Senior Application Cybersecurity Engineer

1 day ago


San Francisco, California, United States Gallup Full time

Anticipate attacks, outsmart threats and safeguard innovation.

Gallup is seeking a senior application cybersecurity engineer who thrives at the intersection of engineering and security. You'll apply deep offensive security expertise to test Gallup's products and collaborate with developers to turn findings into secure, resilient applications. This role offers the autonomy to innovate, the responsibility to safeguard critical systems and the opportunity to leave a lasting impact on how security scales across Gallup.

What You'll Do

  • Review and advise on secure architecture and design for SaaS applications built and hosted in AWS
  • Perform penetration testing across web, mobile and API applications to identify and validate security vulnerabilities
  • Partner with engineering teams to incorporate security into applications from the start through secure coding guidance, reviews and awareness
  • Use static code analysis and code reviews to augment penetration testing and uncover vulnerabilities earlier in the development process
  • Secure open-source and third-party components through software composition analysis (SCA) and package management best practices

What Makes You Stand Out

  • Clear communication: You turn complex risks into clear, actionable guidance.
  • Self-starter mindset: You thrive working independently while knowing when to pull in others.
  • Impactful speed: You move quickly without cutting corners, ensuring durable results.
  • Adaptive focus: You stay effective across shifting priorities and varied demands.
  • Calm under pressure: In urgent incidents, you bring clarity and steadiness.
  • Persistence and precision: You solve tough security challenges with practical, scalable solutions.

What You Need

  • Bachelor's degree in cybersecurity, information assurance, computer science or a related field required
  • At least five years of experience in enterprise application security engineering required
  • Demonstrated deep expertise in mobile, web and API penetration testing required
  • Hands-on experience with secure SaaS (web, API, mobile) design required
  • Proficiency with SAST and code reviews required
  • Strong programming or scripting skills in at least one language (e.g., Python, JavaScript, C#, Java) required
  • Expertise in securing software supply chains and managing open-source dependencies through effective SCA practices preferred
  • Certifications such as OSWE, OSCP, GWAPT and GXPN preferred
  • A commitment to working on-site at Gallup's San Francisco office at least three days a week required

About Gallup

At Gallup, we change the world, one client at a time, through extraordinary analytics and advice on everything important facing humankind.

Gallup offers a robust benefits package that includes medical, dental, vision, life and other insurance options; a fully vested 401(k) retirement savings plan with company matching; an employee stock ownership program; mass transit reimbursement; family-building benefits; an employee assistance program; and various reimbursements and activities that enhance our associates' wellbeing. We also offer an estimated annual salary range of $150,000-$200,000 for this role. Salaries are based on a variety of factors, including an individual's education, experience and skills.

Gallup is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender identity, or any other legally protected basis, in accordance with applicable law.

To review Gallup's Privacy Statement, please click this link: This privacy policy is meant to help you understand what information we collect, why we collect it, and how you can update, manage and delete your information. Your application and the information you provide will be processed and stored in the United States.

#LI-Hybrid 



  • South San Francisco, California, United States IT Engagements Full time

    Hi,Greetings from IT Engagements. IT Engagements is a global staff augmentation firm providing a wide-range of talent on-demand and total workforce solutions. We have an immediate opening for the below position with one of our premium clients.Position Details: Cybersecurity EngineerLocation: San Francisco, CA (onsite 4 days a week)Type: 12 Month Contract...


  • San Diego, California, United States ODME SOLUTIONS, LLC Full time

    Work Location: Point Loma, San Diego, CA.Security Clearance: DoD SecretSalary: $90,000 to $120,000Requisition ID: C-CBISEA-CSE-1Job Summary:The Cybersecurity Engineer supports RMF accreditation and compliance activities by conducting vulnerability assessments, evaluating static and dynamic scans, performing STIG validations, and maintaining POA&Ms to ensure...


  • San Francisco, California, United States Corridor Full time

    DescriptionAI has changed software development. Security hasn't caught up – until now. Corridor is changing the game of product security, giving developers the ability to secure their AI coding.Our team has lived at the intersection of AI and cybersecurity. Collectively, we've led security at some of the world's largest companies, driven cybersecurity...


  • San Francisco, California, United States Iris Software Inc. Full time

    Our Client which is a large Audit is urgently looking to hire Sr. Cybersecurity Consultant.Sr. Cybersecurity Consultant.Location - San Francisco CA ( 100 % Remote )Privileged Access Management EngineerDesign, deploy, and maintain CyberArk or Microsoft PIM solutions to control and monitor privileged access to critical systems.Develop and implement privileged...


  • San Francisco, California, United States Brex Full time

    Engineering at BrexEngineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It's an environment where...


  • San Ramon, California, United States Sennovate Inc. Full time

    Cybersecurity Client Relationships InternSan Ramon, CA (Hybrid / Remote Option) Internship | Cybersecurity | Sales | Client Engagement | AI GovernanceAbout SennovateSennovate is aGlobal Cybersecurity Engineering Companyspecializing in:Identity and Access Management (IAM)Security Operations Center (SOC)AI GovernanceUnified Security EngineeringWe design and...


  • San Francisco, California, United States Airwallex Full time

    About AirwallexAirwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 200,000 businesses worldwide – including Brex, Rippling, Navan, Qantas, SHEIN and many more – with fully integrated solutions to manage everything from business...


  • San Diego, California, United States Military, Veterans and Diverse Job Seekers Full time

    Key Role:Support systems engineering and integration activities for military command, control, communications, computers, and intelligence programs. Ensure cybersecurity requirements are incorporated throughout the system's acquisition life cycle, from pre-award to development and accreditation. Contribute to and review system documents, including...


  • San Francisco, California, United States IT Engagements Full time

    Greetings from IT EngagementsRole: Cybersecurity Architect (NO H1B/ OPT)Location: SFO, CAThe Cyber Security Engineer will be responsible for the planning, development and implementation of enterprise information security solutions (such as authentication and authorization, public key infrastructure, data loss prevention, and security event information...


  • San Jose, California, United States TENEX Full time

    Company OverviewTENEXis an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in...