1

Application Security Manager Jobs in Virginia (NOW HIRING)

Cyber - AWS Cloud Security - Manager

Mclean, VA ยท On-site

$112K - $151K/yr

Experience with container security, application security, or DevSecOps practices * Experience ... Manage security assessments, architecture reviews, and remediation planning for cloud environments ...

Cyber - AWS Cloud Security - Manager

Richmond, VA ยท On-site

$109K - $148K/yr

Experience with container security, application security, or DevSecOps practices * Experience ... Manage security assessments, architecture reviews, and remediation planning for cloud environments ...

Professional, Administrative, and Management Support * Mission and Warfighter Support We are a ... Security Engineer (Web Application) Location: Arlington, VA Security Clearance: Secret Duties and ...

Global Security Manager

Arlington, VA ยท On-site

$150K - $170K/yr

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process. Global Security Manager Full Time ...

Global Security Manager

Arlington, VA ยท On-site

$150K - $170K/yr

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process. Global Security Manager Full Time ...

Showing results 21-40

Application Security Manager information

See Virginia salary details

$39.2K

$120.4K

$200.3K

How much do application security manager jobs pay per year?

As of Sep 11, 2026, the average yearly pay for application security manager in Virginia is $120,424.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,700.00 and $140,800.00 per year, depending on experience, location, and employer.

What does an Application Security Manager do?

An Application Security Manager is responsible for overseeing the security of software applications within an organization. They identify and address potential security vulnerabilities, implement best practices for secure development, and ensure compliance with security standards. Their role often includes working with development teams, conducting security assessments, and responding to security incidents to protect sensitive data. Application Security Managers help maintain the confidentiality, integrity, and availability of applications throughout their lifecycle.

What are the key skills and qualifications needed to thrive as an Application Security Manager, and why are they important?

To thrive as an Application Security Manager, you need expertise in application security principles, risk assessment, secure coding practices, and a relevant degree or certifications like CISSP or CSSLP. Familiarity with security testing tools (such as SAST, DAST, and vulnerability scanners), secure development frameworks, and compliance standards is essential. Strong leadership, communication, and problem-solving skills help you collaborate with development teams and guide security initiatives. These skills are crucial to effectively safeguard applications, ensure regulatory compliance, and reduce security risks within organizations.

What are some common challenges faced by Application Security Managers when integrating security into the software development lifecycle?

Application Security Managers often encounter challenges in embedding security practices early and consistently within fast-paced development environments. Balancing the need for robust security with the demands for rapid delivery can result in pushback from development teams or tight deadlines. They must also navigate evolving threat landscapes and ensure that both technical and non-technical stakeholders are aligned on security priorities. Building strong cross-team relationships and fostering a culture of security awareness are key to overcoming these obstacles.

What cities in Virginia are hiring for Application Security Manager jobs?

Cities in Virginia with the most Application Security Manager job openings:

Infographic showing various Application Security Manager job openings in Virginia as of August 2026, with employment types broken down into 80% Full Time, 19% Part Time, and 1% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $120,424 per year, or $57.9 per hour.

Application Security Engineer (Full Scope Poly)

Reston, VA โ€ข On-site

Concept Plus
51 - 200 employees

$61 - $81.75/hr

Other

Medical, Dental, Vision, Life, PTO

Re-posted 2 days ago


Job description

Application Security Engineer (Full Scope Poly)

About Concept Plus Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm.

Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty.

We offer competitive pay, comprehensive health, dental, and vision insurance, paid life insurance, paid time off, 11 paid holidays, performance bonuses, tuition reimbursement, unlimited training, and the opportunity to thrive in a collaborative, flexible, and innovative environment.

Concept Plus is seeking a highly experienced and motivated Application Security Engineer for an exciting new contract. This role is fully onsite in Reston, VA (5 days per week required).

What you'll do

This role will be part of a team of Data, Cloud, and Security engineers delivering a cloud-native, centralized platform that provides end-to-end budget traceability. The Application Security Engineer will integrate security throughout the software development lifecycle, partnering with developers and cloud engineers to design, build, assess, and sustain secure mission applications.

Required Qualifications

  • Must possess a TS/SCI security clearance with Polygraph.
  • Technical expertise and hands-on experience in application security, secure software development, software engineering, or DevSecOps, with the ability to apply these skills to Oracle Cloud and customer mission challenges.
  • Experience integrating security throughout the software development lifecycle, including secure design and architecture reviews, threat modeling, secure code review, security testing, vulnerability remediation, and release authorization support.
  • Experience with application security testing tools and processes, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and container or infrastructure vulnerability scanning.
  • Experience building and securing cloud-native applications and services using Kubernetes, containers, Docker, REST APIs, and CI/CD pipelines.
  • Experience implementing DevSecOps practices, including automated security controls and testing within build and deployment pipelines.
  • Experience with cloud-native security services and controls; Oracle Cloud Infrastructure (OCI) experience is desired.
  • Knowledge of security frameworks and standards such as NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, and applicable federal security requirements.
  • Experience securing Oracle RDBMS environments, including database access controls, encryption, auditing, and secure handling of sensitive data.
  • Ability to assess, prioritize, document, and communicate application and cloud security risks, findings, and remediation recommendations to both technical and non-technical stakeholders.
  • Passion for technology, curiosity, and willingness to continuously learn new security tools, techniques, and approaches for solving complex technical challenges.
  • Experience working in an Agile framework.
  • 8+ years of relevant experience in application security, software engineering, DevSecOps, cybersecurity, or a related technical discipline.
  • Bachelor's Degree in engineering, computer science or related technical discipline. Master's degree preferred.

Preferred Qualifications

  • Oracle Cloud Infrastructure (OCI) IaaS and/or PaaS certifications are preferred.
  • Security certifications such as CISSP, CSSLP, Security+, GIAC, CEH, OSCP, or comparable credentials.
  • Experience implementing identity and access management, privileged access controls, secrets management, encryption, logging, monitoring, and incident response capabilities in cloud environments.
  • Experience with AI technologies for software development and securing AI-enabled applications or development workflows.
  • Data engineering experience, including securing data validations, business rules, data transformations, and sensitive-data handling.

Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.

#J-18808-Ljbffr