1

Application Security Jobs in Iowa (NOW HIRING)

Application Security Engineer II

Des Moines, IA · On-site

$57.25 - $76.50/hr

The Application Security Engineer II serves as the technical subject matter expert for application security, partnering with software development and technology teams to embed security throughout the ...

Application Security Engineer II

Des Moines, IA · On-site

$57.25 - $76.50/hr

The Application Security Engineer II serves as the technical subject matter expert for application security, partnering with software development and technology teams to embed security throughout the ...

Understanding of secure coding practices and application security principles * Familiarity with AI-assisted development tools (e.g., Copilot, code generation tools) * Experience using Git and modern ...

Understanding of secure coding practices and application security principles * Familiarity with AI-assisted development tools (e.g., Copilot, code generation tools) * Experience using Git and modern ...

Understanding of secure coding practices and application security principles * Familiarity with AI-assisted development tools (e.g., Copilot, code generation tools) * Experience using Git and modern ...

next page

Showing results 1-20

Application Security information

See Iowa salary details

$35

$50

$89

How much do application security jobs pay per hour?

As of Sep 10, 2026, the average hourly pay for application security in Iowa is $50.43, according to ZipRecruiter salary data. Most workers in this role earn between $40.19 and $52.40 per hour, depending on experience, location, and employer.

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications like Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, firewalls, and vulnerability scanners to identify and mitigate risks throughout the development lifecycle.
Infographic showing various Application Security job openings in Iowa as of August 2026, with employment types broken down into 75% Full Time, 21% Part Time, and 4% Contract. Highlights an 89% Physical, 3% Hybrid, and 8% Remote job distribution, with an average salary of $104,891 per year, or $50.4 per hour.

Application Security Engineer II

Des Moines, IA • On-site

$57.25 - $76.50/hr

Full-time

Retirement, PTO

Posted 12 days ago


Job description

At FHLB Des Moines, we work each day to develop an inclusive culture that supports and leverages the complexity of a diverse workforce. This enables us to effectively serve the needs of our members and help them succeed.

The Application Security Engineer II serves as the technical subject matter expert for application security, partnering with software development and technology teams to embed security throughout the Software Development Life Cycle (SDLC). This role performs application security assessments, secure design reviews, DevSecOps initiatives, vulnerability management, and secure coding practices while helping developers deliver secure, resilient applications that protect the organization's information assets and support regulatory compliance.

Accountabilities:

Key Responsibilities:

  • Administer code and pipeline security tooling (SAST, DAST, SCA, etc.) as well as container security tooling (image runtime security, vulnerability assessments, etc.).
  • Maintain and enhance secure code training program.
  • Provide information security recommendations for code repository and development pipeline implementations.
  • Administer and secure enterprise source code repositories.
  • Integrate and automate security controls into CI/CD pipelines and developer workflows.
  • Partner with stakeholders to prioritize highest risk issues for remediation, disseminate the information and monitor progress for completion.
  • Serve as a point of contact with application development stakeholders to answer questions, provide security guidance, and foster a strong relationship between departments.
  • Define processes ensuring third party libraries originate from trusted, approved repositories
  • Secure Infrastructure as Code deployments to ensure successful system implementations.
  • Implement automated security scanning of IaC templates.
  • Identify architectural security risks early in the software development lifecycle
  • Review application architecture and solution designs for security risks.
  • Provide security guidance during application design and planning phases.
  • Contribute security best practice for Bank initiatives that involve updating or creating applications, pipelines, and/or repositories.
  • Assist in detection engineering/refinement to enable detection, prevention and response to incidents in development environments, pipelines, and developed applications.
  • Create scripts or tooling to improve application security processes.
  • Respond to security alerts relating to development environments, pipeline events, and application behavior.
  • Provide security best practice on code reviews where sensitive components of an application were changed or impacted.
  • Generate metrics demonstrating risks and remediation progress.
  • Continuously learn about emerging technologies, their risks, and how to securely leverage them.
  • Develop proposals and implement new tools and processes to mature the bank's security program.
  • Advise and assist with operational security and response to information security incidents.
  • Provide information security requirement input in support of project initiatives.
  • Create, develop, implement, and maintain security standards, procedures, and guidelines to mitigate risk in the Bank's information security posture (internal/external).
  • Assist with information security strategies andorganizational governance. Communicate security strategies and framework to staff, partners, and other stakeholders.
  • Promote security awareness through Bank-wide communication of policies and security threats.
  • Respond and investigate cybersecurity incidents, collect, and analyze information from multiple event sources and internal and external sources.
  • Examine incidents that may be related to ransomware, host compromise, account compromise, phishing, anomalous user behavior, third parties and data leakage.
  • Monitor for incidents with endpoints, databases, applications, networking, mobile and cloud services.
  • Monitor for vulnerabilities within applications, endpoints, databases, networking, and mobile and cloud services.
  • Collaborate as a purple team with colleagues in offense, defense, operators, threat intelligence and risk management roles.
  • Recommend tactical options to reduce attack surface, containment alternatives and impede attackers.
  • Monitor departmental internal controls and regulatory issues.
  • Other duties and projects as assigned.


Qualifications:

Required

  • 3-5 years of experience in Application Security, Information Security, DevSecOps, or a related field.
  • Experience performing application security assessments and validating remediation efforts.
  • Experience working with software development teams throughout the SDLC.
  • Experience with development and security tooling leveraged in a Secure SDLC (such as code scanning, git, pipeline automation tools. etc.)
  • Experience reviewing vulnerabilities and providing remediation guidance.
  • Knowledge of common web application vulnerabilities (OWASP Top 10).
  • Familiarity with secure authentication, authorization, session management, and encryption principles.
  • Working knowledge of one programming or scripting language (Python, Java, C#, JavaScript, PowerShell, etc.).
  • Understanding of REST APIs and modern web application architectures.
  • Understanding of container technologies (Docker/Kubernetes), security concepts, and security tooling.
  • Familiarity with Infrastructure as Code concepts.
  • Strong written and verbal communication.
  • Ability to explain technical security risks to non-security stakeholders.
  • Strong analytical and problem-solving skills.
  • Ability to manage multiple projects simultaneously.
  • Self-directed with strong organizational skills.

Preferred

  • Bachelor's or master's degree in computer science, Cybersecurity, Information Systems, Software Engineering, or a related technical discipline.
  • Experience implementing DevSecOps practices.
  • Experience developing custom security automation.
  • Experience administering application security tooling.
  • Experience performing secure code reviews.
  • Experience integrating security into CI/CD pipelines.
  • Experience building developer security training programs.
  • Experience with threat modeling methodologies.
  • Experience in Agile development environments.
  • Experience supporting cloud-native applications (Azure, AWS, GCP).
  • Working knowledge of one or more of the following: Web Application Firewalls (WAF). API Security platforms, Secrets Management, Kubernetes security, Supply Chai, Security (SBOM, dependency management), Software composition analysis, Threat modeling (STRIDE, PASTA), OWASP ASVS, OWASP SAMM, OWASP API Security Top 10, Secure SDLC maturity frameworks
  • Certifications CSSLP, GWAPT, GWEB, OSCP, CISSP, Security+, Azure/AWS security certifications

Compensation Range:

Annual Salary: $102,210.00 - $121,374.00

This salary range represents the Bank's good faith and reasonable estimate of possible compensation at the time of hire. Offer to be determined by selected applicant's education, experience, knowledge, skills & abilities, as well as internal equity and alignment with market data.This role is also eligible to participate in the Bank's annual incentive plan.
As part of our competitive Total Rewards package, the Bank offers 11 paid holidays, 5 weeks of PTO and a work culture that values work/life balance. Most roles are eligible for our hybrid work schedule. We match 100% of the first 6% you contribute to your 401(k) and provide an additional 4% non-discretionary contribution to your 401(k) at the end of year. More information on our Total Rewards program can be found here.

At FHLB Des Moines, we work to create an inclusive culture. This enables us to effectively serve the needs of our members and help them succeed. FHLB Des Moines is proud to be an Equal Opportunity Employer. We prohibit discrimination on the basis of race, color, religion, sex (including pregnancy, sexual orientation or gender identity), national origin, age, disability, veteran status, genetic information (including family medical history), status as a parent or any other characteristic protected by federal, state or local law.