Application Security Engineer

JFrog Ltd

United States

On-site

USD 120,000 - 160,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

JFrog Ltd. is seeking an Application Security Engineer to drive security across the SDLC at scale, empower developers, and automate security across CI/CD pipelines in a cloud-native environment.

You will work with Product, Engineering, DevOps, and Security teams on SSDLC automation, vulnerability management, and secure coding practices.

The role requires hands-on coding, threat modeling, and collaboration to embed security early and continuously.

Qualifications

  • 6-7 years of experience in AppSec and Product Security.
  • Deep knowledge in application security and vulnerabilities.
  • Strong coding/scripting background (e.g., Python, Go, Java, JavaScript).
  • Hands-on experience with CI/CD pipelines, security tools, and DevSecOps practices.
  • Familiarity with cloud-native architectures (cloud, microservices, containers, Kubernetes).
  • Understanding of secure coding principles.
  • Strong communication and collaboration skills.
  • Penetration testing knowledge is a plus.
  • Familiarity with ML/AI concepts applied to security is a strong advantage.

Responsibilities

  • Assist in the development of internal security tools and AI agents
  • Support the design and implementation of SSDLC practices and automated security controls across the CI/CD pipeline
  • Contribute to building and operating scalable vulnerability management frameworks across cloud-native services and SaaS products
  • Integrate security into Agile and DevOps processes, including threat modeling, SAST, DAST, and SCA
  • Develop Internal application security Tools and Automations
  • Partner with development and DevOps teams to embed security early and often
  • Contribute to secure code reviews and assist with remediation strategies
  • Track, triage, and report vulnerabilities across product lines
  • Support the adoption of secure development best practices

Skills

AppSec experience
Product Security
Coding in Python/Go/Java/JS
CI/CD security
DevSecOps
Threat modeling
SAST/DAST/SCA
Cloud/microservices/Kubernetes
Vulnerability management
Security tooling
communication
collaboration

Job description

At JFrog, we’re reinventing DevSecOps to help the world’s greatest companies innovate.Our team of industry-leading software security experts is a true pioneer, constantly pushing the boundaries with original research and technological innovation.JFrog is a special place with a unique combination of brilliance, spirit, and just all-around great people.Thousands of customers, including the majority of the Fortune 100, trust JFrog to manage, accelerate, and secure their software delivery from code to production – a concept we call “liquid software”. Wouldn't it be amazing if you could join us on our journey?

The JFrog CSO Office is seeking an Application Security Engineer. In this role, you will contribute to driving security across the SDLC at scale, empowering developers, and enabling secure development through automation, process, and tooling. You’ll work as part of a team of security engineers focused on SSDLC automation, vulnerability management, and proactive engagement with R&D. This is a hands-on technical role that combines architecture, coding, and collaboration, working closely with Product, Engineering, DevOps, and Security stakeholders.

As an Application Security Engineer at JFrog you will...
  • Assist in the development of internal security tools and AI agents
  • Support the design and implementation of SSDLC practices and automated security controls across the CI/CD pipeline
  • Contribute to building and operating scalable vulnerability management frameworks across cloud-native services and SaaS products
  • Integrate security into Agile and DevOps processes, including threat modeling, SAST, DAST, and SCA
  • Develop Internal application security Tools and Automations
  • Partner with development and DevOps teams to embed security early and often
  • Contribute to secure code reviews and assist with remediation strategies
  • Track, triage, and report vulnerabilities across product lines
  • Support the adoption of secure development best practices
To be an Application Security Engineer at JFrog, you need…
  • 6-7 years of experience in AppSec And Product Security
  • Deep knowledge in application security and vulnerabilities.
  • Strong coding/scripting background (e.g., Python, Go, Java, JavaScript)
  • Hands-on experience with CI/CD pipelines, security tools, and DevSecOps practices
  • Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes)
  • Understanding of software development processes and secure coding principles.
  • Strong communication and collaboration skills
  • Penetration testing knowledge is a plus
  • Familiarity with machine learning and AI concepts applied to security (e.g., anomaly detection, predictive analytics) is a strong advantage
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer - SDLC Automation & DevSecOps
Application Security Engineer - SDLC Automation & DevSecOps

JFrog Ltd • United States

On-site
USD 120,000 - 160,000
Solutions Engineer
Solutions Engineer

JFrog Ltd • London (KY)

Hybrid
USD 93,000 - 132,000
DevOps Architect
DevOps Architect

JFrog Ltd • United States

On-site
USD 180,000 - 240,000
Field CISO
Field CISO

JFrog • Sunnyvale (CA)

On-site
USD 240,000 - 255,000
Discretionary bonuses or commission eligibility
Equity package of restricted stock units (RSU)
Participation in Employee Stock Purchase Plan
+1
R&D Team Lead, Data Engineering- JFrog Security
R&D Team Lead, Data Engineering- JFrog Security

JFrog Ltd • United States

On-site
USD 120,000 - 180,000
Professional Services DevOps Engineer
Professional Services DevOps Engineer

JFrog • United States

On-site
USD 135,000 - 145,000
Equity RSU
Employee Stock Purchase Plan
Comprehensive benefits including med/d
Strategic Solution Architect, Presales (Central)
Strategic Solution Architect, Presales (Central)

JFrog • Dallas (TX)

On-site
USD 195,000 - 215,000
RSU equity
Stock Purchase Plan
Security Engineer
Security Engineer

Wall Street Consulting Services LLC • New York (NY)

On-site
USD 120,000 - 180,000
Strategic Solution Architect, Presales (Central)
Strategic Solution Architect, Presales (Central)

JFrog Ltd • United States

On-site
USD 195,000 - 215,000
RSU equity
Employee Stock Purchase Plan
Bonuses/Commission
Principal Product Manager - Business Applications
Principal Product Manager - Business Applications

JFrog Ltd • United States

On-site
USD 140,000 - 210,000