1

Application Security Manager Jobs in Virginia (NOW HIRING)

APPLICATION SECURITY ENGINEER

Fairfax, VA · On-site

$60 - $80.25/hr

Guide system teams through Risk Management Framework (RMF) steps related to application security, including control implementation, evidence gathering, and POA&M mitigation. * Lead security ...

Application Security Operations and Maintenance, Application Security Configuration Management and ... Ensure continuous monitoring of all CSD managed applications and implement an alerting system for ...

Application Security Engineer

Ashburn, VA · On-site

$107K - $195K/yr

Application Security Operations and Maintenance, Application Security Configuration Management and ... Ensure continuous monitoring of all CSD managed applications and implement an alerting system for ...

Cyber - AWS Cloud Security - Manager

Mclean, VA · On-site

$112K - $151K/yr

Experience with container security, application security, or DevSecOps practices * Experience ... Manage security assessments, architecture reviews, and remediation planning for cloud environments ...

next page

Showing results 1-20

Application Security Manager information

See Virginia salary details

$39.2K

$120.4K

$200.3K

How much do application security manager jobs pay per year?

As of Aug 12, 2026, the average yearly pay for application security manager in Virginia is $120,424.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,700.00 and $140,800.00 per year, depending on experience, location, and employer.

What does an Application Security Manager do?

An Application Security Manager is responsible for overseeing the security of software applications within an organization. They identify and address potential security vulnerabilities, implement best practices for secure development, and ensure compliance with security standards. Their role often includes working with development teams, conducting security assessments, and responding to security incidents to protect sensitive data. Application Security Managers help maintain the confidentiality, integrity, and availability of applications throughout their lifecycle.

What are the key skills and qualifications needed to thrive as an Application Security Manager, and why are they important?

To thrive as an Application Security Manager, you need expertise in application security principles, risk assessment, secure coding practices, and a relevant degree or certifications like CISSP or CSSLP. Familiarity with security testing tools (such as SAST, DAST, and vulnerability scanners), secure development frameworks, and compliance standards is essential. Strong leadership, communication, and problem-solving skills help you collaborate with development teams and guide security initiatives. These skills are crucial to effectively safeguard applications, ensure regulatory compliance, and reduce security risks within organizations.

What are some common challenges faced by Application Security Managers when integrating security into the software development lifecycle?

Application Security Managers often encounter challenges in embedding security practices early and consistently within fast-paced development environments. Balancing the need for robust security with the demands for rapid delivery can result in pushback from development teams or tight deadlines. They must also navigate evolving threat landscapes and ensure that both technical and non-technical stakeholders are aligned on security priorities. Building strong cross-team relationships and fostering a culture of security awareness are key to overcoming these obstacles.
What cities in Virginia are hiring for Application Security Manager jobs? Cities in Virginia with the most Application Security Manager job openings:
Infographic showing various Application Security Manager job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 12% Part Time, and 1% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $120,424 per year, or $57.9 per hour.

APPLICATION SECURITY ENGINEER

Hirekeyz Inc

Fairfax, VA • On-site

$60 - $80.25/hr

Contractor

Re-posted 19 days ago


Job description

Role: Application Security Engineer 

Location: Onsite in Fairfax, VA 3 days and in Washington, DC 2 days per week.

Duration: Long Term Contract

Positions Require a Secret Clearance

Job Description:

The Application Security Engineer position supports secure application development and cybersecurity operations for Federal DoD programs. The role requires a deep expertise in application security, software development, federal cybersecurity standards, and secure architecture. Will be responsible for senior-level leadership in information security, secure SDLC integration, and compliance with federal security frameworks such as NIST 800‑53, NIST 800‑37 RMF, FedRAMP, and agency-specific security baselines.
 
 
Primary Responsibilities: 
  • Serve as the primary application security SME for the project, ensuring compliance with NIST, FISMA, FedRAMP, DHS, DoD, and agency-specific security requirements.
  • Guide system teams through Risk Management Framework (RMF) steps related to application security, including control implementation, evidence gathering, and POA&M mitigation.
  • Lead security architecture reviews for mission-critical systems, ensuring secure-by-design principles across federal systems and networks.
  • Integrate security into the federal SDLC by defining secure coding standards, conducting code reviews, and providing architectural input.
  • Conduct and lead advanced security testing.
  • Provide CISSP-level expertise on risk evaluation, compensating controls, and secure architecture guidance.
  • Guide enterprise risk posture by advising leadership on vulnerabilities, mitigations, and long-term remediation planning.
  • Ensure secure configurations of cloud resources within AWS GovCloud FedRAMP environments.
  • All other duties as assigned by management.
 
Skills and Qualifications:
  • Bachelor’s degree in computer science or related field
  • 10 years in application development and IT security
  • Experience performing risk assessments for Federal systems in AWS GovCloud
  • Experience supporting FedRAMP High/Moderate systems
  • Knowledge in Java, Python, HTML, SQL, CSS and cloud computing
  • Excellent communication and management skills.
 
Certifications Required:
  • Certified Secure Software Lifecycle Professional (CSSLP)
  • Certified Information Systems Security Professional (CISSP)
  • CompTIA Security +