Support the assessment, design, and implementation of application security for Oracle Cloud ERP, ... Work you'll do As a Security Engineer II on the Cyber Enterprise Security team, you will be ...
Support the assessment, design, and implementation of application security for Oracle Cloud ERP, ... Work you'll do As a Security Engineer II on the Cyber Enterprise Security team, you will be ...
Coordinate assessment lifecycles with system owners, developers, QA, and cybersecurity stakeholders ... Web application security, penetration testing, or secure development experience with at least 3 ...
Coordinate assessment lifecycles with system owners, developers, QA, and cybersecurity stakeholders ... Web application security, penetration testing, or secure development experience with at least 3 ...
Support the assessment, design, and implementation of application security for Oracle Cloud ERP, ... Work you'll do As a Security Engineer II on the Cyber Enterprise Security team, you will be ...
Support the assessment, design, and implementation of application security for Oracle Cloud ERP, ... Work you'll do As a Security Engineer II on the Cyber Enterprise Security team, you will be ...
Information Systems Security Engineer (ISSE)
Herndon, VA · On-site
$140K - $190K/yr
... application of Agency security policy and enterprise solutions. • Apply system security engineering expertise in one or more of the following to: system security design process; engineering life ...
Quick apply
Information Systems Security Engineer (ISSE)
Herndon, VA · On-site
$140K - $190K/yr
... application of Agency security policy and enterprise solutions. • Apply system security engineering expertise in one or more of the following to: system security design process; engineering life ...
Required : • 4 to 7+ years' experience in one or more of the following areas: • Application ... engineering team to implement security requirements • Agile / Scrum • Active TS/SCI with Poly ...
Required : • 4 to 7+ years' experience in one or more of the following areas: • Application ... engineering team to implement security requirements • Agile / Scrum • Active TS/SCI with Poly ...
... application of Agency security policy and enterprise solutions. • Apply system security engineering expertise in one or more of the following to: system security design process; engineering life ...
... application of Agency security policy and enterprise solutions. • Apply system security engineering expertise in one or more of the following to: system security design process; engineering life ...
Sr. Principal Systems Security Engineer
Dulles, VA · On-site
$113K - $155K/yr
Experience in Application Security, Software Development, DevOps, Vulnerability Management and/or related field * Experience with Cloud Security and Best Practices * Strong understanding of Event ...
Sr. Principal Systems Security Engineer
Dulles, VA · On-site
$113K - $155K/yr
Experience in Application Security, Software Development, DevOps, Vulnerability Management and/or related field * Experience with Cloud Security and Best Practices * Strong understanding of Event ...
Application security * Identity and Access Management (IAM) * Encryption technologies * Experience with vulnerability scanning, security assessment, and penetration testing tools. * Familiarity with ...
Quick apply
Application security * Identity and Access Management (IAM) * Encryption technologies * Experience with vulnerability scanning, security assessment, and penetration testing tools. * Familiarity with ...
... Dynamic & Static Application Security Scanning (e.g., Arachni, OWASP ZAP, BurpSuite, Fortify ... At KBR, we deliver science, technology and engineering solutions that are helping governments and ...
... Dynamic & Static Application Security Scanning (e.g., Arachni, OWASP ZAP, BurpSuite, Fortify ... At KBR, we deliver science, technology and engineering solutions that are helping governments and ...
Information Systems Security Engineer (ISSE) - TS/SCI W/Poly - Tysons, Va
Chantilly, VA · On-site
$100K/yr
... Engineer (ISSE) to join our dynamic team in Chantilly, Va. The ISSE will play a critical role in ... Application security standards and processes. * Accreditation and Authorization (A&A), including ...
Information Systems Security Engineer (ISSE) - TS/SCI W/Poly - Tysons, Va
Chantilly, VA · On-site
$100K/yr
... Engineer (ISSE) to join our dynamic team in Chantilly, Va. The ISSE will play a critical role in ... Application security standards and processes. * Accreditation and Authorization (A&A), including ...
Application security standards and processes • 4 to 7+ years' experience in one or more of the ... Coordination with engineering team to implement security requirements • 4 to 7+ years' experience ...
Application security standards and processes • 4 to 7+ years' experience in one or more of the ... Coordination with engineering team to implement security requirements • 4 to 7+ years' experience ...
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME (VIRTUALIZATION AND APPLICATION DEVELOPMENT ...
Arlington, VA · On-site
Leverage AI-assisted analysis tools, automation platforms, and prompt engineering techniques to ... Expert-level mastery of application security architecture including ZT application access control ...
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME (VIRTUALIZATION AND APPLICATION DEVELOPMENT ...
Arlington, VA · On-site
Leverage AI-assisted analysis tools, automation platforms, and prompt engineering techniques to ... Expert-level mastery of application security architecture including ZT application access control ...
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME (VIRTUALIZATION AND APPLICATION DEVELOPMENT ...
Arlington, VA · Remote
Leverage AI-assisted analysis tools, automation platforms, and prompt engineering techniques to ... Expert-level mastery of application security architecture including ZT application access control ...
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME (VIRTUALIZATION AND APPLICATION DEVELOPMENT ...
Arlington, VA · Remote
Leverage AI-assisted analysis tools, automation platforms, and prompt engineering techniques to ... Expert-level mastery of application security architecture including ZT application access control ...
Security Engineer
Roanoke, VA · Remote
Partner with infrastructure and application teams to prioritize and mitigate risks * Contribute to ... Help drive security awareness across engineering teams Key Skills * Identity and access management ...
Security Engineer
Roanoke, VA · Remote
Partner with infrastructure and application teams to prioritize and mitigate risks * Contribute to ... Help drive security awareness across engineering teams Key Skills * Identity and access management ...
Dynamic & Static Application Security Scanning (e.g., Arachni, OWASP ZAP, BurpSuite, Fortify ... Information Systems Security Engineering Professional (ISSEP) * DOD Information Technology Security ...
Dynamic & Static Application Security Scanning (e.g., Arachni, OWASP ZAP, BurpSuite, Fortify ... Information Systems Security Engineering Professional (ISSEP) * DOD Information Technology Security ...
Dynamic & Static Application Security Scanning (e.g., Arachni, OWASP ZAP, BurpSuite, Fortify ... Information Systems Security Engineering Professional (ISSEP) * DOD Information Technology Security ...
Dynamic & Static Application Security Scanning (e.g., Arachni, OWASP ZAP, BurpSuite, Fortify ... Information Systems Security Engineering Professional (ISSEP) * DOD Information Technology Security ...
Dynamic & Static Application Security Scanning (e.g., Arachni, OWASP ZAP, BurpSuite, Fortify ... Information Systems Security Engineering Professional (ISSEP) * DOD Information Technology Security ...
Dynamic & Static Application Security Scanning (e.g., Arachni, OWASP ZAP, BurpSuite, Fortify ... Information Systems Security Engineering Professional (ISSEP) * DOD Information Technology Security ...
Partner with product owners, developers, and quality assurance teams to embed security requirements ... Perform functional application security testing to validate authentication, authorization, session ...
Partner with product owners, developers, and quality assurance teams to embed security requirements ... Perform functional application security testing to validate authentication, authorization, session ...
Cloud Security Engineer (Secret Clearance)
Arlington, VA · On-site
$64.25 - $85.75/hr
As a Cloud Security Engineer, you will help assess and enhance security across Amazon Web Services ... cyber cloud capabilities, application security, and security for emerging technologies and ...
Cloud Security Engineer (Secret Clearance)
Arlington, VA · On-site
$64.25 - $85.75/hr
As a Cloud Security Engineer, you will help assess and enhance security across Amazon Web Services ... cyber cloud capabilities, application security, and security for emerging technologies and ...
Application DevSecOps Engineer (1016) with Security Clearance
$55.75 - $74.50/hr
The engineer will design and implement CI/CD pipelines using GitLab, Terraform, and Ansible to automate deployment and integrate security tools, ensuring the rapid and secure release of software ...
Application DevSecOps Engineer (1016) with Security Clearance
$55.75 - $74.50/hr
The engineer will design and implement CI/CD pipelines using GitLab, Terraform, and Ansible to automate deployment and integrate security tools, ensuring the rapid and secure release of software ...
Application Security Engineer information
See Virginia salary details
$29.55 - $35.55
1% of jobs
$35.55 - $41.55
1% of jobs
$41.55 - $47.56
2% of jobs
$47.56 - $53.56
13% of jobs
$55.74 is the 25th percentile. Wages below this are outliers.
$53.56 - $59.56
23% of jobs
The median wage is $63.85 / hr.
$59.56 - $65.56
15% of jobs
$65.56 - $71.56
16% of jobs
$73.70 is the 75th percentile. Wages above this are outliers.
$71.56 - $77.56
15% of jobs
$77.56 - $83.56
7% of jobs
$83.56 - $89.57
4% of jobs
$89.57 - $95.57
4% of jobs
$29
$65
$95
How much do application security engineer jobs pay per hour?
What Does an Application Security Engineer Do?
An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.
What are some common challenges faced by Application Security Engineers when integrating security into the software development lifecycle?
What does an Application Security Engineer do?
What are the key skills and qualifications needed to thrive as an Application Security Engineer, and why are they important?
What is the difference between Application Security Engineer vs Security Analyst?
| Aspect | Application Security Engineer | Security Analyst |
|---|---|---|
| Certifications | CEH, CISSP, OSCP | CISSP, Security+ |
| Work Environment | Develops security measures, reviews code, tests applications | Monitors security systems, investigates incidents, analyzes threats |
| Industry Usage | Tech companies, software firms, organizations with strong app focus | Broad sectors including finance, healthcare, government |
Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.
- Offensive Security Engineer Remote
- Physical Security Engineer
- Senior Information Security Engineer
- Product Security Engineer
- Trainee Application Security Engineer
- Internship Application Security Engineer
- Freelance Offensive Security Engineer
- Chronicle Siem
- Remote Physical Security Engineer
- Azure Security Engineer
Other
Posted 22 days ago
Deloitte rating
8.1
Based on 86 frontline employees who took The Breakroom Quiz
58th of 138 rated financial services
Job description
Cyber Oracle Cloud Security - Consultant / Security Engineer II
Deloitte's Cyber team helps organizations address complex cybersecurity challenges while supporting resilient, secure growth. In this role, you will support Oracle Cloud security engagements focused on application security, governance, risk, and compliance across Enterprise Resource Planning (ERP), Human Capital Management (HCM), and Supply Chain Management (SCM) environments. You will work with clients to assess risks, design controls, and implement security solutions that strengthen business processes and cloud operations.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Security Engineer II on the Cyber Enterprise Security team, you will be responsible for supporting Oracle Cloud security and controls engagements across client environments.
- Support the assessment, design, and implementation of application security for Oracle Cloud ERP, HCM, SCM, and business process controls environments
- Participate in security design workshops and help translate business and technical requirements into Oracle Cloud security configurations
- Design and configure Oracle Cloud roles across functional areas, including Financials, SCM, HCM, and Enterprise Performance Management (EPM)
- Support the design and implementation of automated controls and governance, risk, and compliance solutions, including Oracle Risk Management Cloud
- Identify business process risks and control considerations and contribute to security-focused implementation and assessment activities
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Our Enterprise Security Offering helps clients embed security across digital transformation efforts by securing core technology environments while enabling business change. The team works across security architecture, secure development and deployment, cloud security, application security, and emerging technology risks. Professionals in this practice help organizations strengthen security capabilities while supporting large-scale transformation programs.
Qualifications
Required:
- Bachelor of Arts or Bachelor of Science degree in Computer Science, Cyber Security, Information Security, Engineering, Information Technology, Management Information Systems, Finance, Accounting and Technology, or Business
- 2+ years of experience on large, complex projects with multiple country or regional rollouts, including support for security design workshops
- 2+ years of experience designing Oracle Cloud roles across Oracle Cloud Financials, Supply Chain Management, Human Capital Management, or Enterprise Performance Management
- 2+ years of experience with business process risk and controls design
- 2+ years of experience designing, configuring, and implementing Oracle Risk Management Cloud
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Experience in consulting or Big 4 environments
- Certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA)
- Experience supporting end-to-end Oracle Cloud security and controls implementations across ERP, HCM, SCM, or EPM
- Experience with Oracle Cloud Infrastructure (OCI) security
- Experience with Segregation of Duties (SOD), personally identifiable information (PII), and Sarbanes-Oxley (SOX) control frameworks
- Experience with Single Sign-On (SSO), Multi-Factor Authentication (MFA), Oracle Identity Cloud Service (IDCS), or data protection tools
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Cyber Oracle Cloud Security - Consultant / Security Engineer II
Deloitte's Cyber team helps organizations address complex cybersecurity challenges while supporting resilient, secure growth. In this role, you will support Oracle Cloud security engagements focused on application security, governance, risk, and compliance across Enterprise Resource Planning (ERP), Human Capital Management (HCM), and Supply Chain Management (SCM) environments. You will work with clients to assess risks, design controls, and implement security solutions that strengthen business processes and cloud operations.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Security Engineer II on the Cyber Enterprise Security team, you will be responsible for supporting Oracle Cloud security and controls engagements across client environments.
- Support the assessment, design, and implementation of application security for Oracle Cloud ERP, HCM, SCM, and business process controls environments
- Participate in security design workshops and help translate business and technical requirements into Oracle Cloud security configurations
- Design and configure Oracle Cloud roles across functional areas, including Financials, SCM, HCM, and Enterprise Performance Management (EPM)
- Support the design and implementation of automated controls and governance, risk, and compliance solutions, including Oracle Risk Management Cloud
- Identify business process risks and control considerations and contribute to security-focused implementation and assessment activities
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Our Enterprise Security Offering helps clients embed security across digital transformation efforts by securing core technology environments while enabling business change. The team works across security architecture, secure development and deployment, cloud security, application security, and emerging technology risks. Professionals in this practice help organizations strengthen security capabilities while supporting large-scale transformation programs.
Qualifications
Required:
- Bachelor of Arts or Bachelor of Science degree in Computer Science, Cyber Security, Information Security, Engineering, Information Technology, Management Information Systems, Finance, Accounting and Technology, or Business
- 2+ years of experience on large, complex projects with multiple country or regional rollouts, including support for security design workshops
- 2+ years of experience designing Oracle Cloud roles across Oracle Cloud Financials, Supply Chain Management, Human Capital Management, or Enterprise Performance Management
- 2+ years of experience with business process risk and controls design
- 2+ years of experience designing, configuring, and implementing Oracle Risk Management Cloud
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Experience in consulting or Big 4 environments
- Certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA)
- Experience supporting end-to-end Oracle Cloud security and controls implementations across ERP, HCM, SCM, or EPM
- Experience with Oracle Cloud Infrastructure (OCI) security
- Experience with Segregation of Duties (SOD), personally identifiable information (PII), and Sarbanes-Oxley (SOX) control frameworks
- Experience with Single Sign-On (SSO), Multi-Factor Authentication (MFA), Oracle Identity Cloud Service (IDCS), or data protection tools
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.