1

Application Security Jobs in Virginia (NOW HIRING)

Senior Engineer, Application Security

Tysons, VA · On-site

$59.50 - $79.25/hr

We're seeking a senior, builder-minded Application Security Engineer who can go deep on hard technical problems while setting the direction for how AI reshapes a security program. This isn't someone ...

Security Engineer (Web Application)

Arlington, VA · On-site

$67.50 - $90.25/hr

Security Engineer (Web Application) Location: Arlington, VA Security Clearance: Secret Duties and Responsibilities The Security Engineer (Web Application) supports this Transportation Security ...

Showing results 21-40

Application Security information

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications such as Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, authorization, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, penetration testing, and code reviews to identify and fix security issues throughout the development lifecycle.
What cities in Virginia are hiring for Application Security jobs? Cities in Virginia with the most Application Security job openings:
Infographic showing various Application Security job openings in Virginia as of August 2026, with employment types broken down into 80% Full Time, 16% Part Time, and 4% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution.

Engineer II, Cybersecurity - Application Security

Carmax

Richmond, VA • On-site

$80K - $120K/yr

Full-time

PTO

Posted 13 days ago


CarMax rating

8.0

Company rating: 8.0 out of 10

Based on 371 frontline employees who took The Breakroom Quiz

24th of 732 rated retailers


Job description

8901 - Corp Office West Crk - 12800 Tuckahoe Creek Parkway, Richmond, Virginia, 23238

CarMax, the way your career should be! 

Job Description

The Cybersecurity Engineer II in our Application Security Program plays a key role in enhancing the security program for a company and national brand that has been listed on the Fortune 100 Best Places to Work.   We work in a collaborative environment where your ideas can help shape the direction and development of critical security capabilities. You will work with a team of talented professionals that are keenly focused on solving complex security challenges and supporting product innovation with technology.  Our team is not afraid to fail fast, learn and are motivated to find ways to make things better.  This role requires you to be flexible, adaptable to change, and willing to ask questions that lead to security posture improvements for CarMax.

What you will do – Essential Responsibilities:

  • Implement, develop, operate, and improve Cybersecurity solutions utilized for to progress Application Security at CarMax including static and dynamic analysis, API Sec, and Container Sec.
    Provide functional and technical expertise on projects that have application security implications for our Company. 

  • Learn and understand the full portfolio of Cybersecurity capabilities at CarMax and how they work together to secure or enterprise.

  • Independently drive tasks and projects to successful completion through effective time and schedule management, customer interaction, and cross functional team interaction

  • Effectively triage support problems and respond with the appropriate level of urgency
    Participate in a 24x7 on-call weekly rotation as scheduled, and the ability to perform after hours support as needed. Current rotation is about 3 weeks per year.

Qualification Requirements:

  • Strong fundamentals in general Cybersecurity concepts with an interest in learning more about and contributing to Application Security

  • Functional understanding with at least one coding or scripting language: e.g. PowerShell, Python, .Net, Javascript, C#

  • Excellent analytical, troubleshooting, and problem-solving skills and performs well in high pressure or stressful situations 

  • Excellent organization and time management skills 

  • Excellent communication skills to include, but not limited to, verbal and written communication; delivering organized presentations; able to tailor message to the audience; and facilitate group discussions with diplomacy and seek diverse opinions

  • Ability to effectively estimate the efforts of others and the impact required to accomplish requested tasks/projects


Preferred Qualifications

  • Functional proficiency with at least one coding or scripting language

  • Experience performing dynamic application security testing (DAST) using open source and commercial tools.

  • Experience performing static security code analysis (SAST) and providing relevant recommendations to stakeholders.

  • Experience integrating security into the container lifecycle, including image assurance, Kubernetes posture management, secrets management, and runtime threat detection


Education and/or Experience:

  • Bachelor’s Degree in Computer Science, Engineering, Cybersecurity, or a related field, or equivalent alternative education, skills, and/or practical experience is required.

  • 2+ years of work experience required in Cybersecurity or other areas directly relevant to cybersecurity responsibilities and tasks.

  • Knowledge of developer tools like GitHub, Azure DevOps, and TeamCity.

  • Experience with Public Cloud: e.g. Azure, AWS, GCP.

  • Understanding of development and product teams and DevSecOps best practices.

  • CISSP certification preferred but not required.

Work Location and Arrangement: This role will be based out of the CarMax Home Office at West Creek (Richmond, VA) and associates will work onsite 4 days per week. 

Work Authorization:  Applicants must be currently authorized to work in the United States on a full-time basis. 

About CarMax

CarMax disrupted the auto industry by delivering the honest, transparent and high-integrity experience customers want and deserve. This innovative thinking around the way cars are bought and sold has helped us become the nation’s largest retailer of used cars, with over 200 locations nationwide.

Our amazing team of more than 25,000 associates work together to deliver iconic customer experiences. Along the way, we help every associate grow their career and achieve their best, at work and in their community.  We are recognized for our commitment to training and diversity and are one of the FORTUNE 100 Best Companies to Work For®.

Our Commitment to Diversity and Inclusion:

CarMax is committed to bringing together people from different backgrounds and perspectives, providing employees with a safe, welcoming, and inclusive work environment.

CarMax is an equal opportunity employer, and all qualified candidates will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, protected veteran status, disability status, or any other characteristic protected by law.

The annual salary for this position is:

$80,600.00 - $120,900.00

May be eligible for bonus and equity.

Benefits:

Except as otherwise required by state law, CarMax Associates are entitled to the following paid sick, vacation, and holiday time.

Associates that are considered full-time hourly or commission/incentive eligible:

  • To earn up to 48 hours of sick time per year accrued on a per pay period basis and between 80 hours and 200 hours per year of vacation time after a 90 day waiting period depending on years of continuous service with the Company. 
  • For 8 hours of pay for each of a total of 6 paid scheduled holidays per year plus 1 floating holiday.  If such an Associate does work on a scheduled holiday due to business need, they are eligible for Holiday Premium Pay. 

Associates considered full-time salaried are entitled to paid time away with no specified limit as needed for sick, vacation, bereavement, jury duty, holidays, floating holiday, etc. subject to manager approval. 

For more details about benefits, please visit our CarMax Benefits website.

Upon an applicant's request, CarMax will consider reasonable accommodation to complete the CarMax Job Application.


What CarMax employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


CarMax logo

About CarMax

Sourced by ZipRecruiter

CarMax disrupted the auto industry by delivering the honest, transparent and high-integrity experience customers want and deserve. This innovative thinking around the way cars are bought and sold has helped us become the nation's largest retailer of used cars, with over 200 locations nationwide. Our amazing team of more than 25,000 associates work together to deliver iconic customer experiences. Along the way, we help every associate grow their career and achieve their best, at work and in their community. We are recognized for our commitment to training and diversity and are one of the FORTUNE 100 Best Companies to Work For®.

Industry

Automobile dealers and finance and insurance

Company size

10,000+ Employees

Headquarters location

Henrico, VA, US