1

Application Security Jobs in Virginia (NOW HIRING)

APPLICATION SECURITY ENGINEER

Fairfax, VA · On-site

$60 - $80.25/hr

Application Security Engineer Location: Onsite in Fairfax, VA 3 days and in Washington, DC 2 days per week. Duration: Long Term Contract Positions Require a Secret Clearance The Application Security ...

Application Security Operations and Maintenance, Application Security Configuration Management and Application Security Logging and Vulnerability Management : * Ensure continuous monitoring of all ...

Application Security Engineer

Ashburn, VA · On-site

$107K - $195K/yr

Application Security Operations and Maintenance, Application Security Configuration Management and Application Security Logging and Vulnerability Management : * Ensure continuous monitoring of all ...

Application Security Engineer

Herndon, VA · Remote

$60.50 - $80.75/hr

Application Security Engineer Company: VivSoft Work Type: Remote Employment: Full Time Location: US Seniority: Mid Level Technologies: GitHub Actions, SAST, DAST, SCA, OWASP Requirements: Experience ...

next page

Showing results 1-20

Application Security information

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications such as Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, authorization, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, penetration testing, and code reviews to identify and fix security issues throughout the development lifecycle.
What cities in Virginia are hiring for Application Security jobs? Cities in Virginia with the most Application Security job openings:
Infographic showing various Application Security job openings in Virginia as of August 2026, with employment types broken down into 80% Full Time, 16% Part Time, and 4% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution.

APPLICATION SECURITY ENGINEER

Hirekeyz Inc

Fairfax, VA • On-site

$60 - $80.25/hr

Contractor

Re-posted 19 days ago


Job description

Role: Application Security Engineer 

Location: Onsite in Fairfax, VA 3 days and in Washington, DC 2 days per week.

Duration: Long Term Contract

Positions Require a Secret Clearance

Job Description:

The Application Security Engineer position supports secure application development and cybersecurity operations for Federal DoD programs. The role requires a deep expertise in application security, software development, federal cybersecurity standards, and secure architecture. Will be responsible for senior-level leadership in information security, secure SDLC integration, and compliance with federal security frameworks such as NIST 800‑53, NIST 800‑37 RMF, FedRAMP, and agency-specific security baselines.
 
 
Primary Responsibilities: 
  • Serve as the primary application security SME for the project, ensuring compliance with NIST, FISMA, FedRAMP, DHS, DoD, and agency-specific security requirements.
  • Guide system teams through Risk Management Framework (RMF) steps related to application security, including control implementation, evidence gathering, and POA&M mitigation.
  • Lead security architecture reviews for mission-critical systems, ensuring secure-by-design principles across federal systems and networks.
  • Integrate security into the federal SDLC by defining secure coding standards, conducting code reviews, and providing architectural input.
  • Conduct and lead advanced security testing.
  • Provide CISSP-level expertise on risk evaluation, compensating controls, and secure architecture guidance.
  • Guide enterprise risk posture by advising leadership on vulnerabilities, mitigations, and long-term remediation planning.
  • Ensure secure configurations of cloud resources within AWS GovCloud FedRAMP environments.
  • All other duties as assigned by management.
 
Skills and Qualifications:
  • Bachelor’s degree in computer science or related field
  • 10 years in application development and IT security
  • Experience performing risk assessments for Federal systems in AWS GovCloud
  • Experience supporting FedRAMP High/Moderate systems
  • Knowledge in Java, Python, HTML, SQL, CSS and cloud computing
  • Excellent communication and management skills.
 
Certifications Required:
  • Certified Secure Software Lifecycle Professional (CSSLP)
  • Certified Information Systems Security Professional (CISSP)
  • CompTIA Security +