a competitive and equitable compensation package that reflects the candidate's expertise and contributions to our organization.
ADDITIONAL DETAILS
-
Benefits: We provide a wide variety of health, wellness and other benefits. These include medical, dental, vision, life insurance and supplemental income plans for you and your dependents, a Headspace app subscription, monthly wellness allowance and a 401(k) Plan with a company match.
-
Work from Home Equipment: Given our virtual environment— in order to set you up for success at home, a one-time payment of $2K will be provided to cover the purchase of in-home office equipment and furniture at your discretion. Also, our teams work with MacBook Pros, which we will deliver to you fully provisioned prior to your first day.
-
Paid Time Off: All employees accrue four weeks of PTO in their first year of employment. New parents receive twelve weeks of fully paid parental leave which may be taken within one year after the birth and/or adoption of a child. The twelve weeks is applicable to both birthing and non-birthing parent.
-
Personal and Professional Development: We're committed to investing in and helping our people grow personally and professionally. All employees receive up to $5000 each year for professional learning, continuing education and career development. All team members also receive LinkedIn Learning subscriptions and access to multiple different coaching opportunities through BetterUp.
LOCATION
We are a remote-first company for most positions so you may work from anywhere you like in the U.S, excluding U.S. territories. For most positions, occasional travel may be requested or encouraged but is not required. Some positions might require travel per the job description provided to the employee. Employees based in the San Francisco Bay Area or in Providence, Rhode Island may commute to one of our local offices as desired.
HOURS
We maintain core meeting hours from 9AM - 2PM Pacific time for collaborating with team members across all time zones.
Quanata, LLC is an equal opportunity workplace. We are committed to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
If you are a San Francisco resident, please read the City and County of San Francisco's Fair Chance Ordinance notice.
This role is employed by Quanata, LLC which is a separate company in the State Farm family of companies.
If you require a reasonable accommodation, please reach out to your Talent Acquisition Partner for assistance.
See All 21 Application Security Engineer Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find JobsApplication Security Engineer Jobs by City in California
Where California roles are concentrated, by current openings.
Application Security Engineer Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring
- Xai3

- Tatari2

- Anthropic1

- BRAIN1

- Butler Labs1

Top Industries Hiring
- Technology & Software10
- Investment & Asset Management2
- Marketing & Advertising2
- Artificial Intelligence1
- Consulting & Professional Services1
What California Employers Look For
The qualifications that appear most often in application security engineer jobs across California.
- Bachelor's degree in computer science, cybersecurity, or a closely related engineering field
- Hands-on experience with secure SDLC practices, threat modeling, and code review
- Proficiency in at least one major programming language such as Python, Java, or Go
- Industry certifications such as OSCP, CSSLP, or CEH recognized by California employers
- Experience with cloud security on AWS, Google Cloud, or Azure in production environments
- Familiarity with OWASP Top Ten, SAST and DAST tooling, and vulnerability management workflows
Application Security Engineer Jobs in California: Frequently Asked Questions
How do you become a application security engineer in California?
Application security engineering is not a state-licensed profession in California, so there is no California-specific exam or registration required to work in the role. The standard path is a bachelor's degree in computer science, software engineering, or cybersecurity followed by experience in software development or IT security. California employers consistently value vendor-neutral certifications such as OSCP or CSSLP alongside a demonstrable portfolio of security work, such as bug bounty findings or open-source contributions.
How much do application security engineers make in California?
Application security engineers in California earn a median of about $174,410 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $105,060 for the lowest 10% to over $272,670 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire application security engineers in California?
Employers hiring application security engineers in California right now include Xai, Tatari, and Anthropic, based on current listings on Migrate Mate as of June 2026. California's concentration of large technology headquarters, defense contractors, and regulated fintech companies means security engineering roles turn over frequently and appear across a wide range of employer sizes.
Which California cities have the most application security engineer jobs?
San Francisco, Palo Alto, and Menlo Park are the California cities with the most application security engineer openings, reflecting the Bay Area's density of enterprise software companies and cloud providers, Los Angeles's growing cybersecurity and aerospace sector, and San Diego's established defense and biotech industry that demands rigorous application security compliance.
Are there remote application security engineer jobs in California?
Yes, and more than most fields. Application security engineering is fundamentally desk and code-based work, which makes it well suited to remote arrangements. About 48% of application security engineer openings tied to California are remote or hybrid as of June 2026, reflecting how broadly distributed engineering teams have become across the state. Code review, threat modeling, and security tooling integration are the tasks most commonly performed fully remote.
How can I get hired as a application security engineer in California with little or no experience?
The most realistic entry path is moving laterally from a software development or IT operations role into a security-focused position such as security analyst or junior penetration tester. Large California technology companies including those headquartered in the Bay Area and Los Angeles run associate security engineer programs and internship pipelines that prioritize candidates without full-time security experience. Building a portfolio through bug bounty platforms, contributing to open-source security tools, or completing a recognized certification like CompTIA Security+ or OSCP gives California candidates a concrete edge when competing for these entry roles.
Where can I find and apply to application security engineer jobs in California?
You can find and apply to application security engineer jobs in California on Migrate Mate, which lists current California openings updated in real time. Find the roles that fit your experience and location, then apply directly to each employer through the listing.
See All 21 Application Security Engineer Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Jobs