Application Security Engineer Jobs in Massachusetts
Application Security Engineer jobs in Massachusetts are among the most active in the country, concentrated in financial services, biotech, defense contracting, and enterprise software across Greater Boston, Cambridge, and Worcester. Employers like Raytheon Technologies, Fidelity Investments, and Liberty Mutual maintain deep security engineering teams in the state, hiring from early-career roles through principal and staff levels. The most in-demand specialties are secure software development lifecycle, cloud security architecture, and penetration testing. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 11+ Application Security Engineer jobs











Join us as we work to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all.
athenahealth is seeking a Lead Security Engineer to help increase the security capabilities of its teams. This role works closely with scrum teams, product managers, and engineering leadership to improve the quality and adoption of Security Development Lifecycle practices, with a strong emphasis on API security.
This position owns the technical direction, implementation, and operation of security capabilities and is suited for someone who enjoys setting technical strategy, influencing stakeholders, and defining measurable security outcomes.
About the Team
This team solves application security problems at scale and partners across engineering and security functions to help protect athenahealth’s products and platforms. The work combines security engineering, software development, and cross-functional communication to support secure product delivery in a healthcare environment.
Core Responsibilities
Security strategy and SDLC adoption
Socialize and drive execution of key security best practices across the R&D organization.
Contribute to the enterprise security catalog of best practices, techniques, and patterns.
Improve the quality and adoption of Security Development Lifecycle practices.
Application security capability ownership
Own the evaluation, design, implementation, integration, reliability, and continuous improvement of application security capabilities.
Support SAST, SCA, DAST, API security testing, and vulnerability management workflows.
Document, share, and help automate coverage for common abuse cases and attacks.
API security program leadership
Lead the API security testing program.
Manage API discovery, authenticated and unauthenticated testing, scanner attribution, onboarding, exclusions, ownership mapping, findings routing, and operational readiness.
Identify and explain feature-level design or architectural weaknesses that could create security issues.
Cross-functional partnership and issue management
Partner with enterprise security leadership to track and prioritize open issues and follow through on resolution.
Work with DevOps, Infrastructure, IAM, API Gateway, NOC, Enterprise Security, and application teams to design and operate security-hardened platforms.
Required Experience & Skills
Bachelor’s degree in Computer Science, Computer Engineering, Cyber Security, or similar, or equivalent experience.
At least 3 years of experience as a software developer and 3–5 years in a security-focused development role in an agile environment.
Experience in software and product design and architecture, product security, and security issue prevention and mitigation.
Strong software engineering background with the ability to develop, review, and troubleshoot code in one or more languages.
Practical experience with Docker and Terraform.
Strong knowledge of OAuth 2.0, OpenID Connect, JWT, SAML, and service-to-service authentication.
Solid understanding of RESTful services, service bus architectures, JSON, and related web services concepts.
Experience with SAST, SCA, DAST, API security testing, vulnerability aggregation, and CI/CD security controls.
Hands-on experience with cloud platforms, containers, infrastructure as code, secrets management, and CI/CD.
Knowledge of HIPAA, HITRUST, and PCI-DSS is a plus.
Why This Role Matters
This role is central to strengthening secure software delivery across athenahealth. It combines technical depth, security leadership, and cross-functional influence to improve how security is built into products from the start.
Expected Compensation
The base salary range shown reflects the full range for this role from minimum to maximum. At athenahealth, base pay depends on multiple factors, including job-related experience, relevant knowledge and skills, how your qualifications compare to others in similar roles, and geographical market rates. Base pay is only one part of our competitive Total Rewards package - depending on role eligibility, we offer both short and long-term incentives by way of an annual discretionary bonus plan, variable compensation plan, and equity plans.
About athenahealth
Our vision: In an industry that becomes more complex by the day, we stand for simplicity. We offer IT solutions and expert services that eliminate the daily hurdles preventing healthcare providers from focusing entirely on their patients — powered by our vision to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all.
Our company culture: Our talented employees — or athenistas, as we call ourselves — spark the innovation and passion needed to accomplish our vision. We are a diverse group of dreamers and do-ers with unique knowledge, expertise, backgrounds, and perspectives. We unite as mission-driven problem-solvers with a deep desire to achieve our vision and make our time here count. Our award-winning culture is built around shared values of inclusiveness, accountability, and support.
Our DEI commitment: Our vision of accessible, high-quality, and sustainable healthcare for all requires addressing the inequities that stand in the way. That's one reason we prioritize diversity, equity, and inclusion in every aspect of our business, from attracting and sustaining a diverse workforce to maintaining an inclusive environment for athenistas, our partners, customers and the communities where we work and serve.
What we can do for you:
Along with health and financial benefits, athenistas enjoy perks specific to each location, including commuter support, employee assistance programs, tuition assistance, employee resource groups, and collaborative workspaces — some offices even welcome dogs.
We also encourage a better work-life balance for athenistas with our flexibility. While we know in-office collaboration is critical to our vision, we recognize that not all work needs to be done within an office environment, full-time. With consistent communication and digital collaboration tools, athenahealth enables employees to find a balance that feels fulfilling and productive for each individual situation.
In addition to our traditional benefits and perks, we sponsor events throughout the year, including book clubs, external speakers, and hackathons. We provide athenistas with a company culture based on learning, the support of an engaged team, and an inclusive environment where all employees are valued.
Learn more about our culture and benefits here: athenahealth.com/careers
https://www.athenahealth.com/careers/equal-opportunity
See All 11 Application Security Engineer Jobs in Massachusetts
Find roles in Massachusetts that match your experience and apply in just a few clicks.
Find JobsApplication Security Engineer Jobs by City in Massachusetts
Where Massachusetts roles are concentrated, by current openings.
Application Security Engineer Job Market in Massachusetts
A snapshot from current Massachusetts openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Technology & Software
- Manufacturing
What Massachusetts Employers Look For
The qualifications that appear most often in application security engineer jobs across Massachusetts.
- Bachelor's degree in computer science, cybersecurity, or a closely related engineering field
- Hands-on experience with SAST, DAST, and software composition analysis tooling
- Proficiency in at least one programming language such as Python, Java, or Go
- Industry certification such as CISSP, CEH, or CSSLP recognized by Massachusetts employers
- Familiarity with OWASP Top 10, threat modeling, and secure code review practices
- Experience working within regulated environments including financial services or defense contracting
Application Security Engineer Jobs in Massachusetts: Frequently Asked Questions
How do you become a application security engineer in Massachusetts?
Most application security engineers in Massachusetts enter the field with a bachelor's degree in computer science, information security, or software engineering, followed by experience in software development or IT security. Massachusetts does not require a state-issued license for this role. Employers across Greater Boston typically look for candidates who hold industry-recognized certifications such as CISSP or CEH and can demonstrate hands-on experience with secure development practices or penetration testing.
How much do application security engineers make in Massachusetts?
Application security engineers in Massachusetts earn a median of about $165,210 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $102,810 for the lowest 10% to over $213,970 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire application security engineers in Massachusetts?
Employers hiring application security engineers in Massachusetts right now include Datadog, Epsilon, and CarGurus, based on current listings on Migrate Mate as of September 2026. Massachusetts's concentration of financial institutions, defense contractors, and health technology firms means demand is consistent and spread across a range of industries rather than concentrated in a single sector.
Which Massachusetts cities have the most application security engineer jobs?
Boston, Massachusetts, and Quincy have the most application security engineer openings in Massachusetts. Boston and Cambridge drive the largest share, anchored by financial services firms, biotech companies, and major universities with affiliated research and technology operations, while Worcester has grown as a secondary hub through its expanding defense and health technology employer base.
Are there remote application security engineer jobs in Massachusetts?
Yes, and more than most fields. About 86% of application security engineer openings tied to Massachusetts are remote or hybrid as of September 2026, reflecting the desk-based and code-centric nature of the work. Roles focused on secure code review, threat modeling, and vulnerability assessment are the most likely to be offered fully remote, while positions requiring lab access or on-site red team work tend to require in-person presence.
How can I get hired as a application security engineer in Massachusetts with little or no experience?
The most realistic entry path is moving laterally from a software development or IT operations role, since Massachusetts employers like Fidelity, Liberty Mutual, and major defense contractors regularly hire associate security engineers from their own developer or systems administrator ranks. Building a portfolio of capture-the-flag challenges and contributing to open-source security tooling helps demonstrate ability. Pursuing a CEH or CompTIA Security+ certification and targeting rotational programs at large Boston-area financial or technology firms accelerates the transition.
Where can I find and apply to application security engineer jobs in Massachusetts?
You can find and apply to application security engineer jobs in Massachusetts on Migrate Mate, which lists current Massachusetts openings. Find the roles that fit your experience and apply directly to the ones that match.
See All 11 Application Security Engineer Jobs in Massachusetts
Find roles in Massachusetts that match your experience and apply in just a few clicks.
Find Jobs