1

Appsec Jobs in Virginia (NOW HIRING)

DevOps Engineer

Arlington, VA · On-site

$77K - $176K/yr

... AppSec compliance, and enabling CI/CD pipelines powered by Docker containerization. Join us. The world can't wait. You Have: * 4+ years of experience with containerization technologies, such as ...

... AppSec compliance, and enabling CI/CD pipelines powered by Docker containerization. Join us. The world can't wait. You Have: * 4+ years of experience with containerization technologies, such as ...

Senior Engineer, Application Security

Tysons, VA · On-site

$59.50 - $79.25/hr

Mentor Engineer II and mid-level teammates, review their automation and findings, and grow the team's AI and AppSec capability. * Communicate risk clearly to both engineering and leadership audiences ...

Showing results 21-25

Appsec information

What is the difference between Appsec vs Security Analyst?

AspectAppsecSecurity Analyst
Required CredentialsCertifications like CISSP, CEH, OSCP; knowledge of secure codingCertifications such as Security+, CISSP; threat analysis skills
Work EnvironmentDevelopment teams, secure coding practices, application testingMonitoring security systems, incident response, risk assessment
Employer & Industry UsageTech companies, software firms, organizations with application security needsAll industries, including finance, healthcare, government, focusing on security monitoring

Appsec professionals focus on securing applications through secure coding, testing, and vulnerability management, while Security Analysts monitor and respond to security threats across systems. Both roles require security certifications and work in overlapping environments, but their core responsibilities differ in scope and focus.

Is Appsec entry level?

Application security (AppSec) roles can be entry-level or require experience, depending on the position. Entry-level AppSec jobs typically focus on basic security practices, vulnerability assessments, and may require foundational knowledge of security tools and programming. More advanced roles often demand prior experience, certifications, or specialized skills in areas like penetration testing or secure coding.

Is application security in demand?

Application security (AppSec) professionals are in high demand due to increasing cyber threats and the widespread adoption of digital services. Organizations seek skilled experts to identify vulnerabilities, implement security measures, and ensure compliance, often requiring knowledge of security tools, coding, and certifications like CISSP or CEH.

Will AI replace appsec engineers?

AI is unlikely to fully replace application security (AppSec) engineers, as their role involves complex analysis, decision-making, and understanding of context that current AI tools cannot replicate. Instead, AI can augment their work by automating routine tasks like vulnerability scanning and code analysis, allowing engineers to focus on more strategic security measures. Continuous learning and expertise in security tools, coding, and threat assessment remain essential for AppSec professionals.

What are popular job titles related to Appsec jobs in Virginia?

For Appsec jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Appsec jobs in Virginia look for?

The top searched job categories for Appsec jobs in Virginia are:

Infographic showing various Appsec job openings in Virginia as of August 2026, with employment types broken down into 84% Full Time, 11% Part Time, and 5% Contract. Highlights an 58% Physical, 13% Hybrid, and 29% Remote job distribution.

Application Security Engineer 3

Bloomberg Industry Group

Arlington, VA • On-site

$155K - $185K/yr

Full-time

Re-posted yesterday


Job description

Responsible for leading application security engineering efforts, designing scalable security architectures, performing advanced risk assessments, integrating security across the SDLC, driving AI-related security controls, evaluating vendor solutions, scaling automation, and contributing to incident response and strategic security improvements.
About the Team:
Bloomberg Industry Group's Application Security team is focused on providing best-in-class security for all internal and external applications. We are constantly evolving our security practices to tackle modern-day threats and ensure our applications remain secure.
Job Summary:
As an Application Security Engineer III, you will lead security engineering initiatives, perform advanced risk assessments, and design scalable security controls across critical applications. You will serve as a subject matter expert (SME) in application, guiding engineering teams, influencing security strategy, and driving automation across the SDLC.
This role requires deep technical expertise, leadership potential, and the ability to shape long-term Application Security direction.
What You Will Do:
  • Design and implement security architectures and controls for large-scale, cloud-native applications.
  • Conduct in-depth risk assessments, including penetration testing and code reviews.
  • Collaborate with developers and DevOps teams to integrate security at all stages of the software development lifecycle (SDLC).
  • Drive security for AI-powered features by defining secure architectures, assessing AI/ML risks, and implementing advanced testing and controls for AI models, agents, and MCP servers.
  • Identify areas of improvements in security tools and practices, and remediate the identified gap by implementing innovative solutions.
  • Evaluate third-party security tools and vendor-provided controls for technical effectiveness, enterprise fit, and alignment with organization's security architecture and standards.
  • Collaborate with vendors to provide actionable technical feedback, drive product improvements, and ensure controls are implemented and configured appropriately for Bloomberg Industry Group's environment.
  • Build, improve, and scale security automation, integrating tooling across CI/CD pipelines and cloud platforms.
  • Provide guidance to junior engineers and cross-functional teams on security best practices.
  • Participate in incident response efforts and investigations into security incidents.
  • Stay ahead of the curve by keeping informed of industry trends and emerging threats, applying this knowledge to continually improve security.

You Need to Have:
  • Deep expertise in application security, secure software design, and risk management, including frameworks such as OWASP ASVS, OWASP Top 10, and NIST 800-53.
  • Extensive experience conducting complex security assessments and building automated security controls for large engineering environments.
  • Proficiency in multiple programming languages (e.g., Python, Java, JavaScript) and hands-on experience with SAST, DAST, SCA, IaC, container, and cloud security tools.
  • Strong understanding of modern architectures (cloud-native, microservices, Kubernetes, containers, serverless) and DevSecOps processes.
  • Advanced understanding of AI/ML security, including model vulnerability analysis, AI threat modeling, secure LLM integration patterns, and familiarity with NIST AI RMF or OWASP Top 10 for LLMs.
  • 5-7 years of relevant experience in Application Security, AppSec engineering, Cloud Security, or Software Engineering.

We would Love to See:
  • Certifications such as
  • AWS Certified Security - Specialty
  • CSSLP or CISSP
  • Certified DevSecOps Expert (CDE) or equivalent
  • A bachelor's degree in information security, Computer Science, or a related field, or equivalent experience.

Compensation Range:
$155,000.00-$185,000.00
Placement in the salary range will be decided upon completion of the interview process. Salary determination will be determined based on factors including but not limited to relevant experience, demonstrated skills related to the requirements of the role, education, certifications, and geographic location.
Equal Opportunity
Bloomberg Industry Group maintains a continuing policy of non-discrimination in employment. It is Bloomberg Industry Group's policy to provide equal opportunity and access for all persons, and the Company is committed to attracting, retaining, developing, and promoting the most qualified individuals without regard to age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy or maternity/parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law ("Protected Characteristic"). Bloomberg prohibits treating applicants or employees less favorably in connection with the terms and conditions of employment, in all phases of the employment process, because of one or more Protected Characteristics ("Discrimination").