1

Application Security Analyst Jobs in Virginia (NOW HIRING)

Application Security Engineer

Ashburn, VA · On-site

$60 - $80.25/hr

Utilize SAST tools to analyze source code for vulnerabilities. * Work closely with development ... Master's with 1-2 years of prior experience in application security with a focus on SAST, SCA, DAST

Application Security Engineer 3

Arlington, VA · On-site

$67.75 - $90.50/hr

Advanced understanding of AI/ML security, including model vulnerability analysis, AI threat ... relevant experience in Application Security, AppSec engineering, Cloud Security, or Software ...

POSITION OVERVIEW Security Analyst supporting Diplomatic Security at the Department of State in the ... Work with application project teams and operations teams to complete RMF steps 1 through 3, as ...

POSITION OVERVIEW Security Analyst supporting Diplomatic Security at the Department of State in the ... Work with application project teams and operations teams to complete RMF steps 1 through 3, as ...

Showing results 21-40

Application Security Analyst information

See Virginia salary details

$34.7K

$82.9K

$137.8K

How much do application security analyst jobs pay per year?

As of Sep 15, 2026, the average yearly pay for application security analyst in Virginia is $82,900.00, according to ZipRecruiter salary data. Most workers in this role earn between $63,900.00 and $93,200.00 per year, depending on experience, location, and employer.

What is an application security analyst?

Application Security Analysts are professionals responsible for identifying and mitigating security vulnerabilities in software applications. They assess applications for risks by performing code reviews, vulnerability assessments, and penetration testing. Their role includes working with development teams to ensure security best practices are followed throughout the software development lifecycle. Application Security Analysts also help develop security policies, provide training, and respond to security incidents related to applications.

What are some common challenges faced by application security analysts when collaborating with development teams?

Application Security Analysts often encounter challenges in aligning security best practices with fast-paced development cycles. Ensuring that security recommendations are integrated early without delaying product releases requires strong communication and a collaborative approach with developers. Analysts must balance advocating for robust security measures while understanding development constraints, and often need to translate technical vulnerabilities into clear, actionable guidance for non-security professionals. Building trust and fostering a culture of shared responsibility for security helps overcome these challenges.

What are the key skills and qualifications needed to thrive as an application security analyst, and why are they important?

To thrive as an Application Security Analyst, you need a strong understanding of secure coding practices, vulnerability assessment, and information security principles, often supported by a degree in computer science or related certifications like CISSP or CEH. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing suites, and security information and event management (SIEM) systems is essential. Analytical thinking, attention to detail, and effective communication are critical soft skills for identifying risks and collaborating with development teams. These competencies are vital to proactively identifying vulnerabilities, minimizing risks, and ensuring robust application security in evolving technology environments.

What is the difference between Application Security Analyst vs Security Engineer?

AspectApplication Security AnalystSecurity Engineer
CertificationsCompTIA Security+, CISSP, CEHCISSP, CEH, Security+
Work EnvironmentFocus on application vulnerabilities, code reviews, and security assessmentsDesigns and implements security infrastructure, manages security tools
Industry UsageCommon in software development and IT teamsFound in cybersecurity teams across various industries
Primary FocusIdentifying and mitigating application security risksBuilding and maintaining security systems and protocols

While both roles involve cybersecurity, Application Security Analysts primarily focus on securing software applications through assessments and vulnerability management. Security Engineers work on developing and maintaining security infrastructure, ensuring overall organizational security. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What cities in Virginia are hiring for Application Security Analyst jobs?

Cities in Virginia with the most Application Security Analyst job openings:

Infographic showing various Application Security Analyst job openings in Virginia as of August 2026, with employment types broken down into 71% Full Time, 25% Part Time, and 4% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $82,900 per year, or $39.9 per hour.

Application Security Engineer I

Arlington, VA • On-site

Bloomberg Industry Group
Library and Information Services • 51 - 200 employees

$90K - $110K/yr

Full-time

Re-posted 11 days ago


Job description

Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation support, and incident response participation, contributing to secure development practices across internal and external applications.
About the Team:
At Bloomberg Industry Group, our Application Security team ensures the security of internal and external applications and services. We leverage innovative security tools and a team of dedicated security engineers to protect our products throughout their lifecycle.
Job Summary:
As an Application Security Engineer I, you will be part of a team responsible for ensuring the security of applications, conducting security assessments, and implementing security controls. You will work closely with developers, providing guidance on secure coding practices, and working to integrate security into our CI/CD pipelines.
This entry-level role is ideal for candidates beginning their Application Security career and looking to grow into a seasoned Application Security Engineer.
What You Will Do:
  • Participate in application security practices such as:
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)
  • Penetration Testing
  • Participate in vulnerability management processes.
  • Assist in the development, deployment and automation of security tools, scripts, and processes.
  • Collaborate with software engineers to design, implement, and review security features in applications.
  • Support the identification and resolution of security incidents as part of the incident response team.
  • Stay current on emerging security trends, vulnerabilities, and tooling to continuously elevate Application Security.

You Need to Have:
  • Basic knowledge of security principles, standards, and best practices.
  • Familiarity with one or more programming languages (e.g., Python, Java, JavaScript).
  • Ambition to learn and grow into AI Security and Security Engineering.
  • Exposure to security testing tools like SAST, DAST, SCA, and/or vulnerability management platforms.
  • An associate's degree in Information Security, Computer Science, or a related field, or equivalent experience.
  • 1-2 years of relevant experience.

We would Love to See:
  • Certifications such as CompTIA Security+ , CompTIA Pentest+, Certified DevSecOps Professional (CDP) or equivalent.
  • Hands-on experience with:
  • CI/CD pipelines (GitLab, GitHub Actions, Jenkins)
  • Cloud environments (AWS)
  • Secure coding or code review
  • Security automation or scripting
  • Participation in security communities, Capture The Flag (CTF) events, open-source contributions, or similar skill-building activities.

Compensation Range:
$90,000.00-$110,000.00
Placement in the salary range will be decided upon completion of the interview process. Salary determination will be determined based on factors including but not limited to relevant experience, demonstrated skills related to the requirements of the role, education, certifications, and geographic location.
Equal Opportunity
Bloomberg Industry Group maintains a continuing policy of non-discrimination in employment. It is Bloomberg Industry Group's policy to provide equal opportunity and access for all persons, and the Company is committed to attracting, retaining, developing, and promoting the most qualified individuals without regard to age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy or maternity/parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law ("Protected Characteristic"). Bloomberg prohibits treating applicants or employees less favorably in connection with the terms and conditions of employment, in all phases of the employment process, because of one or more Protected Characteristics ("Discrimination").