Application Security Engineer
This role conducts comprehensive security reviews and threat modeling across AI-native platforms and data infrastructure, identifying vulnerabilities in applications that power enterprise AI agents, LLM systems, and knowledge graphs. What distinguishes Application Security Engineers from broader security roles is their focus on embedding security into the development lifecycle itself—through code reviews, secure design practices, and CI/CD integration—rather than conducting external assessments alone. These engineers typically sit within dedicated product or application security teams that partner closely with engineering organizations, translating security requirements into developer-friendly practices and tooling that enable teams to ship secure code at scale.
Measured across 27 of 27 open postings.
This role is advertised at one level, so a single figure for the role would describe none of them. Experience and pay are the midpoints for each level on its own.
| Level | Share | Median years | Median pay |
|---|---|---|---|
| Mid | 48%(13) | — | — |
A dash means too few postings stated it to report a midpoint at any level. Most companies do not publish a salary band, so pay is indicative rather than a market rate. 2 levels with fewer than 10 open postings are not shown.
“Building agentic workflows for vulnerability management”
“Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org”
“6+ years of experience in security engineering or security architecture, with at least 2+ years dedicated specifically to AI/ML security, LLM application security, or securing agentic frameworks.”
“AI-assisted triage, context-aware risk scoring, and vulnerability correlation/chaining”
Skills
What companies are looking for in this role.
Security engineering
Application and product security
Threat modeling and architecture review
Vulnerability management
Security tooling and automation engineering
Cloud and infrastructure security
Offensive security testing
CI/CD and release automation
Incident response and forensics
Software supply chain security
Cryptography and key management
Backend and API engineering
Security policy and standards
Security risk management
AI safety and guardrails
Security culture and enablement
Mentoring and code review
Technology
The tools and technologies that define this role.
Open Jobs
27 open Application Security Engineer jobs across 20 companies.
Other Security roles
Secures cloud infrastructure, networks, and systems.
Generalist security engineering role spanning multiple security domains. For security engineers who work across application, infrastructure, and cloud security without a single dominant specialization. The default home for "Security Engineer" titles when the function is clearly Security.
Builds detection systems, investigates security incidents, and leads incident response efforts.
Conducts offensive security assessments including red teaming, penetration testing, and adversarial simulation.
Designs and maintains identity infrastructure, authentication systems, and access control policies.