1

Application Security Engineer Jobs in Virginia (NOW HIRING)

Perform Static Application Security Testing (SAST) toidentifypotential vulnerabilities in the ... Work with DevOps teams to securely harden Linux based machines and cloudinfrastructure Basic ...

... Application Security Engineer, Identity and Access Management Engineer, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...

... Application Security Engineer, Identity and Access Management Engineer, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...

... Application Security Engineer, Identity and Access Management Engineer, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...

Cloud Security Engineer

Arlington, VA · On-site

$140K - $170K/yr

We're looking for a security engineer who understands vulnerability management as an end-to-end ... Partner with platform, cloud, and application teams to drive sustainable remediation outcomes

Our client is currently seeking a Security Engineer - IV [ Additional Description ] ****Working ... Devise mitigation techniques for application and system owners. Follow up on resolution of ...

Showing results 41-60

Application Security Engineer information

See Virginia salary details

$29

$65

$95

How much do application security engineer jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for application security engineer in Virginia is $65.83, according to ZipRecruiter salary data. Most workers in this role earn between $56.01 and $74.86 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are the most commonly searched types of Application Security Engineer jobs in Virginia?

The most popular types of Application Security Engineer jobs in Virginia are:

What are popular job titles related to Application Security Engineer jobs in Virginia?

For Application Security Engineer jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Application Security Engineer jobs in Virginia look for?

The top searched job categories for Application Security Engineer jobs in Virginia are:

What cities in Virginia are hiring for Application Security Engineer jobs?

Cities in Virginia with the most Application Security Engineer job openings:

What are popular job titles related to Application Security Engineer jobs in VA?

For Application Security Engineer jobs in VA, the most frequently searched job titles are:

Infographic showing various Application Security Engineer job openings in Virginia as of September 2026, with employment types broken down into 62% Full Time, and 38% Contract. Highlights an 82% In-person, and 18% Hybrid job distribution, with an average salary of $136,932 per year, or $65.8 per hour.

Engineer II, Cybersecurity - Application Security

Richmond, VA • On-site

Carmax
Automobile Dealers • 10K+ employees

$80K - $120K/yr

Full-time

PTO

Re-posted 16 days ago


CarMax rating

7.9

Company rating: 7.9 out of 10

Based on 378 frontline employees who took The Breakroom Quiz


Job description

8901 - Corp Office West Crk - 12800 Tuckahoe Creek Parkway, Richmond, Virginia, 23238

CarMax, the way your career should be! 

Job Description

The Cybersecurity Engineer II in our Application Security Program plays a key role in enhancing the security program for a company and national brand that has been listed on the Fortune 100 Best Places to Work.   We work in a collaborative environment where your ideas can help shape the direction and development of critical security capabilities. You will work with a team of talented professionals that are keenly focused on solving complex security challenges and supporting product innovation with technology.  Our team is not afraid to fail fast, learn and are motivated to find ways to make things better.  This role requires you to be flexible, adaptable to change, and willing to ask questions that lead to security posture improvements for CarMax.

What you will do – Essential Responsibilities:

  • Implement, develop, operate, and improve Cybersecurity solutions utilized for to progress Application Security at CarMax including static and dynamic analysis, API Sec, and Container Sec.
    Provide functional and technical expertise on projects that have application security implications for our Company. 

  • Learn and understand the full portfolio of Cybersecurity capabilities at CarMax and how they work together to secure or enterprise.

  • Independently drive tasks and projects to successful completion through effective time and schedule management, customer interaction, and cross functional team interaction

  • Effectively triage support problems and respond with the appropriate level of urgency
    Participate in a 24x7 on-call weekly rotation as scheduled, and the ability to perform after hours support as needed. Current rotation is about 3 weeks per year.

Qualification Requirements:

  • Strong fundamentals in general Cybersecurity concepts with an interest in learning more about and contributing to Application Security

  • Functional understanding with at least one coding or scripting language: e.g. PowerShell, Python, .Net, Javascript, C#

  • Excellent analytical, troubleshooting, and problem-solving skills and performs well in high pressure or stressful situations 

  • Excellent organization and time management skills 

  • Excellent communication skills to include, but not limited to, verbal and written communication; delivering organized presentations; able to tailor message to the audience; and facilitate group discussions with diplomacy and seek diverse opinions

  • Ability to effectively estimate the efforts of others and the impact required to accomplish requested tasks/projects


Preferred Qualifications

  • Functional proficiency with at least one coding or scripting language

  • Experience performing dynamic application security testing (DAST) using open source and commercial tools.

  • Experience performing static security code analysis (SAST) and providing relevant recommendations to stakeholders.

  • Experience integrating security into the container lifecycle, including image assurance, Kubernetes posture management, secrets management, and runtime threat detection


Education and/or Experience:

  • Bachelor’s Degree in Computer Science, Engineering, Cybersecurity, or a related field, or equivalent alternative education, skills, and/or practical experience is required.

  • 2+ years of work experience required in Cybersecurity or other areas directly relevant to cybersecurity responsibilities and tasks.

  • Knowledge of developer tools like GitHub, Azure DevOps, and TeamCity.

  • Experience with Public Cloud: e.g. Azure, AWS, GCP.

  • Understanding of development and product teams and DevSecOps best practices.

  • CISSP certification preferred but not required.

Work Location and Arrangement: This role will be based out of the CarMax Home Office at West Creek (Richmond, VA) and associates will work onsite 4 days per week. 

Work Authorization:  Applicants must be currently authorized to work in the United States on a full-time basis. 

About CarMax

CarMax disrupted the auto industry by delivering the honest, transparent and high-integrity experience customers want and deserve. This innovative thinking around the way cars are bought and sold has helped us become the nation’s largest retailer of used cars, with over 200 locations nationwide.

Our amazing team of more than 25,000 associates work together to deliver iconic customer experiences. Along the way, we help every associate grow their career and achieve their best, at work and in their community.  We are recognized for our commitment to training and diversity and are one of the FORTUNE 100 Best Companies to Work For®.

Our Commitment to Diversity and Inclusion:

CarMax is committed to bringing together people from different backgrounds and perspectives, providing employees with a safe, welcoming, and inclusive work environment.

CarMax is an equal opportunity employer, and all qualified candidates will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, protected veteran status, disability status, or any other characteristic protected by law.

The annual salary for this position is:

$80,600.00 - $120,900.00

May be eligible for bonus and equity.

Benefits:

Except as otherwise required by state law, CarMax Associates are entitled to the following paid sick, vacation, and holiday time.

Associates that are considered full-time hourly or commission/incentive eligible:

  • To earn up to 48 hours of sick time per year accrued on a per pay period basis and between 80 hours and 200 hours per year of vacation time after a 90 day waiting period depending on years of continuous service with the Company. 
  • For 8 hours of pay for each of a total of 6 paid scheduled holidays per year plus 1 floating holiday.  If such an Associate does work on a scheduled holiday due to business need, they are eligible for Holiday Premium Pay. 

Associates considered full-time salaried are entitled to paid time away with no specified limit as needed for sick, vacation, bereavement, jury duty, holidays, floating holiday, etc. subject to manager approval. 

For more details about benefits, please visit our CarMax Benefits website.

Upon an applicant's request, CarMax will consider reasonable accommodation to complete the CarMax Job Application.


What CarMax employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


CarMax logo

About CarMax

Sourced by ZipRecruiter

CarMax disrupted the auto industry by delivering the honest, transparent and high-integrity experience customers want and deserve. This innovative thinking around the way cars are bought and sold has helped us become the nation's largest retailer of used cars, with over 200 locations nationwide. Our amazing team of more than 25,000 associates work together to deliver iconic customer experiences. Along the way, we help every associate grow their career and achieve their best, at work and in their community. We are recognized for our commitment to training and diversity and are one of the FORTUNE 100 Best Companies to Work For®.

Industry

Automobile dealers and finance and insurance

Company size

10,000+ Employees

Headquarters location

Henrico, VA, US