Remote Application Security Engineer Jobs

Remote application security engineer jobs are open across the U.S. at remote-first firms, distributed tech teams, and security-focused companies in software, fintech, healthcare, and defense contracting. Employers hiring remotely right now include Affirm, Akumin, and Kastle Systems. Find a role that fits below and apply directly.

Find Jobs

Overview

Open roles307+
Top employerAffirm
Top industryTechnology
Top credentialBachelor's
Companies hiring100+

Showing 5 of 307+ Remote Application Security Engineer jobs

Trinity Health
Consultant Application & Offensive Security
We won't show you this job again
Trinity Health
New 12h ago
Consultant Application & Offensive Security
Trinity Health
Livonia, Michigan
Remote (US)
Bachelor's
10,000+

Have you applied for this role?

PSEG
Manager, Vulnerability Management and Application Security
We won't show you this job again
PSEG
Added 1w ago
Manager, Vulnerability Management and Application Security
PSEG
Bethpage, New York
$121k - $199k/yr
Remote (US)
Bachelor's
10,000+

Have you applied for this role?

Vertafore
Sr. Application Security Engineer
We won't show you this job again
Vertafore
Added 1w ago
Sr. Application Security Engineer
Vertafore
Denver, Colorado
Cybersecurity
Security Engineering
$130k - $165k/yr
Remote (US)
1,001-5,000

Have you applied for this role?

Quanata
Application Security Engineer [Remote-US]
We won't show you this job again
Quanata
Added 1w ago
Application Security Engineer [Remote-US]
Quanata
San Francisco, California
Cybersecurity
Security Engineering
$175k - $215k/yr
Remote (US)
Experience equivalent to degree accepted
201-500

Have you applied for this role?

NetSPI
Senior Security Consultant (Web Application Penetration Tester)
We won't show you this job again
NetSPI
Added 1w ago
Senior Security Consultant (Web Application Penetration Tester)
NetSPI
Minneapolis, Minnesota
Cybersecurity
Consulting & Professional Services
Technical Product & Program Management
Technical Program Management
Remote (US)
Bachelor's
11-50

Have you applied for this role?

See All 307+ Remote Application Security Engineer Jobs

Find roles that match your experience and apply in just a few clicks.

Find Jobs

Remote Application Security Engineer Job Market

Who's Hiring

  • Affirm
    Affirm28
  • Akumin
    Akumin13
  • Kastle Systems
    Kastle Systems11
  • DigitalOcean
    DigitalOcean9
  • Pinterest
    Pinterest8

Top Industries Hiring

  • Technology & Software98
  • Banking & Financial Services41
  • Healthcare & Medical Services25
  • Electronics & Hardware17
  • Consulting & Professional Services13

What Employers Look For

The qualifications that appear most often in remote application security engineer jobs.

  • Proficiency with SAST, DAST, and SCA tools such as Checkmarx, Veracode, or Snyk
  • Experience conducting application penetration testing and vulnerability assessments
  • Strong knowledge of secure coding practices across Java, Python, or similar languages
  • Familiarity with OWASP Top 10, CWE, and threat modeling methodologies like STRIDE
  • Relevant certification such as OSCP, CEH, GWEB, or CSSLP preferred or required
  • Bachelor's degree in computer science, information security, or a related technical field

Tips for Your Remote Application Security Engineer Job Search

Apply early to remote roles that fit

Migrate Mate lists remote application security engineer openings from across the U.S. in one place, so you can find roles that match your skills and apply directly without sorting through unfiltered postings from multiple sources.

Show async security communication in your portfolio

Remote application security engineers document findings, threat models, and remediation guidance in writing. Include sanitized vulnerability reports, secure design reviews, or written security advisories in your portfolio to show you can communicate risk clearly without a meeting.

Highlight remote-relevant security tooling experience

Remote teams rely on integrated tooling more than in-person coordination. Call out hands-on experience with SAST platforms like Semgrep or Checkmarx, DAST tools like Burp Suite, and CI/CD pipeline security integrations, since these signal you can operate independently within a distributed engineering workflow.

Prepare for asynchronous technical interviews

Many remote application security teams screen candidates through take-home code review exercises or written threat modeling scenarios before any live call. Practice producing clear written analysis of vulnerable code samples and articulating your reasoning, since that format mirrors how the actual remote role operates day to day.

Target remote-first companies with distributed engineering teams

Remote-first software companies and distributed fintech or healthcare platforms have built workflows around remote engineers, making them more likely to have structured onboarding and security team processes for remote hires. Look for companies whose engineering blog or job postings explicitly describe async collaboration and distributed team structures.

Remote Application Security Engineer Jobs: Frequently Asked Questions

How do I get a remote application security engineer job?

Target remote-first companies and distributed engineering teams that already operate asynchronously, since those employers are best equipped to onboard and manage remote security engineers. Remote hiring managers screen heavily for written communication, self-direction, and the ability to run threat modeling or code review cycles without daily in-person check-ins. Strong candidates demonstrate hands-on skills in SAST, DAST, secure SDLC practices, and cloud-native security tooling, and can articulate findings clearly in written reports.

Which companies hire remote application security engineers?

Companies hiring remote application security engineers right now include Affirm, Akumin, and Kastle Systems, based on current remote listings on Migrate Mate as of June 2026. Remote-first software firms, distributed fintech platforms, and healthcare technology companies make up a large share of these openings, since their fully distributed engineering teams require dedicated application security support regardless of physical location.

Can you get a remote application security engineer job with no experience?

Yes, but remote entry-level application security roles are harder to land because employers expect you to operate independently from day one without in-office mentorship. Your best paths are bug bounty participation, open-source security contributions, and home lab projects demonstrating OWASP testing or secure code review. Remote-first startups and mid-size SaaS companies occasionally hire junior application security engineers who can show real hands-on output rather than just credentials.

Do you need a degree for remote application security engineer jobs?

Not always. Remote employers in application security weigh demonstrated skills heavily, particularly proficiency in vulnerability assessment, penetration testing tools, and secure development practices. Certifications like OSCP, CEH, or vendor-specific cloud security credentials carry real weight. A portfolio of captured vulnerabilities, CTF results, or contributions to security tooling can substitute for a formal degree at many remote-first companies.

Which industries hire the most remote application security engineers?

The sectors hiring the most remote application security engineers are Technology & Software, Banking & Financial Services, and Healthcare & Medical Services, based on current remote listings on Migrate Mate as of June 2026. These industries rely on distributed engineering teams building customer-facing software and handling sensitive data, which creates sustained demand for application security engineers who can work remotely across the full development lifecycle.

See All 307+ Remote Application Security Engineer Jobs

Find roles that match your experience and apply in just a few clicks.

Find Jobs