H-1B Visa Application Security Engineer Jobs
Application Security Engineer roles qualify as H-1B visa specialty occupations under USCIS guidelines, requiring at least a bachelor's degree in computer science, cybersecurity, or a related field. Employers filing H-1B visa petitions for this role must certify a prevailing wage through a DOL Labor Condition Application before your petition can be approved.
Find H-1B Visa Application Security Engineer JobsOverview
Showing 5 of 133+ Application Security Engineer jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 133+ Application Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Application Security Engineer roles.
Get Access To All Jobs
About Brain Co.
Brain Co. is an applied AI startup co-founded by Jared Kushner and Elad Gil, and backed by leading Silicon Valley builders including Patrick Collison and Andrej Karpathy. We are building AI applications for the world's most important institutions, delivering impact on real-world problems across governments, healthcare systems, and critical industries. Our progress so far:
- Automated construction permitting for a sovereign government 80% faster, unlocking $375M+ in value
- Optimized supply chains for a leading global energy company 30% lower cost, 99% reliability, preventing $100M+ in losses
- Streamlined hospital patient care across national health systems 40% better outcomes, 80% less admin work
Company momentum:
- Raised a $55M Series A from leading investors
- Built a team of 70+ AI experts from Tesla, Google DeepMind, NVIDIA, and Databricks
The Role
As our Security Engineer, Application & AI, you will own the security of our products and application layer — secure development practices, agent security, third-party integration security, and data protection for AI products operating in some of the world's most regulated and sensitive environments.
This is a hands-on builder role. You will write code, ship security tooling, and work directly with product and ML engineers to build security in from the start rather than bolt it on after. You are expected to work AI-natively: using AI to write threat models, automate security review, scale code analysis, and build internal tooling. This is not a nice-to-have — it is how the role is designed to operate and how one person can have outsized impact across a fast-moving engineering organization.
Brain Co.'s products are built on agentic infrastructure — AI that takes actions, calls tools, and operates inside complex institutional workflows. The degree varies by product, but the underlying security surface is consistent: how agents are authorized, what they can touch, and how that is controlled at the application layer. This role is specifically designed to address that surface, working alongside the Infrastructure Security Engineer who owns the platform layer underneath.
What You'll Work On
Application Security
- Own secure development practices across our products: AuthN/AuthZ patterns, secrets management, input handling, and secure-by-default standards that engineers can follow without security becoming a bottleneck.
- Integrate security into the development lifecycle — code review, CI/CD pipelines, and pre-deployment checks — catching risk before it reaches production.
- Conduct threat modeling across product features and release cycles, translating risk into concrete controls that ship alongside each product.
- Build and maintain security tooling and automated checks that scale your reach across the codebase — using AI to move faster and cover more ground than manual review alone could.
Agent & Integration Security
- Own the application-layer security model for Brain Co.'s agentic products — how agents are scoped, what they are authorized to do on behalf of users, and where trust boundaries sit between the agent and the external systems it touches.
- Define secure patterns for how agents integrate with third-party systems and APIs: how credentials are stored and scoped, how responses are validated before being acted on, and how each product limits what agents can do with what they get back.
- Work directly with product and ML engineers during feature development to define secure agent design patterns: tool scoping, permission boundaries, output validation, and safe handling of user context across multi-step workflows.
- Build reusable secure-by-default patterns for agent development — design guidelines, review checklists, and code-level guardrails — so that security standards scale as new agent capabilities are built.
- Produce security artifacts for agent features and product deployments: threat models, architecture reviews, and documentation that supports delivery into regulated customer environments.
Data Protection
- Define and enforce data protection standards at the application layer — ensuring sensitive customer data (PHI, PII, government records) is handled correctly as it flows through AI pipelines and surfaces in agent outputs.
- Build safeguards against unauthorized data exposure across our products: access controls, output filtering, and audit logging that make data handling attributable and reviewable.
- Design secure data handling patterns for AI features operating on regulated data, working with platform and ML teams to ensure the application layer upholds its share of the data protection contract.
You Might Be a Great Fit If You...
- Have 5+ years of experience in application security or product security, with hands-on experience on production systems at scale.
- Are a builder first — you write code and ship security tooling, and see embedding security into the engineering workflow as the job, not a side effect of it.
- Have deep fluency in application security fundamentals: OWASP Top 10, AuthN/AuthZ, secure SDLC, secrets management, secure integration patterns, and cryptography basics.
- Understand the security surface of agentic AI across the product layer — how agents should be designed, scoped, and reviewed for risk — and can work shoulder-to-shoulder with engineers to build those standards in.
- Have experience protecting sensitive data at the application layer: access controls, audit logging, and preventing data exposure through third-party integrations and AI-generated outputs.
- Work AI-natively — you already use AI to write better code, move faster, and do more with less, and you bring that same instinct to security work.
- Think in attack surfaces and trust boundaries and can move cleanly from threat model to concrete shipped control.
- Are comfortable working alongside delivery teams shipping into regulated industries, understanding their constraints and translating them into product-level security requirements.
- Thrive in high-agency environments and want to own and grow the application security function as the company scales.
Bonus Points For
- Experience with agent security, LLM application security, or building authorization and guardrail systems for agentic pipelines.
- Familiarity with compliance frameworks relevant to government and healthcare: FedRAMP, HIPAA, SOC 2, ISO 27001.
- Proficiency in Python, Go, or TypeScript for security tooling and automation.
- Experience with SAST/DAST tooling or integrating automated security checks into developer workflows at scale.
Why Join Us
- Define what application and AI security looks like at a company building frontier AI for governments, hospitals, and critical industries — from the ground up.
- Work directly alongside product and ML teams shipping agentic AI into some of the world's most demanding institutional environments.
- Build the security function AI-natively — using the same technology you're helping secure to scale your own work and impact.
- Work alongside senior engineers from Tesla, DeepMind, Databricks, and other top engineering organizations.
- Ship fast, learn constantly, and see your work protect production systems used by millions of people.
- Earn competitive compensation and meaningful equity in a high-growth company.
Benefits
- Competitive salary plus equity
- Daily lunches
- Commuter benefits
- 401(k)
- Medical, Dental, and Vision
- Unlimited PTO
See all 133+ H-1B Visa Application Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new H-1B Visa Application Security Engineer Jobs.
Get Access To All JobsTips for Finding H-1B Visa Sponsorship as an Application Security Engineer
Map your degree to the SOC code
USCIS evaluates specialty occupation eligibility by matching your degree field to the job's SOC code. For Application Security Engineer roles, the relevant O*NET profile lists computer science, information security, and software engineering as qualifying degree fields.
Verify the prevailing wage before accepting
Run the OFLC Wage Search using the Application Security Engineer SOC code and the employer's worksite zip code. If the offered salary falls below the Level I or Level II wage, the DOL will reject the LCA and block your H-1B filing.
Target E-Verify enrolled employers early
STEM-adjacent roles like Application Security Engineer attract employers already enrolled in E-Verify, which is required for any sponsor filing cap-subject H-1B petitions. Filter your search on Migrate Mate to surface employers with active H-1B LCA filing history in security roles.
Document hands-on security certifications strategically
USCIS RFEs for security engineer roles often challenge whether the position truly requires a specific degree rather than broad IT experience. Certifications like OSCP, CEH, or CISSP strengthen the specialty occupation argument when your job duties include penetration testing or secure architecture design.
Confirm the employer files cap-subject or cap-exempt petitions
Universities, nonprofit research organizations, and government-affiliated entities can file cap-exempt H-1B petitions year-round with no lottery. If you're already on OPT, a cap-exempt employer in application security gives you an H-1B path outside the annual registration window.
Negotiate premium processing into your offer timeline
Application Security Engineer roles often involve security clearance timelines or project start dates that can't wait five to seven months for standard USCIS adjudication. Ask the employer to include premium processing in the offer letter before you sign, not after.
H-1B Visa Application Security Engineer: Frequently Asked Questions
Does an Application Security Engineer role qualify as an H-1B specialty occupation?
Yes. USCIS classifies Application Security Engineer positions as specialty occupations because the role normally requires a bachelor's degree or higher in computer science, cybersecurity, software engineering, or a closely related field. Employers strengthen the petition by documenting that the specific duties, including threat modeling, code review, or penetration testing, require that theoretical and practical expertise.
Which employers actively sponsor H-1B visas for Application Security Engineer roles?
Technology companies, financial institutions, cloud infrastructure providers, and defense contractors are the most active H-1B sponsors for Application Security Engineer positions, based on DOL LCA disclosure data. Migrate Mate surfaces employers with verified H-1B filing history in security engineering roles, so you can prioritize outreach to organizations that have already navigated the sponsorship process.
Can I transfer my H-1B to a new employer for an Application Security Engineer position?
Yes. Under H-1B portability rules, you can start working for a new employer as soon as the new I-129 petition is filed with USCIS, without waiting for approval, as long as you've been in valid H-1B status for at least 180 days. The new employer must file a fresh LCA certified to the Application Security Engineer wage level at the new worksite location.
How does the DOL prevailing wage apply to Application Security Engineer H-1B filings?
Before filing your H-1B petition, your employer must submit an LCA to the DOL certifying they'll pay at least the prevailing wage for Application Security Engineer roles in the worksite's metropolitan area. Wages are set at four levels based on experience and complexity. You can verify the applicable wage using the OFLC Wage Search before evaluating any offer.
What documentation should I prepare if USCIS issues an RFE for my Application Security Engineer H-1B?
RFEs for security engineer roles typically challenge either specialty occupation status or the degree-to-job-duty match. Prepare a detailed job duty breakdown showing that the role requires security-specific theoretical knowledge, not just general IT skills. Supporting evidence includes org charts showing the role alongside other degreed engineers, job postings for similar roles, and industry standards from professional bodies like NIST or ISC2.