1

Application Security Jobs (NOW HIRING)

Application Security Engineer

Washington, DC ยท On-site

$135K - $155K/yr

The Application Security Engineer protects mission-critical web applications, application programming interfaces (APIs), and sensitive data by embedding security across the software development ...

Application Security Engineer

$60.25 - $80.25/hr

RIT Solutions, Inc. is seeking an Application Security Engineer to enhance the security of their ongoing AI development efforts. The role involves designing and implementing cloud and application ...

Application Security (AppSec) Engineer $60/hr W2 Onsite - Maryland Heights, MO Cog Kit BGV must be cleared to start What are the top 3 skills required for this role? * Application Security (AppSec)

Application Security Engineer

$60.25 - $80.25/hr

Overview Application Security Engineer Remote within the US US Citizen Approximately 8 Month Contract (w/ possible extensions) Summary The Application Security Engineer candidate will have a strong ...

Application Security Analyst

Auburn Hills, MI ยท On-site

$55.50 - $74.25/hr

Application Security & Testing * Perform security testing: SAST, DAST, IAST, mobile security, and dynamic testing * Analyze vulnerabilities and recommend secure coding fixes * Demonstrate ...

Application Security Engineer

Salt Lake City, UT ยท On-site +1

$56.75 - $76/hr

Application Security Engineer About the Role Packsize is seeking an experienced Application Security Engineer to champion secure software development across our technology stack. You will collaborate ...

Application Security Specialist Location: Cambridge, MA Duration: 6 Months(Extendable) Roles & Responsibilities: Creating application security related policies & processes Creating RFP for selecting ...

Application Security Principal

Dublin, OH ยท On-site +1

$56.75 - $75.75/hr

About the role The Application Security Principal is a senior, hands-on security leader who reports directly to the Chief Information Security Officer (CISO) and is responsible for building ...

Application Security Principal

Dublin, OH ยท On-site +1

$56.75 - $75.75/hr

About the role The Application Security Principal is a senior, hands-on security leader who reports directly to the Chief Information Security Officer (CISO) and is responsible for building ...

Application Security Engineer

Dallas, TX ยท On-site

$58.25 - $78/hr

Application security testing; SAST/DAST (Veracode/Burp Suite); vulnerability validation; secure SDLC. * Design, develop, and maintain scalable test automation frameworks for enterprise applications.

$54.50 - $72.75/hr

Reporting to the Head of Application & Product Security, you'll work closely with software engineers to identify, investigate and remediate security vulnerabilities while helping embed security ...

Application Security Engineer

Boston, MA ยท Hybrid

$145K - $155K/yr

The Application Security Engineer (ASE) will serve in a multi-functional role, advising development teams on secure coding and accepted industry procedures. The ASE is responsible for leading SDLC ...

Application Security Testing

Foster City, CA ยท On-site

$68.50 - $91.50/hr

Knowledge of application security vulnerabilities such as the OWASP Top 10 * Ability to handle difficult situations and to provide alternative solutions or workarounds to address vulnerabilities

Director, Application Security

San Francisco, CA ยท On-site

$69.25 - $92.50/hr

They are seeking a Director of Application Security to lead the development of an AI-native Application Security function, embedding security intelligence into the software development lifecycle and ...

Application Security Engineer

$60.25 - $80.25/hr

The Application Security Engineer supports secure coding standards, threat modeling, static and dynamic testing, and secure secrets management. This position plays a critical role in strengthening ...

Showing results 41-60

Application Security information

See salary details

$38

$53

$95

How much do application security jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for application security in the United States is $53.69, according to ZipRecruiter salary data. Most workers in this role earn between $42.79 and $55.77 per hour, depending on experience, location, and employer.

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications such as Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, authorization, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, penetration testing, and code reviews to identify and fix security issues throughout the development lifecycle.
What cities are hiring for Application Security jobs? Cities with the most Application Security job openings:
What states have the most Application Security jobs? States with the most job openings for Application Security jobs include:
Infographic showing various Application Security job openings in the United States as of August 2026, with employment types broken down into 77% Full Time, 18% Part Time, and 5% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $111,673 per year, or $53.7 per hour.

Application Security Engineer

Spry Methods

Washington, DC โ€ข On-site

$135K - $155K/yr

Contractor

Medical, Dental, Vision, Retirement, PTO

This job post hasย expired today.ย Applications are no longer accepted.


Job description

Company Overview

Spry Methods is a proven provider of mission-focused technology, cybersecurity, and program management solutions supporting critical Federal and DoD missions. We specialize in delivering integrated, high-impact solutions across cyber operations, enterprise resource management, and mission support services. Our culture emphasizes collaboration, accountability, and innovation - empowering our teams to deliver meaningful outcomes in complex, high-security environments. 


Who Weโ€™re Looking For (Position Overview):

The Application Security Engineer protects mission-critical web applications, application programming interfaces (APIs), and sensitive data by embedding security across the software development lifecycle. This role combines application security engineering, secure software development, vulnerability remediation, monitoring, and compliance support.   

\\n


What Your Day-To-Day Looks Like (Position Responsibilities):
  • Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs. 

  • Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions. 

  • Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services. 

  • Review and analyze web server and application logs to detect anomalies and indicators of compromise. 

  • Implement automation scripts for threat intelligence integration and application security monitoring. 

  • Participate in audits, risk assessments, and security authorization activities tied to federal frameworks. 


What You Need to Succeed (Minimum Requirements):
  • Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work. 

  • Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation. 

  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL). 

  • Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts. 

  • Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools. 

  • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies. 

  • Bachelor\'s degree or higher in computer science, cybersecurity, information systems, engineering, or a related field. 

  • Ability to meet federal screening and suitability requirements prior to start. 

  • Current security certifications maintained for a minimum of five years: 

    • Specialized AppSec:
      • Certified Secure Software Lifecyle Professional (CSSLP)
      • GIAC Certified Web Application Defender (GWEB)
      • EC-Council Certified Application Security Engineer (CASE)
    • Offensive Security:
      • OffSec Web Expert (OSWE)
      • Offensive Security Certified Professional (OSCP)
    • Foundational Security:
      • Security+
      • GSEC


Ideally, You Also Have (Preferred Qualifications):
  • In-depth experience with federal cybersecurity frameworks and authorization processes. 

  • Experience with threat modeling, resilient security architecture, cloud security, and container security. 


\\n$135,000 - $155,000 a yearFinal compensation will be based on experience, qualifications, certifications, clearance level, and contract requirements. This position is contingent upon contract award.\\n

Perks of Working for Us (Benefits):

Medical Coverage โ€“ Cigna - 4 Options

- Traditional - PPO Open Access Plus Network

- (2) HDHP - PPO Open Access Plus Network

- HDHP - EPO Open Access Plus Network

Dental Coverage โ€“ Cigna - PPO Base & Buy-Up Plans

Vision Coverage โ€“ Principal - VSP Choice Network

Paid Holidays: Full-time employees receive 11 paid federal holidays

Paid Time Off (PTO) โ€“ PTO accrual starts at 15 days per year

Training Benefit โ€“ Annual training allowance available toward any job-related training or education

401(k) โ€“ Multiple Fund Choices through Fidelity with a company match

For our full list of benefits, please visit http://www.sprymethods.com/careers/benefits/

EEO Statement

At Spry, we believe talented and dedicated employees are our most valued assets and the foundation of our success. We are committed to crafting a diverse and inclusive workplace that endorses engagement, creativity, quality and innovation.

We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.