1

Application Security Engineer Jobs in Virginia (NOW HIRING)

Security Engineer, AWS AppSec

Herndon, VA ยท On-site

$60.50 - $80.75/hr

AWS Security is looking for an Application Security Engineer to help validate that our services, applications, and websites are designed and implemented to the highest security standards. You will be ...

Security Engineer, AWS AppSec

Herndon, VA ยท On-site

$60.50 - $80.75/hr

AWS Security is looking for an Application Security Engineer to help validate that our services, applications, and websites are designed and implemented to the highest security standards. You will be ...

Security Engineer, AWS AppSec

Herndon, VA

$60.50 - $80.75/hr

AWS Security is looking for an Application Security Engineer to help validate that our services, applications, and websites are designed and implemented to the highest security standards. You will be ...

Senior Security Engineer, Application Position location: Richmond, Va., Lynchburg, Va. This position is available to Virginia residents as Richmond or Lynchburg, Virginia in-office applicants *A ...

Senior Engineer, Application Security

Tysons, VA ยท On-site

$59.50 - $79.25/hr

We're seeking a senior, builder-minded Application Security Engineer who can go deep on hard technical problems while setting the direction for how AI reshapes a security program. This isn't someone ...

AppSec Security Engineer

Arlington, VA ยท On-site

$67.50 - $90.25/hr

None POSITION SUMMARY STATEMENT We are seeking an experienced Application Security Engineer to build, mature, and scale our AppSec program. In this role, you will embed directly with our Product and ...

Security Engineer (Mobile) Location: Arlington, VA Security Clearance:Secret Duties and ... Review of mobile application code and conduct testing using both Information Assurance ...

At least five (5) years of experience performing application security testing. * At least three (3) ... Strong programming languages background such as Python, Java, PowerShell, C#, C++, JavaScript.

Perform Static Application Security Testing (SAST) toidentifypotential vulnerabilities in the ... Work with DevOps teams to securely harden Linux based machines and cloudinfrastructure Basic ...

... Application Security Engineer, Identity and Access Management Engineer, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...

Showing results 21-40

Application Security Engineer information

See Virginia salary details

$29

$65

$95

How much do application security engineer jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for application security engineer in Virginia is $65.83, according to ZipRecruiter salary data. Most workers in this role earn between $56.01 and $74.86 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are the most commonly searched types of Application Security Engineer jobs in Virginia?

The most popular types of Application Security Engineer jobs in Virginia are:

What job categories do people searching Application Security Engineer jobs in Virginia look for?

The top searched job categories for Application Security Engineer jobs in Virginia are:

What cities in Virginia are hiring for Application Security Engineer jobs?

Cities in Virginia with the most Application Security Engineer job openings:

What are popular job titles related to Application Security Engineer jobs in VA?

For Application Security Engineer jobs in VA, the most frequently searched job titles are:

Infographic showing various Application Security Engineer job openings in Virginia as of August 2026, with employment types broken down into 71% Full Time, 25% Part Time, and 4% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $136,932 per year, or $65.8 per hour.

Staff Application Security Engineer - AI & Agentic Systems

Hispanic Alliance for Career Enhancement

Richmond, VA โ€ข On-site

$107 - $284/hr

Other

Medical, Dental, Vision, Retirement, PTO

This job post hasย expired 1 day ago.ย Applications are no longer accepted.


Job description

We're building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Healthยฎ, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger - helping to simplify health care one person, one family and one community at a time.

Position Summary

We are seeking a Staff Application Security Engineer - AI & Agentic Systems to help secure the next generation of AI-enabled applications, large language model integrations, and agentic systems. This role will partner closely with engineering, product, platform, and data teams to embed security into the design, development, and operation of both traditional and AI-driven solutions.

As a senior technical contributor, you will help define secure design patterns, conduct threat modeling and risk assessments, guide engineering teams on secure development practices, and support the adoption of responsible AI security controls across the enterprise.

Key Responsibilities Secure Development, Standards & Design
  • Develop and maintain application and AI security standards, best practices, and guardrails.
  • Promote secure-by-design principles across application and AI development lifecycles.
  • Establish secure design patterns for AI agents, prompt management, tool integrations, memory handling, and autonomous workflows.
  • Partner with engineering teams to identify and mitigate AI-specific security risks such as prompt injection, model abuse, data leakage, and unauthorized agent actions.
AI & Agentic Security Architecture
  • Serve as a subject matter expert supporting the security of AI-enabled applications and agentic systems.
  • Review and provide guidance on architectures utilizing large language models, retrieval augmented generation pipelines, AI agents, and AI-powered workflows.
  • Define and recommend identity, authorization, data protection, observability, and governance controls for AI environments.
  • Collaborate with AI platform, engineering, product, and data teams to ensure secure and responsible AI adoption.
Security Testing & Risk Management
  • Perform threat modeling, architecture reviews, and security assessments for applications and AI-enabled systems.
  • Conduct security analysis of AI workflows, model integrations, agent interactions, and data flows.
  • Partner with engineering teams to prioritize and remediate security findings.
  • Evaluate emerging AI security tools and technologies to improve organizational security posture.
Collaboration & Technical Leadership
  • Influence engineering teams to integrate security controls into development processes and product roadmaps.
  • Partner with privacy, compliance, legal, and risk teams to align security controls with organizational requirements.
  • Provide guidance on AI security considerations, emerging threats, and industry best practices.
  • Participate in strategic initiatives supporting secure AI adoption across the enterprise.
Incident Response & Continuous Improvement
  • Support investigation and response efforts involving application and AI-related security events.
  • Assist in identifying root causes and implementing long-term security improvements.
  • Drive continuous improvement of security controls, processes, and engineering practices.
Mentorship & Innovation
  • Mentor security engineers and development teams on secure coding, threat modeling, and AI security best practices.
  • Contribute to the evaluation of emerging AI security research, technologies, and industry standards.
  • Help advance the organization's application and AI security strategy through innovation and technical leadership.
Required Qualifications
  • 7+ years of experience designing, building, or securing enterprise-scale applications and platforms.
  • 5+ years of application security experience, including threat modeling, secure design, code review, and vulnerability management.
  • 5+ years of programming experience in one or more languages such as Python, Java, JavaScript, C#, or Go.
  • 3+ years of experience developing or securing AI, machine learning, or generative AI solutions.
  • 3+ years of experience with public cloud platforms including AWS, Azure, or Google Cloud Platform.
Preferred Qualifications
  • Experience securing modern application architectures, including APIs, containers, microservices, and serverless technologies.
  • Strong understanding of secure software development lifecycle practices and application security testing methodologies.
  • Handsโ€‘on experience securing AI agents, retrieval augmented generation solutions, and large language model integrations.
  • Experience conducting threat modeling and security assessments for AI-enabled systems.
  • Familiarity with responsible AI principles, AI governance, and emerging AI security frameworks.
  • Experience integrating security controls into continuous integration and continuous delivery pipelines.
  • Knowledge of common compliance frameworks such as PCI DSS, HIPAA, NIST, HITRUST, and CSA.
  • Ability to influence technical decisions across multiple teams and organizations.
  • Experience contributing to security research, openโ€‘source projects, or industry communities.
Education
  • Bachelor's degree from an accredited college or university, or equivalent combination of education and relevant work experience (High School Diploma/GED plus 4 years of related experience)

Health100 is America's trusted front door to health and care. The Health100 platform integrates any participating health plan, PBM, pharmacy (retail and specialty), provider, digital health point solution provider, and employer, and addresses the top health care challenges for the consumer.

Pay Range

The typical pay range for this role is:

$106,605.00 - $284,280.00

This pay range represents the base hourly rate or base annual fullโ€‘time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or shortโ€‘term incentive program in addition to the base pay range listed above. This position also includes an award target in the company's equity award program.

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This fullโ€‘time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial wellโ€‘being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.

Additional details about available benefits are provided during the application process and on Benefits Moments.

We anticipate the application window for this opening will close on: 08/24/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

#J-18808-Ljbffr