Application Product Security Engineer
Jobgether
$130,000–$170,000from the description
Jul 20, 2026
—
Jul 22, 2026
What this job asks for AI summary
A hands-on application security engineering role embedded within product and engineering teams. Day-to-day work spans threat modeling, secure code review, vulnerability triage, and building security tooling such as static analysis and dependency scanning into development pipelines, alongside participation in incident response. Suited to engineers with a few years of application or product security experience who are comfortable writing code and working closely with software development teams.
Mid level · 2+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 6,700 people nationally plausibly meet what this posting asks for (information security analysts). range 1,400–10,100
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (6)
The role is posted via Jobgether on behalf of an unnamed partner company; the actual employer is not disclosed.
Total experience requirement is stated as '2–4 years', which maps to a Mid-level band despite the breadth of responsibilities (threat modeling, incident response, security tooling). The advertised title carries no explicit seniority modifier.
Python/TypeScript/JavaScript/Go are listed together as interchangeable coding-language options ('such as … or similar'); emitted as one skill with alternatives rather than separate entries.
Cloud security (AWS/GCP/Azure) and compliance frameworks (SOC 2, GDPR) appear only under Preferred Qualifications.
Experience securing AI/ML applications and financial data products is mentioned as preferred but names no specific technology, so it is omitted per the no-generic-concepts rule.
Bug bounty, CTF, and open-source contributions are preferred but name no concrete technology and are omitted.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.