H-1B Visa Application Security Engineer Jobs
Application Security Engineer roles qualify as H-1B specialty occupations under USCIS guidelines, requiring at least a bachelor's degree in computer science, cybersecurity, or a related field. Employers filing H-1B petitions for this role must certify a prevailing wage through a DOL Labor Condition Application before your petition can be approved.
See All Application Security Engineer JobsOverview
Showing 5 of 160+ Application Security Engineer jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 160+ Application Security Engineer jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Application Security Engineer roles.
Get Access To All Jobs
INTRODUCTION
Heartflow is a medical technology company advancing the diagnosis and management of coronary artery disease, the #1 cause of death worldwide, using cutting-edge technology. The flagship product—an AI-driven, non-invasive cardiac test supported by the ACC/AHA Chest Pain Guidelines called the Heartflow FFRCT Analysis—provides a color-coded, 3D model of a patient’s coronary arteries indicating the impact blockages have on blood flow to the heart. Heartflow is the first AI-driven non-invasive integrated heart care solution across the CCTA pathway that helps clinicians identify stenoses in the coronary arteries (RoadMap™Analysis), assess coronary blood flow (FFRCT Analysis), and characterize and quantify coronary atherosclerosis (Plaque Analysis). Our pipeline of products is growing and so is our team; join us in helping to revolutionize precision heartcare. Heartflow is a publicly traded company (HTFL) that has received international recognition for exceptional strides in healthcare innovation, is supported by medical societies around the world, cleared for use in the US, UK, Europe, Japan and Canada, and has been used for more than 500,000 patients worldwide.
We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC). In this role, you’ll have the chance to use your security and software development background to protect patients as we build products that leverage AI to improve healthcare. If you enjoy working with talented engineers to solve complex technical challenges and want to see your work make a direct difference in patient outcomes, we encourage you to apply. This role is a hybrid, requiring three days a week in our San Francisco office.
ROLE AND RESPONSIBILITIES
What You’ll Do:
- Partner with the engineering team to provide hands-on technical guidance to software developers throughout the vulnerability remediation lifecycle. Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
- Drive vulnerability identification using SAST, DAST, SCA and in-house AI tooling and manage external penetration testing.
- Support engineering team on vulnerability management, including risk assessment, remediation, improving identification of vulnerabilities and translate security and privacy requirements into technical requirements.
- Build security awareness through training on secure coding practices, security standards and latest security threats.
BASIC QUALIFICATIONS
What You Bring:
- Security Communication – Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences. Experience leading training, speaking internally/externally about security projects valued.
- Programming Skills – Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python). Comfortable with testing frameworks and CI/CD pipelines.
- AI Development Tools – Experience using AI code tools such as Claude Code and Github Copilot for development and security testing.
- Education & Experience – BS in Computer Science (or related degree) or relevant certifications and equivalent experience. 5+ years of total experience with at least 1 year working in Application Security or performing security tasks in a development role.
- Securing SDLC – Have contributed to secure SDLC activities, including threat modeling, code review, security testing and vulnerability management.
- Knowledge of Modern AI Security Threats – Experience working with or ability to discuss current AI threats for both machine learning and generative AI.
PREFERRED QUALIFICATIONS
What Helps You Stand Out:
- Healthcare Experience – Current knowledge of HIPAA, HITRUST and the complexities of working in a regulated environment. Experience with Software as a Medical Device (SaMD) is especially valuable.
- Infrastructure as Code & Cloud – Familiarity with AWS (or equivalent cloud providers) and configuration tools (Terraform, Chef, Ansible). Experience with containerization (Docker, Kubernetes) and orchestration (GitHub Actions or similar).
COMPENSATION
A reasonable estimate of the base salary compensation range is $145,000 to $180,000 per year, bonus, and equity.
Heartflow is an Equal Opportunity Employer. We are committed to a work environment that supports, inspires, and respects all individuals and do not discriminate against any employee or applicant because of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law. This policy applies to every aspect of employment at Heartflow, including recruitment, hiring, training, relocation, promotion, and termination.
Positions posted for Heartflow are not intended for or open to third party recruiters / agencies. Submission of any unsolicited resumes for these positions will be considered to be free referrals.
Heartflow has become aware of a fraud where unknown entities are posing as Heartflow recruiters in an attempt to obtain personal information from individuals as part of our application or job offer process. Before providing any personal information to outside parties, please verify the following: A) all legitimate Heartflow recruiter email addresses end with “@heartflow.com” and B) the position described is found on our careers site at www.heartflow.com/about/careers/.
See all 160+ Application Security Engineer jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Application Security Engineer roles.
Get Access To All JobsTips for Finding H-1B Visa Sponsorship as an Application Security Engineer
Map your degree to the SOC code
USCIS evaluates specialty occupation eligibility by matching your degree field to the job's SOC code. For Application Security Engineer roles, the relevant O*NET profile lists computer science, information security, and software engineering as qualifying degree fields.
Verify the prevailing wage before accepting
Run the OFLC Wage Search using the Application Security Engineer SOC code and the employer's worksite zip code. If the offered salary falls below the Level I or Level II wage, the DOL will reject the LCA and block your H-1B filing.
Target E-Verify enrolled employers early
STEM-adjacent roles like Application Security Engineer attract employers already enrolled in E-Verify, which is required for any sponsor filing cap-subject H-1B petitions. Filter your search on Migrate Mate to surface employers with active H-1B LCA filing history in security roles.
Document hands-on security certifications strategically
USCIS RFEs for security engineer roles often challenge whether the position truly requires a specific degree rather than broad IT experience. Certifications like OSCP, CEH, or CISSP strengthen the specialty occupation argument when your job duties include penetration testing or secure architecture design.
Confirm the employer files cap-subject or cap-exempt petitions
Universities, nonprofit research organizations, and government-affiliated entities can file cap-exempt H-1B petitions year-round with no lottery. If you're already on OPT, a cap-exempt employer in application security gives you an H-1B path outside the annual registration window.
Negotiate premium processing into your offer timeline
Application Security Engineer roles often involve security clearance timelines or project start dates that can't wait five to seven months for standard USCIS adjudication. Ask the employer to include premium processing in the offer letter before you sign, not after.
Application Security Engineer jobs are hiring across the US. Find yours.
Find Application Security Engineer JobsApplication Security Engineer H-1B Visa: Frequently Asked Questions
Does an Application Security Engineer role qualify as an H-1B specialty occupation?
Yes. USCIS classifies Application Security Engineer positions as specialty occupations because the role normally requires a bachelor's degree or higher in computer science, cybersecurity, software engineering, or a closely related field. Employers strengthen the petition by documenting that the specific duties, including threat modeling, code review, or penetration testing, require that theoretical and practical expertise.
Which employers actively sponsor H-1B visas for Application Security Engineer roles?
Technology companies, financial institutions, cloud infrastructure providers, and defense contractors are the most active H-1B sponsors for Application Security Engineer positions, based on DOL LCA disclosure data. Migrate Mate surfaces employers with verified H-1B filing history in security engineering roles, so you can prioritize outreach to organizations that have already navigated the sponsorship process.
Can I transfer my H-1B to a new employer for an Application Security Engineer position?
Yes. Under H-1B portability rules, you can start working for a new employer as soon as the new I-129 petition is filed with USCIS, without waiting for approval, as long as you've been in valid H-1B status for at least 180 days. The new employer must file a fresh LCA certified to the Application Security Engineer wage level at the new worksite location.
How does the DOL prevailing wage apply to Application Security Engineer H-1B filings?
Before filing your H-1B petition, your employer must submit an LCA to the DOL certifying they'll pay at least the prevailing wage for Application Security Engineer roles in the worksite's metropolitan area. Wages are set at four levels based on experience and complexity. You can verify the applicable wage using the OFLC Wage Search before evaluating any offer.
What documentation should I prepare if USCIS issues an RFE for my Application Security Engineer H-1B?
RFEs for security engineer roles typically challenge either specialty occupation status or the degree-to-job-duty match. Prepare a detailed job duty breakdown showing that the role requires security-specific theoretical knowledge, not just general IT skills. Supporting evidence includes org charts showing the role alongside other degreed engineers, job postings for similar roles, and industry standards from professional bodies like NIST or ISC2.
See which Application Security Engineer employers are hiring and sponsoring visas right now.
Search Application Security Engineer Jobs