1

Application Security Engineer Jobs in Maryland (NOW HIRING)

APPLICATION SECURITY ENGINEER

Rockville, MD ยท On-site

$100 - $130/hr

The Application Security Engineer (ASE) is responsible for promoting, designing, and evaluating application security in all phases of the application life cycle. The ASE shall ensure that appropriate ...

$87 - $198/hr

R0246153 Application Security Engineer The Opportunity: Integrate security practices throughout the soft software development lifecycle to enhance and maintain the security posture of software. Apply ...

Application Security

Bethesda, MD

$63 - $84/hr

Proactively work with team members to address security and compliance issues Provide education and assistance to application developers for applying Security Software Development Life Cycle ...

Cloud Security Engineer with a specific focus on secure Azure management, application hosting, and ... Application Security / DevSecOps Analyst, SaaS security administration, cloud tool operations, SIEM ...

Lead Security Engineer

Suitland, MD ยท On-site

$120K - $190K/yr

Suitland, MD We are seeking a Subject Matter Expert (SME)-level Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program. This role ...

Suitland, MD We are seeking a Subject Matter Expert (SME)-level Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program. This role ...

Suitland, MD We are seeking a Subject Matter Expert (SME)-level Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program. This role ...

Lead Security Engineer

Suitland, MD ยท On-site

$120K - $190K/yr

Suitland, MD We are seeking a Subject Matter Expert (SME)-level Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program. This role ...

$125.30 - $233/hr

Application Security Senior Manager The Opportunity: Establish and grow Booz Allen's Application ... Educate and influence client software engineering teams on cybersecurity best practices. Assist ...

next page

Showing results 1-20

Application Security Engineer information

See Maryland salary details

$28

$64

$93

How much do application security engineer jobs pay per hour?

As of Aug 24, 2026, the average hourly pay for application security engineer in Maryland is $64.45, according to ZipRecruiter salary data. Most workers in this role earn between $54.81 and $73.27 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are the most commonly searched types of Application Security Engineer jobs in Maryland?

The most popular types of Application Security Engineer jobs in Maryland are:

What are popular job titles related to Application Security Engineer jobs in Maryland?

For Application Security Engineer jobs in Maryland, the most frequently searched job titles are:

What job categories do people searching Application Security Engineer jobs in Maryland look for?

The top searched job categories for Application Security Engineer jobs in Maryland are:

What cities in Maryland are hiring for Application Security Engineer jobs?

Cities in Maryland with the most Application Security Engineer job openings:

What are popular job titles related to Application Security Engineer jobs in MD?

For Application Security Engineer jobs in MD, the most frequently searched job titles are:

Infographic showing various Application Security Engineer job openings in Maryland as of August 2026, with employment types broken down into 87% Full Time, 2% Part Time, and 11% Contract. Highlights an 86% In-person, 2% Hybrid, and 12% Remote job distribution, with an average salary of $134,048 per year, or $64.4 per hour.

APPLICATION SECURITY ENGINEER

Rockville, MD โ€ข On-site

Target Labs, Inc
1 - 10 employees

$100 - $130/hr

Other

Posted 6 days ago


Job description

The Application Security Engineer (ASE) is responsible for promoting, designing, and evaluating application security in all phases of the application life cycle. The ASE shall ensure that appropriate and effective security techniques and solutions are identified, implemented, and used.

Essential Job Functions:

Software Security Assessment:

- Evaluate applications for appropriate and effective use of security controls using tools and techniques such as source code analysis, vulnerability scanners, and manual testing techniques..

Application Security Control Development:

- Provide expert guidance to developers on the appropriate selection and implementation of relevant application security controls.

Security Awareness Training:

- Design, develop and deliver presentations focused on raising awareness for crucial security relevant considerations and defensive programming techniques.

Contract Security Provision Review:

- Work with business stakeholders and legal services to evaluate service agreements with Application Service Providers (ASPs), and provide expert guidance related to security provisions necessary to help ensure the necessary visibility and rights needed to protect our data and meet our commitments.

Other Job Functions:

Participate in research of information security technologies (in the areas of application and application infrastructure components) and propose ideas for new security service development. Participate in all aspects of security service development projects including the following project phases: business case development, requirements gathering, architecture development, product/service selection and procurement, functional & QA testing, detailed technical design, technology infrastructure implementation and deployment, migration from existing services, operational process and procedure documentation, operations staff training, and internal marketing of security services. Advise and consult internal clients on appropriate application of security practices and existing security services to solve problems or enable new business opportunities. Deliver previously developed information security services in support of corporate needs including: requirements gathering, technical design, service deployment and integration, migration, operational transition, end user documentation, user training. In support of various enterprise IT initiatives, recommend, customize, implement, document, and transition to operations reusable technical security service components including application level intrusion detection systems, authentication systems, authorization systems, audit trail management systems, cryptographic systems, and others as defined by management. Research and implement new security technologies to be used as point solutions for IT initiatives unable to take advantage of or needing greater functionality than reusable enterprise security services. Recommend new security service development ideas based on accumulated knowledge of project-specific security requirements. Identify and implement improvements to application security team processes and supporting software tools (Java and C#/ASP based) to continually improve the teamโ€™s effectiveness and efficiency. Serve as subject matter expert on application and information security technologies and methodologies. Perform other duties and responsibilities as assigned.

Essential Education/Experience Requirements:

- Bachelor of Science in Computer Science, or equivalent education or experience. Emphasis in software security a plus.

At least three (3) years of professional experience, including:

- Two (2) or more years in software engineering and development with emphasis on the delivery of secure, Internet-exposed, multi-tier, web-based systems using Java/J2EE and/or C#/ASP/.NET (experience with both a plus)..

- At least one (1) year of hands-on experience evaluating the security of applications using both manual and automated techniques. Relevant tool experience should include code security scanners such as Fortify SCA, web vulnerability scanners such as HP WebInspect or IBM Rational AppScan, assessment support tools such as BurpSuite, Metasploit, Core Impact, etcโ€ฆ .

Strong written and verbal communication skills. Specific relevant experience may include technical reports (especially application security assessment reports), technical whitepapers, presentation development and delivery (for both technical and business audiences), technical training, etc. Candidate should have experience making and defending sound technical arguments that incorporate relevant technical and business considerations, and building consensus among stakeholders

Other Desirable Experience:

Security-related experience with the following:

- Providing software architecture security guidance, including developing application threat models and methodically protecting against business logic and design flaws that could introduce security vulnerabilities.

- Web Application Firewalls such as Imperva SecureSphere and Breach WebDefend.

- Design patterns and coding standards for secure software.

- Secure configuration and operation of Application Servers, Web Servers, Directory Servers, Media/Content Servers, Messaging Servers, Database Servers, and Integration Servers.

- Application authentication & authorization systems such as RSA ClearTrust and Netegrity Siteminder.

- Application layer intrusion detection systems such as Sanctum AppShield, or Kavado.

- Knowledge of PKI systems such as RSA Keon.

- Knowledge of cryptographic tool kits for application development such as RSA BSAFE or others.

- Knowledge of and experience with built-in and add-on security capabilities of common application infrastructure components such as MS SQLServer, Oracle, MS IIS, iPlanet Directory, MS Active Directory, MQSeries, MSMQ, MS Exchange.

- Knowledge of general application security API's and protocols such as: MS CryptoAPI, Kerberos, SSL/TLS, SAML, S/MIME, and PKCS API's.

- End-to-end, hands-on experience in security solutions for complex enterprise architectures.

- Knowledge of cryptographic solutions for protection of data in use, in transit and at rest, such as: Masking, SSL/TLS, IPSec, format preserving encryption & sanitization, etcโ€ฆ.

- Knowledge of security considerations related to virtualization and cloud computing.

- Mobile Application Security on iOS and/or Android devices; includes experience in secure development of applications and/or analysis.

Financial services industry (Insurance, Banking, Investments) experience a plus.

#J-18808-Ljbffr