1

Application Security Jobs in Virginia (NOW HIRING)

Security Engineer, AWS AppSec

Herndon, VA · On-site

$60.50 - $80.75/hr

AWS Security is looking for an Application Security Engineer to help validate that our services, applications, and websites are designed and implemented to the highest security standards. You will be ...

Security Engineer, AWS AppSec

Herndon, VA · On-site

$60.50 - $80.75/hr

AWS Security is looking for an Application Security Engineer to help validate that our services, applications, and websites are designed and implemented to the highest security standards. You will be ...

Security Engineer, AWS AppSec

Herndon, VA

$60.50 - $80.75/hr

AWS Security is looking for an Application Security Engineer to help validate that our services, applications, and websites are designed and implemented to the highest security standards. You will be ...

Sr Security Engineer

Reston, VA · On-site

$140K - $202K/yr

Primary focus is Application Security-embedding security into the SDLC and CI/CD pipelines, strengthening web/API protections, and enabling proactive detection, while contributing broadly to Security ...

New

Sr Security Engineer

Reston, VA · On-site

$140K - $202K/yr

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process. Sr Security Engineer Reston, VA, US ...

New

This role will work closely with the EHR Application Team, EHR Security Officer, Information Security Office (ISO), EHR Core Team, IT Technical Team, Support Team, and HIPAA Compliance stakeholders ...

DevSecOps Engineer

Arlington, VA · On-site

$67.50 - $90.25/hr

Integrate automated security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and container ...

Showing results 41-60

Application Security information

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications like Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, firewalls, and vulnerability scanners to identify and mitigate risks throughout the development lifecycle.

What cities in Virginia are hiring for Application Security jobs?

Cities in Virginia with the most Application Security job openings:

Infographic showing various Application Security job openings in Virginia as of August 2026, with employment types broken down into 71% Full Time, 25% Part Time, and 4% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution.

Senior Java Technical Lead - Application Security Remediation

Mclean, VA • On-site

Contractor

Posted 6 days ago


Job description

Job Title

Senior Technical Lead - Application Security Remediation (Java / Spring Boot / Angular)

Experience

10+ years of software engineering experience
Required range: 8-10 years

Role Overview

We are seeking a hands-on Senior Technical Lead to lead enterprise-wide application security remediation initiatives across multiple engineering teams. The role combines software development, application security, vulnerability management, and technical leadership.

The candidate will analyze security vulnerabilities, define remediation strategies, implement security fixes across Java/Spring Boot and Angular applications, and drive secure development practices across engineering teams.

Key Responsibilities
  • Lead application security remediation initiatives across multiple engineering teams.
  • Analyze vulnerabilities and security findings from ArmorCode, Contrast Security, Snyk, SonarQube, and similar tools.
  • Prioritize vulnerabilities based on severity, risk, and business impact.
  • Track remediation activities and drive vulnerabilities to closure.
  • Perform hands-on coding to implement security fixes in Java/Spring Boot and Angular applications.
  • Conduct code reviews and recommend secure coding practices.
  • Develop reusable security remediation patterns to reduce recurring vulnerabilities.
  • Collaborate with Engineering, Architecture, Security, and DevOps teams.
  • Lead and mentor a 3-5 member security remediation team.
  • Monitor remediation progress and provide dashboards, status reports, and executive-level updates.
  • Support security governance, change management, and continuous improvement initiatives.
Required Technical Skills Skill Requirement Java Strong hands-on experience Spring Boot Strong hands-on experience Angular Strong hands-on experience JavaScript / TypeScript Strong hands-on experience REST APIs Required Microservices Required GitHub Required CI/CD Required OWASP Top 10 Strong understanding Secure SDLC Required DevSecOps Required SAST / DAST Required Vulnerability Management Required Security Tools ArmorCode, Contrast, Snyk, Veracode, Checkmarx, SonarQube or similar Security & Governance
  • Strong understanding of application security principles and secure software development.
  • Experience identifying and remediating vulnerabilities throughout the SDLC.
  • Understanding of SAST, DAST, code scanning, dependency vulnerabilities, and security findings.
  • Experience with security governance and vulnerability tracking.
  • Ability to work with development teams to implement sustainable security improvements.
Leadership & Soft Skills
  • Strong technical leadership and mentoring capabilities.
  • Experience leading a small technical/security remediation team.
  • Excellent communication and stakeholder management skills.
  • Ability to work with engineering, architecture, security, and business stakeholders.
  • Strong problem-solving and analytical skills.
  • Ability to provide clear technical and executive-level status reporting.
Preferred Background
  • Experience in enterprise application security remediation.
  • Experience working with Java/Spring Boot and Angular applications.
  • Experience managing vulnerabilities across multiple applications or engineering teams.
  • Healthcare/security governance experience is beneficial if applicable.