1

Application Security Engineer Jobs in Washington, DC

Application Security Engineer

Washington, DC ยท On-site

$66.50 - $89/hr

Work with application developers ensure adoption of security principals and best practices. 6. Provides direction and support in security management and security architecture standards and ...

APPLICATION SECURITY ENGINEER

Fairfax, VA ยท On-site

$60 - $80.25/hr

Application Security Engineer Location: Onsite in Fairfax, VA 3 days and in Washington, DC 2 days per week. Duration: Long Term Contract Positions Require a Secret Clearance The Application Security ...

Application Security Engineer

Washington, DC ยท On-site

$66.25 - $88.50/hr

Ryder System, Inc. is seeking a highly motivated and experienced Application Security Engineer to join their growing security team. The role involves ensuring that the software development lifecycle ...

Application Security Engineer Location: Washington, DC * Support PeopleSoft HCM/FSCM/ELM/CRM/EPM application security. * Implement specifically SSO for Oracle ELM, HCM and Finance PeopleSoft Modules ...

As an Application Security Engineer I, you will be part of a team responsible for ensuring the security of applications, conducting security assessments, and implementing security controls. You will ...

New

Application Security Engineer

Herndon, VA ยท Hybrid

$60.25 - $80.75/hr

Minimum of 5 years experience working "hands-on" in application security engineering * Hands-on experience with Fortify, Veracode, Tenable, Black Duck, or similar platforms * Hands-on experience with ...

APPLICATION SECURITY ENGINEER

Rockville, MD ยท On-site

$100 - $130/hr

The Application Security Engineer (ASE) is responsible for promoting, designing, and evaluating application security in all phases of the application life cycle. The ASE shall ensure that appropriate ...

New

Application Security Engineer

Washington, DC ยท On-site +1

$180K - $200K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

As an application security engineer you will help our engineering teams maintain and develop our product, and directly have impact in a security centric company and product. An ideal candidate is ...

Application Security Engineer

Ashburn, VA ยท On-site

$107K - $195K/yr

Primary Responsibilities Leidos is looking for an Application Security Engineer to support: Application Security Operations and Maintenance, Application Security Configuration Management and ...

Application Security Engineer

Ashburn, VA ยท On-site

$107K - $195K/yr

Primary Responsibilities Leidos is looking for an Application Security Engineer to support: Application Security Operations and Maintenance, Application Security Configuration Management and ...

Application Security Engineer

Bethesda, MD ยท On-site

$9 - $198/hr

  • Medical

  • Life

  • Retirement

  • PTO

R0246153 Application Security Engineer The Opportunity: Integrate security practices throughout the soft software development lifecycle to enhance and maintain the security posture of software. Apply ...

New

Application Security Engineer

Bethesda, MD ยท On-site

$86K - $198K/yr

  • Medical

  • Life

  • Retirement

  • PTO

Application Security Engineer The Opportunity: Integrate security practices throughout the software development lifecycle to enhance and maintain the security posture of software. Apply advanced ...

next page

Showing results 1-20

Application Security Engineer information

See Washington, DC salary details

$33

$75

$109

How much do application security engineer jobs pay per hour?

As of Aug 19, 2026, the average hourly pay for application security engineer in Washington, DC is $75.21, according to ZipRecruiter salary data. Most workers in this role earn between $63.99 and $85.48 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are the most commonly searched types of Application Security Engineer jobs in Washington, DC?

The most popular types of Application Security Engineer jobs in Washington, DC are:

What job categories do people searching Application Security Engineer jobs in Washington, DC look for?

The top searched job categories for Application Security Engineer jobs in Washington, DC are:

Infographic showing various Application Security Engineer job openings in Washington, DC as of August 2026, with employment types broken down into 77% Full Time, 18% Part Time, and 5% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $156,430 per year, or $75.2 per hour.

Application Security Engineer

Eliassen Group

Washington, DC โ€ข On-site

$66.50 - $89/hr

Full-time

Re-posted 7 days ago


Job description

Company Description
Demonstrate your expertise and challenge your skills in this exciting IT Security Engineering opportunity! We are seeking an experienced IT Security Engineer for a lead role within our Security Team in our Washington DC IT Department. In this role, you will provide IT security support for applications and software systems in all platforms as well as providing security support to all systems in production, staging and development environments. This Security Engineer role will work closely with Washington DC IT departments and ensures the security and protection of organizational information assets including data, applications, systems, databases, networks, and other resources. We offer a competitive salary and comprehensive benefits, making this a great opportunity for an experienced IT Security Engineer, like you, to take their IT career to the next level!
Job Description
1. Security Engineer works on defining security frameworks for existing and new systems.
2. Represents the IT security team for enterprise projects during development phases like architecture/design review, providing IT security consulting and recommendations, to ensure the implementation of a secure application design.
3. Responsible for supporting the implementation and enforcement of secure application design principles
4. Responsible for explaining and demonstrating vulnerabilities to application/system owners, and provide recommendations for mitigation.
5. Responsible for defining and designing security code analysis tools and framework, Performing code and design reviews of all internal and external software products. Work with application developers ensure adoption of security principals and best practices.
6. Provides direction and support in security management and security architecture standards and documentations.
7. Provides fault resolution and escalation advice.
8. Responsible for defining processes to manage and enforce application security.
9. Conducts active penetration tests; discover vulnerabilities in information systems.
10. Participate in IT security compliance and audit efforts (eg PCI DSS )
Qualifications
โ€ข College degree (relevant field) or equivalent experience; 3-5 years of work experience.
โ€ข 2+ years of experience in web application development in .NET, Java EE, and SQL
โ€ข 1+ years of experience in web or mobile application security preferred
โ€ข HTTP protocol knowledge required
โ€ข Knowledge of authentication mechanisms like SAML, OAuth etc. along with web service security protocols for SOAP such as WS-Security are nice to have
โ€ข Knowledge of information security principles, web applications and a level of familiarity with malicious code and common techniques used by hackers
โ€ข Experience with application security code review practices / static analysis and methods, such as OWASP Top Ten
โ€ข Detailed knowledge and understanding of the Payment Card Industry (PCI) data security standards (PCI DSS) as well as experience in the implementation of controls to mitigate PCI issues
โ€ข Experience with Application Security Firewalls, F5' ASM / Citrix's Teros etc are desirable
โ€ข Experience in creating, maintaining, and executing Incident Response Plans
โ€ข Strong interpersonal and communications skills along with strong customer service skills
โ€ข Strong programming background with: JavaScript, JSP, PHP, ASP.Net strongly preferred
โ€ข Knowledge of Security Flaws and its Resolution as listed in sites like OWASP, SANS etc.
โ€ข Knowledge and understanding of network and web related protocols (e.g., TCP/IP, UDP, IPSEC, DNS, LTM, GTM) preferred
โ€ข Experience in technical security countermeasures, risk management, contingency planning, and data communications networking preferred
Additional Information
All your information will be kept confidential according to EEO guidelines.
http://www.eliassen.com/consulting-services-consultant/agile-consulting-services

Eliassen Group logo

About Eliassen Group

Sourced by ZipRecruiter

Eliassen Group provides strategic consulting and talent solutions to drive our clients' innovation and business results. Our purpose is to positively impact the lives of our employees, clients, consultants, and the communities in which we operate. Leveraging over 30 years of success, our expertise in talent solutions, life sciences consulting, Agile consulting, cloud services, risk management, business optimization, and managed services enables us to partner with our clients to execute their business strategy and scale effectively. Headquartered in Reading, MA, and with offices from coast to coast, Eliassen Group offers local community presence and deep networks, as well as national reach.

Industry

It services

Company size

5,001 - 10,000 Employees

Headquarters location

Reading, MA, US

Year founded

1989