Remote Application Security Engineer Jobs
Remote application security engineer jobs are open across the U.S. at remote-first firms, distributed tech teams, and security-focused companies in software, fintech, healthcare, and defense contracting. Employers hiring remotely right now include Affirm, Akumin, and Kastle Systems. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 307+ Remote Application Security Engineer jobs











Employment Type:
Full time
Shift:
Description:
The primary responsibility of the Consultant Applications and Offensive Security is to design, build, and operationalize a Secure Coding Center of Excellence (CoE). This role will partner with development teams to embed security into the software development lifecycle, standardize secure coding practices, and improve the organization’s ability to prevent vulnerabilities at scale. This position influences development teams, drives adoption, and delivers measurable risk reduction.
- Designs, develops, and supports the implementation of a Secure Coding Center of Excellence (CoE), including operating model, standards, and governance.
- Embeds secure development lifecycle (SDLC) practices into development processes by integrating security controls into CI/CD pipelines and developer workflows.
- Develops, documents, and promotes adoption of enterprise secure coding standards and patterns across multiple development teams and technology stacks.
- Performs platform application security assessments and threat modeling to identify design weaknesses and exploitable conditions.
- Provides clear, actionable remediation guidance to development teams, translating security findings into practical development fixes.
- Drives adoption of secure coding practices by partnering with development, product, and DevOps teams and influencing design and development decisions.
- Implements and optimizes application security tooling and augment automated results with manual and adversarial testing where tooling falls short.
- Develops and delivers role-based secure coding training and developer enablement programs, including support for security champions initiatives.
- Analyzes vulnerability data and application risk to support risk-based prioritization and reduction of systemic weaknesses.
- Defines, tracks, and reports on application security metrics and KPIs, including vulnerability trends, remediation timelines, and defect recurrence.
- Advises stakeholders on alignment with industry frameworks and standards (e.g., NIST CSF, Zero Trust, OWASP) and supports audit and compliance requirements.
- Contributes to continuous improvement of application security practices by identifying opportunities to standardize, automate, and scale controls across the enterprise.
- Collaborates cross-functionally with security, architecture, development, and operations teams to drive consistent and sustainable security practices.
- Performs manual application security testing, including deep-dive code-assisted analysis and adversarial testing techniques, to identify exploitable vulnerabilities beyond automated tooling.
- Validates the effectiveness of secure coding standards and SDLC controls through offensive testing and exploitation-driven analysis.
- Partners with development teams to reproduce, exploit, and remediate complex application vulnerabilities.
- Supports penetration testing and offensive security initiatives by providing application-layer expertise, design review, and exploitability analysis.
pay grade 17 range 120,446.2905-198,736.3793 Actual compensation will fall within the range but may vary based on factors such as experience, qualifications, education, location, licensure, certification requirements, and comparisons to colleagues in similar roles.
Minimum Qualifications
- Bachelor’s degree in Computer Science, Engineering, Information Systems, Cyber Security or a related field or an equivalent combination of education and experience.
- 8-10 or more years of progressive experience with application security and offensive security protocols.
- Demonstrated experience building or supporting secure coding and application security programs, including development and adoption of secure coding standards and patterns.
- Demonstrated experience conducting manual application penetration testing or adversarial security assessments, with the ability to assess exploitability and real-world impact.
- Strong expertise in secure SDLC practices and embedding security controls into CI/CD pipelines and development workflows.
- Deep understanding of web and API security, including OWASP Top 10 vulnerabilities, authentication, authorization, and data protection concepts.
- Hands-on experience performing application threat modeling and security assessments, with the ability to translate findings into secure design recommendations.
- Experience integrating and utilizing application security tooling (SAST, DAST, SCA) and guiding development teams on remediation.
- Ability to apply a risk-based approach to vulnerability management, considering business impact, exploitability, and exposure.
- Proven ability to collaborate with and influence development teams, providing actionable guidance and communicating security concepts to technical and non-technical stakeholders.
Our Commitment
Rooted in our Mission and Core Values, we honor the dignity of every person and recognize the unique perspectives, experiences, and talents each colleague brings. By finding common ground and embracing our differences, we grow stronger together and deliver more compassionate, person-centered care. We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other status protected by federal, state, or local law.
See All 307+ Remote Application Security Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsRemote Application Security Engineer Job Market
Who's Hiring
- Affirm28

- Akumin13

- Kastle Systems11

- DigitalOcean9

- Pinterest8

Top Industries Hiring
- Technology & Software98
- Banking & Financial Services41
- Healthcare & Medical Services25
- Electronics & Hardware17
- Consulting & Professional Services13
What Employers Look For
The qualifications that appear most often in remote application security engineer jobs.
- Proficiency with SAST, DAST, and SCA tools such as Checkmarx, Veracode, or Snyk
- Experience conducting application penetration testing and vulnerability assessments
- Strong knowledge of secure coding practices across Java, Python, or similar languages
- Familiarity with OWASP Top 10, CWE, and threat modeling methodologies like STRIDE
- Relevant certification such as OSCP, CEH, GWEB, or CSSLP preferred or required
- Bachelor's degree in computer science, information security, or a related technical field
Tips for Your Remote Application Security Engineer Job Search
Apply early to remote roles that fit
Migrate Mate lists remote application security engineer openings from across the U.S. in one place, so you can find roles that match your skills and apply directly without sorting through unfiltered postings from multiple sources.
Show async security communication in your portfolio
Remote application security engineers document findings, threat models, and remediation guidance in writing. Include sanitized vulnerability reports, secure design reviews, or written security advisories in your portfolio to show you can communicate risk clearly without a meeting.
Highlight remote-relevant security tooling experience
Remote teams rely on integrated tooling more than in-person coordination. Call out hands-on experience with SAST platforms like Semgrep or Checkmarx, DAST tools like Burp Suite, and CI/CD pipeline security integrations, since these signal you can operate independently within a distributed engineering workflow.
Prepare for asynchronous technical interviews
Many remote application security teams screen candidates through take-home code review exercises or written threat modeling scenarios before any live call. Practice producing clear written analysis of vulnerable code samples and articulating your reasoning, since that format mirrors how the actual remote role operates day to day.
Target remote-first companies with distributed engineering teams
Remote-first software companies and distributed fintech or healthcare platforms have built workflows around remote engineers, making them more likely to have structured onboarding and security team processes for remote hires. Look for companies whose engineering blog or job postings explicitly describe async collaboration and distributed team structures.
Remote Application Security Engineer Jobs: Frequently Asked Questions
How do I get a remote application security engineer job?
Target remote-first companies and distributed engineering teams that already operate asynchronously, since those employers are best equipped to onboard and manage remote security engineers. Remote hiring managers screen heavily for written communication, self-direction, and the ability to run threat modeling or code review cycles without daily in-person check-ins. Strong candidates demonstrate hands-on skills in SAST, DAST, secure SDLC practices, and cloud-native security tooling, and can articulate findings clearly in written reports.
Which companies hire remote application security engineers?
Companies hiring remote application security engineers right now include Affirm, Akumin, and Kastle Systems, based on current remote listings on Migrate Mate as of June 2026. Remote-first software firms, distributed fintech platforms, and healthcare technology companies make up a large share of these openings, since their fully distributed engineering teams require dedicated application security support regardless of physical location.
Can you get a remote application security engineer job with no experience?
Yes, but remote entry-level application security roles are harder to land because employers expect you to operate independently from day one without in-office mentorship. Your best paths are bug bounty participation, open-source security contributions, and home lab projects demonstrating OWASP testing or secure code review. Remote-first startups and mid-size SaaS companies occasionally hire junior application security engineers who can show real hands-on output rather than just credentials.
Do you need a degree for remote application security engineer jobs?
Not always. Remote employers in application security weigh demonstrated skills heavily, particularly proficiency in vulnerability assessment, penetration testing tools, and secure development practices. Certifications like OSCP, CEH, or vendor-specific cloud security credentials carry real weight. A portfolio of captured vulnerabilities, CTF results, or contributions to security tooling can substitute for a formal degree at many remote-first companies.
Which industries hire the most remote application security engineers?
The sectors hiring the most remote application security engineers are Technology & Software, Banking & Financial Services, and Healthcare & Medical Services, based on current remote listings on Migrate Mate as of June 2026. These industries rely on distributed engineering teams building customer-facing software and handling sensitive data, which creates sustained demand for application security engineers who can work remotely across the full development lifecycle.
See All 307+ Remote Application Security Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs