Lead Application Security Engineer at Jobgether
$140,000–$180,000from the description
Jul 16, 2026
—
Jul 21, 2026
What this job asks for AI summary
A senior individual-contributor role focused on embedding security across the software development lifecycle in an AI-heavy technology environment. Day-to-day work spans threat modeling, automated security testing (SAST, DAST, SCA, container scanning), CI/CD pipeline integration, and building policy-as-code controls, with particular attention to AI/ML-specific risks such as prompt injection and model abuse. Suits an experienced application security or DevSecOps engineer comfortable working across engineering, product, and cloud teams.
Senior level · 5+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 2,600 people nationally plausibly meet what this posting asks for (information security analysts). range 540–4,700
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The title is 'Lead Application Security Engineer' but carries no explicit seniority level word (Junior/Senior/Staff/etc.) in the title itself, so the title states no level; the 5+ years requirement and scope of responsibilities support a Senior classification.
The degree requirement states 'Bachelor's degree … or equivalent professional experience', which means no formal degree is hard-gated.
The application architecture technologies (React, Node.js, Django, FastAPI, OAuth2/OIDC/JWT) are listed under the Requirements section as knowledge the candidate must bring for securing those environments — not as development skills per se, but as required context for the security role.
Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, and GitHub Advanced Security are all listed together as examples of required tooling ('such as … or similar platforms'); Semgrep and Burp Suite are used as primary names with the others as alternatives where they are genuinely interchangeable substitutes.
Policy-as-code, IaC security, CI/CD security controls, and certifications (OSCP, GWAPT, CSSLP) are listed under a 'Preferred experience' clause and are marked accordingly.
The alternative occupation code 15-1252 (Software Developers) is noted because the role has a strong hands-on security engineering and automation-building component, but the primary framing is application security analysis and defense, making 15-1212 the better fit.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): SANS CWE Top 25.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.