Application Security Engineer Jobs in Massachusetts
Application Security Engineer jobs in Massachusetts are open across Boston and other Massachusetts metros, with employers like State Street, Berkshire Hathaway Specialty Insurance, and CVS Health hiring at every experience level. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 8+ Application Security Engineer jobs











Job Description Summary
For over forty years, HarbourVest has been home to a committed team of professionals with an entrepreneurial spirit and a desire to deliver impactful solutions to our clients and investing partners. As our global firm grows, we continue to add individuals who seek a collaborative, open-door culture that values diversity and innovative thinking.
In our collegial environment that’s marked by low turnover and high energy, you’ll be inspired to grow and thrive. Here, you will be encouraged to build on your strengths and acquire new skills and experiences.
We are committed to fostering an environment of inclusion that promotes mutual respect among all employees. Understanding and valuing these differences optimizes the potential of both the individual and the firm.
HarbourVest is an equal opportunity employer.
This position will be a hybrid work arrangement. You will receive 18 remote workdays per quarter to use at your discretion, subject to manager approval. For example, you may choose to work in the office 4 days per week and take one remote day weekly (typically 13 weeks per quarter), leaving 5 additional remote days to be used as needed.
As a key member of the Security Engineering team, this person will help lead HarbourVest’s Application Security program. The Application Security Engineer (ASE) will serve in a multi-functional role, advising development teams on secure coding and accepted industry procedures. The ASE is responsible for leading SDLC initiatives that include secure code reviews, architecture assessments, and application scanning methods. They will provide end-to-end leadership for application security, working closely within platform teams to advocate for and enhance a strong program focused on application security. In this role, they will help uphold and continuously improve HarbourVest’s high security standards across infrastructure, applications, and operational processes.
The ideal candidate is someone who is:
- Dedicated to protecting sensitive financial data, client information, and critical business systems
- Skilled in navigating regulated financial services settings
- Able to assess and prioritize security concerns by considering their effect on business and financial outcomes
- A collaborative partner to engineering, risk, compliance, and audit teams
- Proactive, diligent, and calm when responding to security incidents
What you will do:
- Identify risks and areas of exposure in applications, SDLC processes, and architecture
- Define guardrails, standards, and secure usage patterns for agentic AI–based coding tools, enabling engineering teams to adopt them safely while managing data exposure, code quality, and security risk
- Perform secure build reviews, threat modeling, and application security testing (SAST, DAST, SCA)
- Identify, assess, and support remediation of vulnerabilities in web applications and APIs
- Partner with engineering teams to promote secure coding standards utilizing CI/CD pipelines and DevSecOps practices
- Support audits, regulatory exams, penetration tests, and security incident response
- Secure and continuously monitor third-party SaaS applications using SSPM tools, ensuring configurations, access controls, and integrations meet HarbourVest security standards
- Establish metrics and reporting to track coverage and effectiveness of security processes
- Enable developers through secure coding guidance, training, and tooling
- And other responsibilities as required!
What you bring:
- Solid understanding of application security principles and OWASP Top 10 risks
- Experience securing web applications, APIs, and microservices in financial environments
- Hands-on experience with AI-assisted coding tools such as Cursor, GitHub Copilot, and ChatGPT Codex, with an understanding of their security implications in enterprise software development
- Proficiency reviewing code in at least one common language (Java, Python, C#, or JavaScript)
- Familiarity with cloud platforms, containers, IaaC, and modern DevSecOps tooling
- Ability to clearly communicate technical risk to both technical and non-technical collaborators
Education Preferred:
- Bachelor’s degree or equivalent experience in Computer Science, Information Security, or a related field
- Security certifications such as CISSP, CSSLP, OSCP, GWAPT, or similar are a plus
Experience:
- 3-5 years of experience in application security or secure software development
- Experience working in controlled sectors such as finance, banking, or fintech
- Exposure to compliance frameworks (e.g., SOC 2, SOX, PCI DSS, GDPR)
LI-Hybrid
Base Salary Range:
$145,000.00 - $155,000.00
This USD base salary range represents only one component of total compensation for this role and is provided in accordance with local requirements. This role is eligible for a discretionary annual bonus, which is determined based on individual and overall firm performance. In addition to salary and bonus, total compensation may include eligibility for long-term reward programs and a comprehensive total rewards package that may include retirement, health, insurance, paid time off, and wellness programs. Our total rewards offerings are influenced by several business factors, and eligibility for certain components will vary by position and geography. Please note the posted ranges do not apply outside the U.S. and should not be converted to other currencies as a proxy for compensation in other countries.
See All 8 Application Security Engineer Jobs in Massachusetts
Find roles in Massachusetts that match your experience and apply in just a few clicks.
Find JobsApplication Security Engineer Jobs by City in Massachusetts
Where Massachusetts roles are concentrated, by current openings.
Application Security Engineer Job Market in Massachusetts
A snapshot from current Massachusetts openings, updated as new roles post.
Who's Hiring
- State Street2

- Berkshire Hathaway Specialty Insurance1

- CVS Health1

- Datadog1

- HarbourVest1

Top Industries Hiring
- Banking & Financial Services2
- Technology & Software2
- Consulting & Professional Services1
- Healthcare & Medical Services1
- Insurance1
What Massachusetts Employers Look For
The qualifications that appear most often in application security engineer jobs across Massachusetts.
- Proficiency with SAST, DAST, and SCA tools such as Checkmarx, Veracode, or Snyk
- Experience conducting application penetration testing and vulnerability assessments
- Strong knowledge of secure coding practices across Java, Python, or similar languages
- Familiarity with OWASP Top 10, CWE, and threat modeling methodologies like STRIDE
- Relevant certification such as OSCP, CEH, GWEB, or CSSLP preferred or required
- Bachelor's degree in computer science, information security, or a related technical field
Application Security Engineer Jobs in Massachusetts: Frequently Asked Questions
How many application security engineer jobs are there in Massachusetts?
There are 8+ application security engineer openings in Massachusetts on Migrate Mate as of June 2026, with the most roles in Boston. New positions post regularly as employers across Massachusetts hire.
How much do application security engineers make in Massachusetts?
Application security engineers in Massachusetts earn a median of about $165,210 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $102,810 for the lowest 10% to over $213,970 for the top 10%. Pay rises with experience, specialty, and employer.
Which Massachusetts cities have the most application security engineer jobs?
Boston have the most application security engineer openings in Massachusetts right now, with additional roles spread across smaller metros statewide.
Which companies hire application security engineers in Massachusetts?
Employers hiring application security engineers in Massachusetts include State Street, Berkshire Hathaway Specialty Insurance, and CVS Health, based on current listings on Migrate Mate as of June 2026.
Are there remote application security engineer jobs in Massachusetts?
Yes. About 38% of application security engineer openings tied to Massachusetts are remote or hybrid as of June 2026. The rest are on-site roles based in Massachusetts metros.
How do I apply for application security engineer jobs in Massachusetts?
You can apply to application security engineer jobs in Massachusetts directly on Migrate Mate. Search the listings above, find roles that match your experience and preferred Massachusetts location, then apply to each one that fits.
See All 8 Application Security Engineer Jobs in Massachusetts
Find roles in Massachusetts that match your experience and apply in just a few clicks.
Find Jobs