1

Application Security Analyst Jobs in Virginia (NOW HIRING)

Understand enterprise operating environments, including security posture, application environment ... Execution and Analysis of vulnerability scans ; such as but not limited to: Nessus/Security Center ...

Understand enterprise operating environments, including security posture, application environment ... Execution and Analysis of vulnerability scans ; such as but not limited to: Nessus/Security Center ...

Senior Security Analyst

Herndon, VA Β· Hybrid

$98K - $129K/yr

Application of enterprise security frameworks, including FISMA and NIST SP 800, especially for ... Experience analyzing container vulnerabilities and remediation paths (OS and App level)

Security Engineer (Web Application)

Arlington, VA Β· On-site

$67.50 - $90.25/hr

Security Engineer (Web Application) Location: Arlington, VA Security Clearance: Secret Duties and ... Strong organizational, analytical, and technical writing skills to be able to document findings in ...

The Information Security Analyst will monitor and respond to security threats, ensure compliance ... If you require assistance with completing the application process, please call 703-600-0347. NO ...

ORA_ON_SITE Description ο»ΏSAIC is seeking a Senior Security Analyst to provide general ... courier card application processing; computer/network account access requests; and visit ...

ORA_ON_SITE Description ο»ΏSAIC is seeking a Senior Security Analyst to provide general ... courier card application processing; computer/network account access requests; and visit ...

Information Security Analyst

Arlington, VA Β· On-site

$85K - $202K/yr

The Information Security Analyst will support the design, implementation, and management of ... application system due to a disability. Please send your request tohr@avalore.ai. Avalore is an ...

Showing results 41-60

Application Security Analyst information

See Virginia salary details

$34.7K

$82.9K

$137.8K

How much do application security analyst jobs pay per year?

As of Sep 15, 2026, the average yearly pay for application security analyst in Virginia is $82,900.00, according to ZipRecruiter salary data. Most workers in this role earn between $63,900.00 and $93,200.00 per year, depending on experience, location, and employer.

What is an application security analyst?

Application Security Analysts are professionals responsible for identifying and mitigating security vulnerabilities in software applications. They assess applications for risks by performing code reviews, vulnerability assessments, and penetration testing. Their role includes working with development teams to ensure security best practices are followed throughout the software development lifecycle. Application Security Analysts also help develop security policies, provide training, and respond to security incidents related to applications.

What are some common challenges faced by application security analysts when collaborating with development teams?

Application Security Analysts often encounter challenges in aligning security best practices with fast-paced development cycles. Ensuring that security recommendations are integrated early without delaying product releases requires strong communication and a collaborative approach with developers. Analysts must balance advocating for robust security measures while understanding development constraints, and often need to translate technical vulnerabilities into clear, actionable guidance for non-security professionals. Building trust and fostering a culture of shared responsibility for security helps overcome these challenges.

What are the key skills and qualifications needed to thrive as an application security analyst, and why are they important?

To thrive as an Application Security Analyst, you need a strong understanding of secure coding practices, vulnerability assessment, and information security principles, often supported by a degree in computer science or related certifications like CISSP or CEH. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing suites, and security information and event management (SIEM) systems is essential. Analytical thinking, attention to detail, and effective communication are critical soft skills for identifying risks and collaborating with development teams. These competencies are vital to proactively identifying vulnerabilities, minimizing risks, and ensuring robust application security in evolving technology environments.

What is the difference between Application Security Analyst vs Security Engineer?

AspectApplication Security AnalystSecurity Engineer
CertificationsCompTIA Security+, CISSP, CEHCISSP, CEH, Security+
Work EnvironmentFocus on application vulnerabilities, code reviews, and security assessmentsDesigns and implements security infrastructure, manages security tools
Industry UsageCommon in software development and IT teamsFound in cybersecurity teams across various industries
Primary FocusIdentifying and mitigating application security risksBuilding and maintaining security systems and protocols

While both roles involve cybersecurity, Application Security Analysts primarily focus on securing software applications through assessments and vulnerability management. Security Engineers work on developing and maintaining security infrastructure, ensuring overall organizational security. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What cities in Virginia are hiring for Application Security Analyst jobs?

Cities in Virginia with the most Application Security Analyst job openings:

Infographic showing various Application Security Analyst job openings in Virginia as of August 2026, with employment types broken down into 71% Full Time, 25% Part Time, and 4% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $82,900 per year, or $39.9 per hour.

Application Security Engineer (Full Scope Poly) with Security Clearance

Reston, VA β€’ On-site

Concept Plus LLC
51 - 200 employees

$61.25 - $81.75/hr

Contractor

Medical, Dental, Vision, Life, PTO

Posted 14 days ago


Job description

About Concept Plus Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm. Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty. We offer competitive pay, comprehensive health, dental, and vision insurance, paid life insurance, paid time off, 11 paid holidays, performance bonuses, tuition reimbursement, unlimited training, and the opportunity to thrive in a collaborative, flexible, and innovative environment. For more information, visit . About the role Concept Plus is seeking a highly experienced and motivated Application Security Engineer for an exciting new contract. This role is fully onsite in Reston, VA (5 days per week required). What you'll do This role will be part of a team of Data, Cloud, and Security engineers delivering a cloud-native, centralized platform that provides end-to-end budget traceability. The Application Security Engineer will integrate security throughout the software development lifecycle, partnering with developers and cloud engineers to design, build, assess, and sustain secure mission applications. Required Qualifications * US Citizen * Must possess a TS/SCI security clearance with Polygraph. * Technical expertise and hands-on experience in application security, secure software development, software engineering, or DevSecOps, with the ability to apply these skills to Oracle Cloud and customer mission challenges. * Experience integrating security throughout the software development lifecycle, including secure design and architecture reviews, threat modeling, secure code review, security testing, vulnerability remediation, and release authorization support. * Experience developing or reviewing applications using Python, JavaScript frameworks, SQL, Shell scripting, PL/SQL, and other programming languages, with a strong understanding of common application vulnerabilities and secure coding practices. * Experience with application security testing tools and processes, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and container or infrastructure vulnerability scanning. * Experience building and securing cloud-native applications and services using Kubernetes, containers, Docker, REST APIs, and CI/CD pipelines. * Experience implementing DevSecOps practices, including automated security controls and testing within build and deployment pipelines. * Experience with cloud-native security services and controls; Oracle Cloud Infrastructure (OCI) experience is desired. * Knowledge of security frameworks and standards such as NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, and applicable federal security requirements. * Experience securing Oracle RDBMS environments, including database access controls, encryption, auditing, and secure handling of sensitive data. * Ability to assess, prioritize, document, and communicate application and cloud security risks, findings, and remediation recommendations to both technical and non-technical stakeholders. * Passion for technology, curiosity, and willingness to continuously learn new security tools, techniques, and approaches for solving complex technical challenges. * Experience working in an Agile framework. * 8+ years of relevant experience in application security, software engineering, DevSecOps, cybersecurity, or a related technical discipline. * Bachelor's Degree in engineering, computer science or related technical discipline. Master's degree preferred. Preferred Qualifications * Oracle Cloud Infrastructure (OCI) IaaS and/or PaaS certifications are preferred. * Security certifications such as CISSP, CSSLP, Security+, GIAC, CEH, OSCP, or comparable credentials. * Experience implementing identity and access management, privileged access controls, secrets management, encryption, logging, monitoring, and incident response capabilities in cloud environments. * Experience with AI technologies for software development and securing AI-enabled applications or development workflows. * Data engineering experience, including securing data validations, business rules, data transformations, and sensitive-data handling. Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.