Testing for Platform + App Security Regressions * Implement tests for platform upgrade regressions using tools like kube-bench, kube-hunter, and e2e integration suites. C) Federal Cybersecurity ...
Testing for Platform + App Security Regressions * Implement tests for platform upgrade regressions using tools like kube-bench, kube-hunter, and e2e integration suites. C) Federal Cybersecurity ...
... app security. Understand the underlying data and able to map the same with the dashboard. Creation of Power BI dashboard and transforming the manual reports, support Power BI dashboard deployment ...
... app security. Understand the underlying data and able to map the same with the dashboard. Creation of Power BI dashboard and transforming the manual reports, support Power BI dashboard deployment ...
Director, Information & Technology Security
Chicago, IL · Hybrid
$160K - $180K/yr
Support future-state cloud app security capabilities * Ensure security controls align with business workflows, not disrupt them Incident Response, Monitoring amp; Operations * Own incident response ...
Director, Information & Technology Security
Chicago, IL · Hybrid
$160K - $180K/yr
Support future-state cloud app security capabilities * Ensure security controls align with business workflows, not disrupt them Incident Response, Monitoring amp; Operations * Own incident response ...
Senior Product Security Engineer
Seattle, WA · On-site
$204K - $281K/yr
Qualifications * 5+ years of proven experience in product and application security concepts, including API, web, and mobile app security. * Ability to communicate complex security concepts to ...
Senior Product Security Engineer
Seattle, WA · On-site
$204K - $281K/yr
Qualifications * 5+ years of proven experience in product and application security concepts, including API, web, and mobile app security. * Ability to communicate complex security concepts to ...
Senior Product Security Engineer
$129K - $177K/yr
Qualifications * 5+ years of proven experience in product and application security concepts, including API, web, and mobile app security. * Ability to communicate complex security concepts to ...
Senior Product Security Engineer
$129K - $177K/yr
Qualifications * 5+ years of proven experience in product and application security concepts, including API, web, and mobile app security. * Ability to communicate complex security concepts to ...
Director, Information & Technology Security
Chicago, IL · On-site
$160K - $180K/yr
Support future-state cloud app security capabilities * Ensure security controls align with business workflows, not disrupt them Incident Response, Monitoring & Operations * Own incident response ...
Director, Information & Technology Security
Chicago, IL · On-site
$160K - $180K/yr
Support future-state cloud app security capabilities * Ensure security controls align with business workflows, not disrupt them Incident Response, Monitoring & Operations * Own incident response ...
Senior Product Security Engineer - Applications
Plano, TX · On-site
$107K - $146K/yr
Demonstrable experience with product and application security concepts, including API, web, and mobile app security. * Excellent communication skills, both written and verbal, and the ability to ...
Senior Product Security Engineer - Applications
Plano, TX · On-site
$107K - $146K/yr
Demonstrable experience with product and application security concepts, including API, web, and mobile app security. * Excellent communication skills, both written and verbal, and the ability to ...
Power BI Developer
New York, NY · On-site
... app security. Understand the underlying data and able to map the same with the dashboard. Creation of Power BI dashboard and transforming the manual reports, support Power BI dashboard deployment ...
Power BI Developer
New York, NY · On-site
... app security. Understand the underlying data and able to map the same with the dashboard. Creation of Power BI dashboard and transforming the manual reports, support Power BI dashboard deployment ...
Senior Product Security Engineer - Applications
$107K - $146K/yr
Demonstrable experience with product and application security concepts, including API, web, and mobile app security. * Excellent communication skills, both written and verbal, and the ability to ...
Senior Product Security Engineer - Applications
$107K - $146K/yr
Demonstrable experience with product and application security concepts, including API, web, and mobile app security. * Excellent communication skills, both written and verbal, and the ability to ...
Senior Product Security Engineer - Applications
$110K - $150K/yr
Demonstrable experience with product and application security concepts, including API, web, and mobile app security. * Excellent communication skills, both written and verbal, and the ability to ...
Senior Product Security Engineer - Applications
$110K - $150K/yr
Demonstrable experience with product and application security concepts, including API, web, and mobile app security. * Excellent communication skills, both written and verbal, and the ability to ...
Knowledge of static and dynamic mobile app security analysis concepts * Knowledge of protocol and network analysis using mitmproxy and Wireshark * Knowledge of common mobile application ...
Knowledge of static and dynamic mobile app security analysis concepts * Knowledge of protocol and network analysis using mitmproxy and Wireshark * Knowledge of common mobile application ...
Security Software Engineer Project Intern (Product Security) - 2026 Start (BS/MS)
San Jose, CA · On-site
$45 - $60/hr
... app security, network security, operating system internals and hardening, applied cryptography, cloud computing. You're expected to be an expert in at least one of these areas. - Experience in ...
Security Software Engineer Project Intern (Product Security) - 2026 Start (BS/MS)
San Jose, CA · On-site
$45 - $60/hr
... app security, network security, operating system internals and hardening, applied cryptography, cloud computing. You're expected to be an expert in at least one of these areas. - Experience in ...
Security Software Engineer Project Intern (Product Security) - 2026 Start (BS/MS)
San Jose, CA · On-site
$45 - $60/hr
... app security, network security, operating system internals and hardening, applied cryptography, cloud computing. You're expected to be an expert in at least one of these areas. - Experience in ...
Security Software Engineer Project Intern (Product Security) - 2026 Start (BS/MS)
San Jose, CA · On-site
$45 - $60/hr
... app security, network security, operating system internals and hardening, applied cryptography, cloud computing. You're expected to be an expert in at least one of these areas. - Experience in ...
Lead Software Engineer-Full Stack
Manhattan, NY · On-site
$152K - $215K/yr
... App Security Tests, performance checks. * Defines and track measurable outcomes from AI assisted workflows: developer throughput, review cycle time, defect density without compromising security or ...
Lead Software Engineer-Full Stack
Manhattan, NY · On-site
$152K - $215K/yr
... App Security Tests, performance checks. * Defines and track measurable outcomes from AI assisted workflows: developer throughput, review cycle time, defect density without compromising security or ...
Power BI Developer
New York, NY · On-site
... app security. • Understand the underlying data and able to map the same with the dashboard. • Creation of Power BI dashboard and transforming the manual reports, support Power BI dashboard ...
Power BI Developer
New York, NY · On-site
... app security. • Understand the underlying data and able to map the same with the dashboard. • Creation of Power BI dashboard and transforming the manual reports, support Power BI dashboard ...
... experience in App Security Engineering or DevSecOps . (Developer Security operations experience) * Deep expertise in security vulnerability management, secure coding practices, and security ...
Quick apply
... experience in App Security Engineering or DevSecOps . (Developer Security operations experience) * Deep expertise in security vulnerability management, secure coding practices, and security ...
... App Security Tests, performance checks. * Defines and track measurable outcomes from AI assisted workflows: developer throughput, review cycle time, defect density without compromising security or ...
... App Security Tests, performance checks. * Defines and track measurable outcomes from AI assisted workflows: developer throughput, review cycle time, defect density without compromising security or ...
... App Security Tests, performance checks. * Defines and track measurable outcomes from AI assisted workflows: developer throughput, review cycle time, defect density without compromising security or ...
... App Security Tests, performance checks. * Defines and track measurable outcomes from AI assisted workflows: developer throughput, review cycle time, defect density without compromising security or ...
... App Security Tests, performance checks. * Defines and track measurable outcomes from AI assisted workflows: developer throughput, review cycle time, defect density without compromising security or ...
... App Security Tests, performance checks. * Defines and track measurable outcomes from AI assisted workflows: developer throughput, review cycle time, defect density without compromising security or ...
Mobile Application Security Engineer
Fort George G Meade, MD · On-site
$69K - $158K/yr
Knowledge of static and dynamic mobile app security analysis concepts * Knowledge of protocol and network analysis using mitmproxy and Wireshark * Knowledge of common mobile application ...
Mobile Application Security Engineer
Fort George G Meade, MD · On-site
$69K - $158K/yr
Knowledge of static and dynamic mobile app security analysis concepts * Knowledge of protocol and network analysis using mitmproxy and Wireshark * Knowledge of common mobile application ...
App Security information
See salary details
$24.28 - $29.20
9% of jobs
$29.20 - $34.11
0% of jobs
$34.11 - $39.03
0% of jobs
$39.03 - $43.95
5% of jobs
$43.95 - $48.86
7% of jobs
$49.77 is the 25th percentile. Wages below this are outliers.
$48.86 - $53.78
16% of jobs
The median wage is $57.11 / hr.
$53.78 - $58.70
18% of jobs
$62.78 is the 75th percentile. Wages above this are outliers.
$58.70 - $63.61
23% of jobs
$63.61 - $68.53
12% of jobs
$68.53 - $73.45
5% of jobs
$73.45 - $78.37
4% of jobs
$24
$56
$78
How much do app security jobs pay per hour?
What are the key skills and qualifications needed to thrive in the App Security position, and why are they important?
To thrive in App Security, you need a strong grasp of software development, cybersecurity principles, and vulnerability assessment, often supported by a Computer Science degree or equivalent experience. Familiarity with tools like static and dynamic application security testing (SAST/DAST), penetration testing suites, and certifications such as CISSP or CEH are highly valued. Analytical thinking, attention to detail, and strong communication skills help you collaborate effectively across development and security teams. These skills are crucial for safeguarding applications against evolving threats and ensuring compliance with industry standards.
What is an App Security job?
An App Security job focuses on protecting applications from threats and vulnerabilities by implementing security practices throughout the software development lifecycle. Professionals in this field conduct security assessments, identify and remediate risks, and ensure compliance with security standards. They work closely with developers, IT teams, and security analysts to design, test, and enforce security measures, reducing the risk of breaches or attacks.
What are the typical daily responsibilities of an App Security professional?
App Security professionals are responsible for identifying and mitigating security vulnerabilities within software applications, conducting regular security assessments, and collaborating closely with development teams to implement secure coding practices. They often review code, run automated security scans, and respond to potential incidents or breaches. Additionally, they may develop and maintain security policies, educate staff on secure development practices, and keep current with the latest security threats and technologies. This combination of proactive and reactive tasks ensures robust protection of software assets and aligns with industry standards.

$119K - $163K/yr
Other
Posted 26 days ago
Job description
Expertise in cross-domain CI/CD, blue-green testing, and platform deployment within disconnected environments. Familiar with image/helm/chart mirroring, FIPS 140 validated crypto, OS hardening (e.g., Alpine), and SELinux enforcing. Registry and Artifact Governance Maintain and govern a disconnected container registry, ensuring content sources, image signing, SBOMs, and vulnerability gating.
Familiarity with tools such as Cosign, Syft, Grype, Trivy, OCI level attestations, and curated repository promotions. Admission Control & Policy Enforcement Enforce security baselines and policies without internet dependencies using tools like OPA Gatekeeper, Kyverno, and image provenance verification. Cluster Multi-Tenancy in SCIFs * Implement RBAC, namespace isolation, and mTLS for mixed-sensitivity workloads within a SCIF (Sensitive Compartmented Information Facility).
Patching and CVE Response Offline Manage critical Kubernetes CVEs in air-gapped enclaves through risk triage, change windows, and mirrored updates. B) CI/CD & Security Test Automation (Disconnected) Pipeline Architecture for Classified Enclaves Design CI/CD pipelines to build, test, sign, scan, and promote containers across Dev → Test → Prod in closed networks. * Familiarity with GitLab/Jenkins runners, artifact promotion, and "compliance as code" practices.
Automated Security Testing Coverage Implement automated tests for SAST, DAST, IAST, SCA, and IaC scanning within CI/CD pipelines. Ensure pipeline failures persist if discrepancies are detected. Evidence Generation for RMF * Generate RMF/ATO evidence via automated pipeline outputs, mapping artifacts to NIST controls.
Knowledge of OSCAL output, control mappings, and integration with evidence stores like eMASS. Promotion Gates & Provenance Ensure artifacts meet quality and security criteria (e.g., reproducible builds, signed/provenanced artifacts, passing STIG checks) before promotion to higher environments. Testing for Platform + App Security Regressions * Implement tests for platform upgrade regressions using tools like kube-bench, kube-hunter, and e2e integration suites.
C) Federal Cybersecurity Requirements (RMF/ATO, STIGs, CNSS, FedRAMP) RMF Tailoring in Containerized Systems Tailor NIST 800-53 controls for microservices platforms, identifying platform vs. app team responsibilities. * Work with shared responsibility matrices and control inheritance catalogs.
DISA STIG Application to Kubernetes Workloads Apply and track Kubernetes/Docker/OpenShift STIG findings and exceptions. Implement a "STIG as code" approach in CI/CD pipelines and perform continuous drift checks. Continuous Monitoring (CONMON) * Implement telemetry collection for CONMON using on-prem tools (e.g., Prometheus, Grafana, auditd, Falco).
Design and manage control dashboards and evidence snapshots. ATO Acceleration through Automation Reduce ATO lead times using automated assessments, OSCAL generation, and integration with tools like eMASS. Policy Conflicts & Adjudication * Reconcile conflicts between NIST, CNSS, and program-specific directives, leveraging risk-based decision memos and compensating controls.
D) Networking, Identity & Zero Trust in On-Prem/Classified Enclaves Zero Trust in Kubernetes Implement Zero Trust principles within Kubernetes beyond mTLS and RBAC, using tools like SPIFFE, SPIRE, and service mesh authZ. Offline PKI Operations Manage certificate lifecycles in air-gapped environments, utilizing offline roots, short-lived certs, and mesh cert synchronization strategies. East-West Segmentation Strategy Design and implement micro-segmentation and egress controls for multi-tenancy within classified environments.
Identity Propagation Across Layers Ensure identity propagation from build systems through runtime enforcement, using tools like Sigstore attestations and audit chain linking. Cross-Domain and Data Movement Patterns Securely move artifacts across domains with tamper-evident transfer logs, hash-based validation, and offline review stations. E) Operations, SRE & Incident Response in SCIFs Observability without SaaS Build observability solutions for logs, metrics, traces, and capacity planning using on-prem tools like EFK, Prometheus, and Tempo.
Break Glass & Change Control Design a break-glass process with time-bound privilege elevation, session recording, and immutable logs. Forensics & Container Runtime Collect forensic evidence from compromised container nodes while preserving data integrity through disk snapshots and isolated triage nodes. Resiliency & DR in Disconnected Sites Develop strategies for service continuity across multiple isolated sites, including staged upgrades and backup/restore drills.
Application Team & SOC Integration Integrate containerized environments with enterprise SOC teams during incident detection, containment, and recovery. Define roles, telemetry requirements, and communication channels for effective response. REQUIRED QUALIFICATIONS: 12 years of experience and a Masters degree.
Degree can be substituted for 6 additional years of applicable experience IAT/IAM Level 3 Certification in compliance with DoD 8570/8140 guidelines Extensive experience working with Kubernetes, OpenShift, RKE2, and container registry management in air-gapped and classified environments. Deep understanding of CI/CD pipeline architectures, especially in disconnected networks. Expertise in federal cybersecurity frameworks, such as NIST 800-53, DISA STIGs, RMF, and ATO processes.
Familiarity with security testing tools (SAST, DAST, IAST, IaC) and automated compliance validation. Proven track record of enforcing Zero Trust principles, PKI management, and network segmentation in a classified environment. * Strong ability to map pipeline artifacts to RMF/ATO controls and support security operations during incidents.
Extensive experience in cybersecurity design and architecture. CLEARANCE: Top Secret minimum
About Procession Systems
Sourced by ZipRecruiter
Procession Systems, based in Reston, Virginia, United States, is an industry leader operating in the Information Technology Services sector. Established to address complex business and technology challenges, the company delivers innovative tech solutions for government entities, primarily focusing on systems integration and software development. Procession Systems takes pride in their commitment to quality, responsiveness, and results, geared towards improving public sector services and saving taxpayer dollars.
Industry
Recruiting and staffing services
Company size
11 - 50 Employees
Headquarters location
Reston, VA, US
Year founded
2016