1

Application Security Jobs in Washington (NOW HIRING)

Application Security Engineer

Ashburn, VA · On-site

$60 - $80.25/hr

Work on ensuring systems and applications comply with Security Technical Implementation Guide * Establish and maintain the definitive current basis for control and status accounting of application ...

Sr. Application Security Engineer

Vienna, VA · On-site

$59 - $78.75/hr

As an Application Security Engineer at Esri, you will fill a critical role in helping secure Esri's intellectual property and sensitive data against a variety of complex threats with support from all ...

Our Application Security team collaborates closely with the application development, DevSecOps, and information security departments to design security into our applications up front, perform ...

Sr. Application Security Engineer

Vienna, VA · On-site

$59 - $78.75/hr

Perform application layer security reviews of the code developed by our application teams, across multiple languages and frameworks used internally * Assist with application layer penetration testing ...

Application Security Engineer 3

Arlington, VA · On-site

$67.75 - $90.50/hr

Job Summary As an Application Security EngineerIII, you will lead security engineering initiatives, perform advanced risk assessments, and design scalable security controls across critical ...

Showing results 21-40

Application Security information

See Washington salary details

$43

$60

$107

How much do application security jobs pay per hour?

As of Sep 12, 2026, the average hourly pay for application security in Washington is $60.81, according to ZipRecruiter salary data. Most workers in this role earn between $48.46 and $63.17 per hour, depending on experience, location, and employer.

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications like Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, firewalls, and vulnerability scanners to identify and mitigate risks throughout the development lifecycle.

What cities in Washington are hiring for Application Security jobs?

Cities in Washington with the most Application Security job openings:

Infographic showing various Application Security job openings in Washington as of August 2026, with employment types broken down into 75% Full Time, 15% Part Time, 2% Temporary, and 8% Contract. Highlights an 87% Physical, 2% Hybrid, and 11% Remote job distribution, with an average salary of $126,481 per year, or $60.8 per hour.

Application Security Engineer I

Arlington, VA • On-site

Bloomberg Industry Group
Library and Information Services • 51 - 200 employees

$90K - $110K/yr

Full-time

Re-posted 6 days ago


Job description

Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation support, and incident response participation, contributing to secure development practices across internal and external applications.

About the Team:
At Bloomberg Industry Group, our Application Security team ensures the security of internal and external applications and services. We leverage innovative security tools and a team of dedicated security engineers to protect our products throughout their lifecycle.

Job Summary:
As an Application Security Engineer I, you will be part of a team responsible for ensuring the security of applications, conducting security assessments, and implementing security controls. You will work closely with developers, providing guidance on secure coding practices, and working to integrate security into our CI/CD pipelines.

This entry-level role is ideal for candidates beginning their Application Security career and looking to grow into a seasoned Application Security Engineer.

What You Will Do:

  • Participate in application security practices such as:
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)
  • Penetration Testing
  • Participate in vulnerability management processes.
  • Assist in the development, deployment and automation of security tools, scripts, and processes.
  • Collaborate with software engineers to design, implement, and review security features in applications.
  • Support the identification and resolution of security incidents as part of the incident response team.
  • Stay current on emerging security trends, vulnerabilities, and tooling to continuously elevate Application Security.

You Need to Have:

  • Basic knowledge of security principles, standards, and best practices.
  • Familiarity with one or more programming languages (e.g., Python, Java, JavaScript).
  • Ambition to learn and grow into AI Security and Security Engineering.
  • Exposure to security testing tools like SAST, DAST, SCA, and/or vulnerability management platforms.
  • An associate's degree in Information Security, Computer Science, or a related field, or equivalent experience.
  • 1-2 years of relevant experience.

We would Love to See:

  • Certifications such as CompTIA Security+ , CompTIA Pentest+, Certified DevSecOps Professional (CDP) or equivalent.
  • Hands-on experience with:
  • CI/CD pipelines (GitLab, GitHub Actions, Jenkins)
  • Cloud environments (AWS)
  • Secure coding or code review
  • Security automation or scripting
  • Participation in security communities, Capture The Flag (CTF) events, open-source contributions, or similar skill-building activities.

Compensation Range:

$90,000.00-$110,000.00

Placement in the salary range will be decided upon completion of the interview process. Salary determination will be determined based on factors including but not limited to relevant experience, demonstrated skills related to the requirements of the role, education, certifications, and geographic location.


Equal Opportunity


Bloomberg Industry Group maintains a continuing policy of non-discrimination in employment. It is Bloomberg Industry Group's policy to provide equal opportunity and access for all persons, and the Company is committed to attracting, retaining, developing, and promoting the most qualified individuals without regard to age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy or maternity/parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law ("Protected Characteristic"). Bloomberg prohibits treating applicants or employees less favorably in connection with the terms and conditions of employment, in all phases of the employment process, because of one or more Protected Characteristics ("Discrimination").