1

Application Security Jobs in Virginia (NOW HIRING)

APPLICATION SECURITY ENGINEER

Fairfax, VA · On-site

$60 - $80.25/hr

Application Security Engineer Location: Onsite in Fairfax, VA 3 days and in Washington, DC 2 days per week. Duration: Long Term Contract Positions Require a Secret Clearance The Application Security ...

Application Security Engineer

Ashburn, VA · On-site

$107K - $195K/yr

Application Security Operations and Maintenance, Application Security Configuration Management and Application Security Logging and Vulnerability Management : * Ensure continuous monitoring of all ...

Application Security Engineer

Ashburn, VA · On-site

$107K - $195K/yr

Application Security Operations and Maintenance, Application Security Configuration Management and Application Security Logging and Vulnerability Management : * Ensure continuous monitoring of all ...

Work on ensuring systems and applications comply with Security Technical Implementation Guide * Establish and maintain the definitive current basis for control and status accounting of application ...

As an Application Security Engineer at Esri, you will fill a critical role in helping secure Esri's intellectual property and sensitive data against a variety of complex threats with support from all ...

Our Application Security team collaborates closely with the application development, DevSecOps, and information security departments to design security into our applications up front, perform ...

next page

Showing results 1-20

Application Security information

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications like Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, firewalls, and vulnerability scanners to identify and mitigate risks throughout the development lifecycle.

What cities in Virginia are hiring for Application Security jobs?

Cities in Virginia with the most Application Security job openings:

Infographic showing various Application Security job openings in Virginia as of August 2026, with employment types broken down into 71% Full Time, 25% Part Time, and 4% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution.

Application Security Engineer

Reston, VA • On-site

Bespoke Technologies, Inc.
Recruiting and Staffing Services • 11 - 50 employees

$125 - $150/hr

Other

Posted 13 days ago


Job description

BT-411 – Application Security Engineer

Location: Reston, VA

Please do NOT apply if you do not have an active Poly clearance. Those without a Poly will not be considered.

Bespoke Technologies is seeking a highly experienced and motivated Application Security Engineer for an exciting new contract. This role will be part of a team of Data, Cloud, and Security engineers delivering a cloud-native, centralized platform that provides end-to-end budget traceability. The Application Security Engineer will integrate security throughout the software development lifecycle, partnering with developers and cloud engineers to design, build, assess, and sustain secure mission applications.

Required Skills and Qualifications:
  • Technical expertise and hands‑on experience in application security, secure software development, software engineering, or DevSecOps, with the ability to apply these skills to Oracle Cloud and customer mission challenges.
  • Experience integrating security throughout the software development lifecycle, including secure design and architecture reviews, threat modeling, secure code review, security testing, vulnerability remediation, and release authorization support.
  • Experience with application security testing tools and processes, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and container or infrastructure vulnerability scanning.
  • Experience building and securing cloud‑native applications and services using Kubernetes, containers, Docker, REST APIs, and CI/CD pipelines.
  • Experience implementing DevSecOps practices, including automated security controls and testing within build and deployment pipelines.
  • Experience with cloud‑native security services and controls; Oracle Cloud Infrastructure (OCI) experience is desired.
  • Knowledge of security frameworks and standards such as NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, and applicable federal security requirements.
  • Experience securing Oracle RDBMS environments, including database access controls, encryption, auditing, and secure handling of sensitive data.
  • Ability to assess, prioritize, document, and communicate application and cloud security risks, findings, and remediation recommendations to both technical and non‑technical stakeholders.
  • Passion for technology, curiosity, and willingness to continuously learn new security tools, techniques, and approaches for solving complex technical challenges.
  • Experience working in an Agile framework.
BT-411 – Application Security Engineer

Location: Reston, VA

Please do NOT apply if you do not have an active Poly clearance. Those without a Poly will not be considered.

Bespoke Technologies is seeking a highly experienced and motivated Application Security Engineer for an exciting new contract. This role will be part of a team of Data, Cloud, and Security engineers delivering a cloud-native, centralized platform that provides end-to-end budget traceability. The Application Security Engineer will integrate security throughout the software development lifecycle, partnering with developers and cloud engineers to design, build, assess, and sustain secure mission applications.

Required Skills and Qualifications:
  • Technical expertise and hands‑on experience in application security, secure software development, software engineering, or DevSecOps, with the ability to apply these skills to Oracle Cloud and customer mission challenges.
  • Experience integrating security throughout the software development lifecycle, including secure design and architecture reviews, threat modeling, secure code review, security testing, vulnerability remediation, and release authorization support.
  • Experience developing or reviewing applications using Python, JavaScript frameworks, SQL, Shell scripting, PL/SQL, and other programming languages, with a strong understanding of common application vulnerabilities and secure coding practices.
  • Experience with application security testing tools and processes, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and container or infrastructure vulnerability scanning.
  • Experience building and securing cloud‑native applications and services using Kubernetes, containers, Docker, REST APIs, and CI/CD pipelines.
  • Experience implementing DevSecOps practices, including automated security controls and testing within build and deployment pipelines.
  • Experience with cloud‑native security services and controls; Oracle Cloud Infrastructure (OCI) experience is desired.
  • Knowledge of security frameworks and standards such as NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, and applicable federal security requirements.
  • Experience securing Oracle RDBMS environments, including database access controls, encryption, auditing, and secure handling of sensitive data.
  • Ability to assess, prioritize, document, and communicate application and cloud security risks, findings, and remediation recommendations to both technical and non‑technical stakeholders.
  • Passion for technology, curiosity, and willingness to continuously learn new security tools, techniques, and approaches for solving complex technical challenges.
  • Experience working in an Agile framework.
Desired Skills and Qualifications:
  • Oracle Cloud Infrastructure (OCI) IaaS and/or PaaS certifications are preferred.
  • Security certifications such as CISSP, CSSLP, Security+, GIAC, CEH, OSCP, or comparable credentials.
  • Experience implementing identity and access management, privileged access controls, secrets management, encryption, logging, monitoring, and incident response capabilities in cloud environments.
  • Experience with AI technologies for software development and securing AI‑enabled applications or development workflows.
  • Data engineering experience, including securing data validations, business rules, data transformations, and sensitive‑data handling.
Required Credentials and Experience:
  • 8+ years of relevant experience in application security, software engineering, DevSecOps, cybersecurity, or a related technical discipline.
  • Bachelor’s Degree in engineering, computer science or related technical discipline. Master’s degree preferred.
#J-18808-Ljbffr