1

Application Security Jobs in Virginia (NOW HIRING)

AppSec Security Engineer

Arlington, VA

$67.50 - $90.25/hr

None POSITION SUMMARY STATEMENT We are seeking an experienced Application Security Engineer to build, mature, and scale our AppSec program. In this role, you will embed directly with our Product and ...

The work The Application Security Lead is responsible for leading the end‑to‑end security readiness of applications, ensuring compliance with federal and enterprise security frameworks, ATO ...

DevSecOps Engineer

Arlington, VA · On-site

$67.50 - $90.25/hr

Integrate automated security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and container ...

Showing results 41-60

Application Security information

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications such as Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, authorization, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, penetration testing, and code reviews to identify and fix security issues throughout the development lifecycle.
What cities in Virginia are hiring for Application Security jobs? Cities in Virginia with the most Application Security job openings:
Infographic showing various Application Security job openings in Virginia as of August 2026, with employment types broken down into 80% Full Time, 16% Part Time, and 4% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution.

Web Application Security Testing Team Lead

gTANGIBLE

Arlington, VA

Full-time

Re-posted 19 days ago


Job description

gTANGIBLE Corporation (gTC), www.gtangible.com, is a C corporation and a registered Government contractor that provides services and solutions in:

  • National Security Programs
  • Professional, Administrative, and Management Support
  • Mission and Warfighter Support

We are a Service Disabled Veteran Owned Small Business (SDVOSB) and the founder has years of successful experience in the Government contracting arena. Our leadership team is an exceptional group of Government contracting professionals. gTANGIBLE is in the process of identifying candidates for the following position.

Requisition Type: Full Time

Position Status: Contingent

Position Title: Web Application Security Testing Team Lead

Location: National Capital Region

Security Clearance: Secret

Duties and Responsibilities

The Web Application Security Testing Team Lead supports this Transportation Security Administration Information Technology (TSA IT) Task Order (TO) by web application testing that require testing both via automated tools and with manual testing techniques. Application testing will require authenticated and non-authenticated testing to ensure full evaluation of the cybersecurity controls for the applications. Off hours testing conducted on a as needed basis. Periodic travel required.

Team duties include the following:

  • Become, and remain, familiar with TSA and DHS security policies and Technical Standards relating to web applications and web application development to facilitate effective security assessments. Make recommendations for updates, additions, and modifications to TSA security policy as gaps or deficiencies in security policy are identified.
  • Engage with testing engagement stakeholders to gather all required information needed to create detailed test plans.
  • Conduct security testing of web applications and services (and other web-related assets) using both Information Assurance and Cybersecurity Division (IAD)-provided automated testing tools and manual testing techniques.
  • Troubleshoot any technical issues preventing successful completion of testing engagements within the scheduled time allotted for the engagement (i.e. insufficient credentials, proxy blocking, accounts blocked/expired, etc.).
  • Participate in findings meetings to review and provide input on the validity of application stakeholder responses to IAD findings.
  • Recommend adjustments of finding validity (valid or false positive) and severity (high, medium, low) to Governance, Risk, and Compliance (GRC) Portfolio Managers and Primary Assessors based on stakeholder responses.
  • Review application stakeholder mitigation or remediation actions to address valid findings to assist IAD with determining the applicability and effectiveness of those actions.
  • Provide Subject Matter Expertise for a variety of topics concerning web applications in a variety of formats (verbal or written). Includes common and emerging web and mobile technologies, languages, and frameworks to discuss the benefits and security detriments of those technologies.
  • Provide support for external security audits conducted of the TSA. Such support would include items such as: providing technical insight into data calls required by external Federal entities, offering technical information to facilitate external auditors work, or validating findings identified in external audit reports.

Knowledge and Qualifications

  • At least eight (8) years of technical IT security experience. Such experience can come from system or network administration, security analysis, security testing and evaluation, security incident response, security monitoring, IT project implementation, or other similar technical activities.
  • At least five (5) years of experience performing security control assessments (i.e. security testing such as security auditing, primary assessor for Security Control Assessments, etc.).
  • At least three (3) years of experience performing web application security testing.
  • At least one (1) year of experience performing security testing of Federal IT systems.
  • Experience with NIST and FIPS security controls, DISA STIGs, and CIS standards.
  • Experience working in groups acting as the sole security practitioner, as well as experience working in team(s) of various sizes of security personnel reviewing the same system.
  • Experience with HP WebInspect, IBM/HCL AppScan, Portswigger BurpSuite, SmartBear SoapUI, Nessus Professional, HP Fortify, Apple Developers Toolkit, Eclipse, and Wireshark.
  • Excellent communication skills to be able to understand concepts being verbally presented, participate in group discussions, and to present recommendations.
  • Strong organizational, analytical, and technical writing skills to be able to document findings in reports.

gTANGIBLE Corporation is an equal opportunity employer and does not discriminate against any employee or applicant because of race, age, sex, color, physical or mental disability, religion, sexual orientation, marital status, national origin, or political affiliation.

Employment Type: Full-Time