1

Application Security Manager Jobs in Virginia (NOW HIRING)

AppSec Security Engineer

Arlington, VA

$67.50 - $90.25/hr

Cybersecurity Engineering Manager Direct Reports: None POSITION SUMMARY STATEMENT We are seeking an experienced Application Security Engineer to build, mature, and scale our AppSec program. In this ...

Be Seen First

Health insurance Application Question(s): * If hired, how soon would you be available to start? * Please describe in detail the extent of your experience managing large-scale security contracts.

DevSecOps Engineer

Arlington, VA · On-site

$67.50 - $90.25/hr

Experience with security automation tools, vulnerability management platforms, and secure software development methodologies. * Knowledge of secure coding standards, application security principles ...

Showing results 41-60

Application Security Manager information

See Virginia salary details

$39.2K

$120.4K

$200.3K

How much do application security manager jobs pay per year?

As of Aug 12, 2026, the average yearly pay for application security manager in Virginia is $120,424.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,700.00 and $140,800.00 per year, depending on experience, location, and employer.

What does an Application Security Manager do?

An Application Security Manager is responsible for overseeing the security of software applications within an organization. They identify and address potential security vulnerabilities, implement best practices for secure development, and ensure compliance with security standards. Their role often includes working with development teams, conducting security assessments, and responding to security incidents to protect sensitive data. Application Security Managers help maintain the confidentiality, integrity, and availability of applications throughout their lifecycle.

What are the key skills and qualifications needed to thrive as an Application Security Manager, and why are they important?

To thrive as an Application Security Manager, you need expertise in application security principles, risk assessment, secure coding practices, and a relevant degree or certifications like CISSP or CSSLP. Familiarity with security testing tools (such as SAST, DAST, and vulnerability scanners), secure development frameworks, and compliance standards is essential. Strong leadership, communication, and problem-solving skills help you collaborate with development teams and guide security initiatives. These skills are crucial to effectively safeguard applications, ensure regulatory compliance, and reduce security risks within organizations.

What are some common challenges faced by Application Security Managers when integrating security into the software development lifecycle?

Application Security Managers often encounter challenges in embedding security practices early and consistently within fast-paced development environments. Balancing the need for robust security with the demands for rapid delivery can result in pushback from development teams or tight deadlines. They must also navigate evolving threat landscapes and ensure that both technical and non-technical stakeholders are aligned on security priorities. Building strong cross-team relationships and fostering a culture of security awareness are key to overcoming these obstacles.
What cities in Virginia are hiring for Application Security Manager jobs? Cities in Virginia with the most Application Security Manager job openings:
Infographic showing various Application Security Manager job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 12% Part Time, and 1% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $120,424 per year, or $57.9 per hour.

Cyber Oracle Cloud Security - Manager / Engineering Manager II

Deloitte

Richmond, VA • On-site

$109K - $148K/yr

Full-time

Re-posted 23 days ago


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 92 frontline employees who took The Breakroom Quiz

45th of 150 rated financial services


Job description

Cyber Oracle Cloud Security - Manager / Engineering Manager II

Are you interested in working in a dynamic environment that offers opportunities for growth and new responsibilities? As an Engineering Manager II in Deloitte's Cyber practice, you will help clients strengthen Oracle Cloud ERP, HCM, and SCM security by delivering governance, risk, and compliance solutions that reduce risk and improve control effectiveness. In this role, you will lead Oracle Cloud security assessments, design role-based access and segregation of duties controls, and support the implementation of Oracle Risk Management Cloud capabilities to enable secure, reliable operations across the enterprise.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As an Engineering Manager II on the Cyber team, you will be responsible for...

  • Lead Oracle Cloud security assessments and implementations across ERP, HCM, and SCM, including role design, segregation of duties, and control configuration.
  • Design and deploy Oracle Risk Management Cloud capabilities, including Advanced Access Controls, Advanced Financial Controls, and Financial Reporting Controls.
  • Manage multi-release and multi-country programs, including design workshops, scope, budget, resources, and quality oversight.
  • Guide teams in developing reusable accelerators and applying technology-enabled delivery methods to improve consistency and efficiency.
  • Collaborate with client stakeholders to define security strategy, develop deliverables, and transition solutions into operations.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

The team

Our Deloitte Cyber team helps organizations address cybersecurity challenges while enabling business transformation. The team delivers solutions and managed services that help clients simplify complexity, operate with resilience, and grow with confidence in an evolving threat landscape.

Within Cyber, our Enterprise Security Offering helps embed security across digital transformation initiatives by securing the technical backbone of the organization. The practice includes security architecture, secure development and deployment, cloud security capabilities, application security, and security for emerging technologies and connected products.

Qualifications

Required:

  • Bachelor's degree in Computer Science, Cyber Security, Information Security, Engineering, Information Technology, Management Information Systems, Finance, Accounting and Technology, or Business
  • 6+ years of experience with Oracle security and governance, risk, and compliance
  • 3+ end-to-end Oracle Cloud Enterprise Resource Planning implementation projects led
  • 3+ years of experience designing Oracle Cloud roles for Financials, Supply Chain Management, Human Capital Management, or Enterprise Performance Management
  • 3+ years of experience delivering programs with multiple releases or countries and managing teams, budgets, and resources
  • 3+ years of experience leading security design workshops and configuring Oracle Risk Management Cloud, including Advanced Access Controls, Advanced Financial Controls, and Financial Reporting Controls
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Previous consulting or Big 4 experience
  • Certified Information Systems Security Professional, Certified Information Security Manager, or Certified Information Systems Auditor certification
  • 2+ years of experience with Oracle Enterprise Resource Planning Cloud security concepts across application modules
  • Experience with Oracle Enterprise Resource Planning or Human Capital Management Cloud security design and implementation methodology
  • 2+ years of experience applying segregation of duties frameworks and protecting personally identifiable information
  • 1+ year of experience implementing single sign-on, multi-factor authentication, identity and access management, or data protection tools

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Qualifications:

Cyber Oracle Cloud Security - Manager / Engineering Manager II

Are you interested in working in a dynamic environment that offers opportunities for growth and new responsibilities? As an Engineering Manager II in Deloitte's Cyber practice, you will help clients strengthen Oracle Cloud ERP, HCM, and SCM security by delivering governance, risk, and compliance solutions that reduce risk and improve control effectiveness. In this role, you will lead Oracle Cloud security assessments, design role-based access and segregation of duties controls, and support the implementation of Oracle Risk Management Cloud capabilities to enable secure, reliable operations across the enterprise.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As an Engineering Manager II on the Cyber team, you will be responsible for...

  • Lead Oracle Cloud security assessments and implementations across ERP, HCM, and SCM, including role design, segregation of duties, and control configuration.
  • Design and deploy Oracle Risk Management Cloud capabilities, including Advanced Access Controls, Advanced Financial Controls, and Financial Reporting Controls.
  • Manage multi-release and multi-country programs, including design workshops, scope, budget, resources, and quality oversight.
  • Guide teams in developing reusable accelerators and applying technology-enabled delivery methods to improve consistency and efficiency.
  • Collaborate with client stakeholders to define security strategy, develop deliverables, and transition solutions into operations.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

The team

Our Deloitte Cyber team helps organizations address cybersecurity challenges while enabling business transformation. The team delivers solutions and managed services that help clients simplify complexity, operate with resilience, and grow with confidence in an evolving threat landscape.

Within Cyber, our Enterprise Security Offering helps embed security across digital transformation initiatives by securing the technical backbone of the organization. The practice includes security architecture, secure development and deployment, cloud security capabilities, application security, and security for emerging technologies and connected products.

Qualifications

Required:

  • Bachelor's degree in Computer Science, Cyber Security, Information Security, Engineering, Information Technology, Management Information Systems, Finance, Accounting and Technology, or Business
  • 6+ years of experience with Oracle security and governance, risk, and compliance
  • 3+ end-to-end Oracle Cloud Enterprise Resource Planning implementation projects led
  • 3+ years of experience designing Oracle Cloud roles for Financials, Supply Chain Management, Human Capital Management, or Enterprise Performance Management
  • 3+ years of experience delivering programs with multiple releases or countries and managing teams, budgets, and resources
  • 3+ years of experience leading security design workshops and configuring Oracle Risk Management Cloud, including Advanced Access Controls, Advanced Financial Controls, and Financial Reporting Controls
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Previous consulting or Big 4 experience
  • Certified Information Systems Security Professional, Certified Information Security Manager, or Certified Information Systems Auditor certification
  • 2+ years of experience with Oracle Enterprise Resource Planning Cloud security concepts across application modules
  • Experience with Oracle Enterprise Resource Planning or Human Capital Management Cloud security design and implementation methodology
  • 2+ years of experience applying segregation of duties frameworks and protecting personally identifiable information
  • 1+ year of experience implementing single sign-on, multi-factor authentication, identity and access management, or data protection tools

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom