1

Application Security Engineer Jobs (NOW HIRING)

Application Security Engineer

Nashville, TN · On-site

$56.75 - $75.75/hr

The Application Security Engineer will serve as a trusted technical advisor, performing application security assessments, supporting secure software development practices, and helping engineering ...

Application Security Engineer

$60.25 - $80.25/hr

RIT Solutions, Inc. is seeking an Application Security Engineer to enhance the security of their ongoing AI development efforts. The role involves designing and implementing cloud and application ...

Application Security Engineer

Media, PA · On-site

$58.50 - $78/hr

Application Security Engineer Location: Corporate Department: Information Technology Job Summary: The Application Security Engineer is responsible for operating, supporting, maintaining, and ...

Application Security Engineer

Wawa, PA · On-site

$57.25 - $76.25/hr

Application Security Engineer Location: Corporate Department: Information Technology Job Summary: The Application Security Engineer is responsible for operating, supporting, maintaining, and ...

$43.25 - $58/hr

Zof AI is seeking an Application Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent ...

Application Security Engineer

$60.25 - $80.25/hr

The Application Security Engineer supports secure coding standards, threat modeling, static and dynamic testing, and secure secrets management. This position plays a critical role in strengthening ...

Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

Zof AI is seeking an Application Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent ...

NY · On-site

$54.25 - $72.50/hr

Security | Application Security Engineer SOFTSWISS is growing, and we are seeking a skilled Application Security Engineer to join our team. If you are driven by excellence and share our values, we ...

Application Security Engineer

Washington, DC · On-site

$66.50 - $89/hr

Work with application developers ensure adoption of security principals and best practices. 6. Provides direction and support in security management and security architecture standards and ...

APPLICATION SECURITY ENGINEER

Fairfax, VA · On-site

$60 - $80.25/hr

Application Security Engineer Location: Onsite in Fairfax, VA 3 days and in Washington, DC 2 days per week. Duration: Long Term Contract Positions Require a Secret Clearance The Application Security ...

Application Security Engineer

$60.25 - $80.25/hr

Application security engineer - threat & vulnerability management (ai focus) Us remote, cst zone Application security engineer - threat & vulnerability management (ai focus) Secure-by-design ...

Application Security Engineer

Saint Louis, MO · On-site

$57 - $76.25/hr

Application Security Engineer (Senior AppSec) Location: Remote Duration: 6-12+ Months Contract Role Overview We are seeking experienced Senior Application Security Engineers to join our team and play ...

next page

Showing results 1-20

Application Security Engineer information

See salary details

$29

$66

$96

How much do application security engineer jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for application security engineer in the United States is $66.40, according to ZipRecruiter salary data. Most workers in this role earn between $56.49 and $75.48 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What cities are hiring for Application Security Engineer jobs?

Cities with the most Application Security Engineer job openings:

What are the most commonly searched types of Application Security Engineer jobs?

The most popular types of Application Security Engineer jobs are:

Who are the top companies hiring for Application Security Engineer jobs?

The top employers for Application Security Engineer jobs are:

What states have the most Application Security Engineer jobs?

States with the most job openings for Application Security Engineer jobs include:

What are popular job titles related to Application Security Engineer jobs?

For Application Security Engineer jobs, the most frequently searched job titles are:

Infographic showing various Application Security Engineer job openings in the United States as of September 2026, with employment types broken down into 56% Full Time, and 44% Contract. Highlights an 78% In-person, and 22% Hybrid job distribution, with an average salary of $138,117 per year, or $66.4 per hour.

Application Security Engineer

Reston, VA • On-site

Bespoke Technologies, Inc.
Recruiting and Staffing Services • 11 - 50 employees

$61 - $81.75/hr

Other

Posted 18 days ago


Job description

BT-411 – Application Security Engineer

Location: Reston, VA

Please do NOT apply if you do not have an active Poly clearance. Those without a Poly will not be considered.

Bespoke Technologies is seeking a highly experienced and motivated Application Security Engineer for an exciting new contract. This role will be part of a team of Data, Cloud, and Security engineers delivering a cloud-native, centralized platform that provides end-to-end budget traceability. The Application Security Engineer will integrate security throughout the software development lifecycle, partnering with developers and cloud engineers to design, build, assess, and sustain secure mission applications.

Required Skills and Qualifications:
  • Technical expertise and hands‑on experience in application security, secure software development, software engineering, or DevSecOps, with the ability to apply these skills to Oracle Cloud and customer mission challenges.
  • Experience integrating security throughout the software development lifecycle, including secure design and architecture reviews, threat modeling, secure code review, security testing, vulnerability remediation, and release authorization support.
  • Experience with application security testing tools and processes, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and container or infrastructure vulnerability scanning.
  • Experience building and securing cloud‑native applications and services using Kubernetes, containers, Docker, REST APIs, and CI/CD pipelines.
  • Experience implementing DevSecOps practices, including automated security controls and testing within build and deployment pipelines.
  • Experience with cloud‑native security services and controls; Oracle Cloud Infrastructure (OCI) experience is desired.
  • Knowledge of security frameworks and standards such as NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, and applicable federal security requirements.
  • Experience securing Oracle RDBMS environments, including database access controls, encryption, auditing, and secure handling of sensitive data.
  • Ability to assess, prioritize, document, and communicate application and cloud security risks, findings, and remediation recommendations to both technical and non‑technical stakeholders.
  • Passion for technology, curiosity, and willingness to continuously learn new security tools, techniques, and approaches for solving complex technical challenges.
  • Experience working in an Agile framework.
BT-411 – Application Security Engineer

Location: Reston, VA

Please do NOT apply if you do not have an active Poly clearance. Those without a Poly will not be considered.

Bespoke Technologies is seeking a highly experienced and motivated Application Security Engineer for an exciting new contract. This role will be part of a team of Data, Cloud, and Security engineers delivering a cloud-native, centralized platform that provides end-to-end budget traceability. The Application Security Engineer will integrate security throughout the software development lifecycle, partnering with developers and cloud engineers to design, build, assess, and sustain secure mission applications.

Required Skills and Qualifications:
  • Technical expertise and hands‑on experience in application security, secure software development, software engineering, or DevSecOps, with the ability to apply these skills to Oracle Cloud and customer mission challenges.
  • Experience integrating security throughout the software development lifecycle, including secure design and architecture reviews, threat modeling, secure code review, security testing, vulnerability remediation, and release authorization support.
  • Experience developing or reviewing applications using Python, JavaScript frameworks, SQL, Shell scripting, PL/SQL, and other programming languages, with a strong understanding of common application vulnerabilities and secure coding practices.
  • Experience with application security testing tools and processes, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and container or infrastructure vulnerability scanning.
  • Experience building and securing cloud‑native applications and services using Kubernetes, containers, Docker, REST APIs, and CI/CD pipelines.
  • Experience implementing DevSecOps practices, including automated security controls and testing within build and deployment pipelines.
  • Experience with cloud‑native security services and controls; Oracle Cloud Infrastructure (OCI) experience is desired.
  • Knowledge of security frameworks and standards such as NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, and applicable federal security requirements.
  • Experience securing Oracle RDBMS environments, including database access controls, encryption, auditing, and secure handling of sensitive data.
  • Ability to assess, prioritize, document, and communicate application and cloud security risks, findings, and remediation recommendations to both technical and non‑technical stakeholders.
  • Passion for technology, curiosity, and willingness to continuously learn new security tools, techniques, and approaches for solving complex technical challenges.
  • Experience working in an Agile framework.
Desired Skills and Qualifications:
  • Oracle Cloud Infrastructure (OCI) IaaS and/or PaaS certifications are preferred.
  • Security certifications such as CISSP, CSSLP, Security+, GIAC, CEH, OSCP, or comparable credentials.
  • Experience implementing identity and access management, privileged access controls, secrets management, encryption, logging, monitoring, and incident response capabilities in cloud environments.
  • Experience with AI technologies for software development and securing AI‑enabled applications or development workflows.
  • Data engineering experience, including securing data validations, business rules, data transformations, and sensitive‑data handling.
Required Credentials and Experience:
  • 8+ years of relevant experience in application security, software engineering, DevSecOps, cybersecurity, or a related technical discipline.
  • Bachelor’s Degree in engineering, computer science or related technical discipline. Master’s degree preferred.
#J-18808-Ljbffr