1

Microsoft Application Security Engineer Jobs (NOW HIRING)

Application Security Engineer

Herndon, VA ยท On-site

$60.50 - $80.75/hr

The Application Security Engineer will be responsible for the end-to-end administration of Burp Suite and Veracode, managing Integrated Development Environment (IDE) plugins and ensuring all ...

Application Security Engineer

Herndon, VA ยท On-site

$60.50 - $80.75/hr

The Application Security Engineer will be responsible for the end-to-end administration of Burp Suite and Veracode, managing Integrated Development Environment (IDE) plugins and ensuring all ...

Application Security Engineer

New York, NY ยท On-site

$64.25 - $86/hr

Learn more about our work with Microsoft: Valence Brings AI Coaching More Deeply Into the Flow of ... The Role We are seeking a seasoned Application Security Engineer to help us secure our products and ...

Application Security Engineer

Manhattan, NY ยท On-site

$64.75 - $86.50/hr

Application Security Engineer NYC / Charlotte NC- 3 Days Onsite W2 Position Overview: This role will be an integral component of the application security program end-to-end -- from discovery and ...

Define application security strategy, standards, and SDLC integration points; champion secure-by-design practices across engineering and DevSecOps teams. * Lead threat modeling and secure ...

Define application security strategy, standards, and SDLC integration points; champion secure-by-design practices across engineering and DevSecOps teams. * Lead threat modeling and secure ...

Description Your Impact The Application Security Engineer is responsible for embedding security throughout the software development lifecycle (SDLC), leading application security testing, and driving ...

Application Security Engineer

Herndon, VA ยท On-site

$104K - $166K/yr

Define application security strategy, standards, and SDLC integration points; champion secure-by-design practices across engineering and DevSecOps teams. * Lead threat modeling and secure ...

Application Security Engineer

$60.25 - $80.25/hr

Opportunity We are seeking a highly motivated Application Security Engineer to join our growing security organization. This role will be instrumental in building and managing our application and ...

OR

$58.75 - $78.50/hr

Rubrik is seeking an Application Security Engineer. In this role, you will be responsible for ensuring that Rubrik's products and services are designed and implemented to the highest possible ...

Application Security Engineer

Herndon, VA ยท Hybrid

$60.25 - $80.75/hr

Minimum of 5 years experience working "hands-on" in application security engineering * Hands-on experience with Fortify, Veracode, Tenable, Black Duck, or similar platforms * Hands-on experience with ...

Application Security Engineer

Lindon, UT ยท On-site

$53 - $70.75/hr

We're looking for an Application Security Engineer joining our IT & Security team to build and mature our application security program as we continue to scale our SaaS platform. In this role, you'll ...

Application Security Engineer

Lindon, UT ยท On-site

$53 - $70.75/hr

We're looking for an Application Security Engineer joining our IT & Security team to build and mature our application security program as we continue to scale our SaaS platform. In this role, you'll ...

We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud ...

Senior Application Security Engineer

Westbrook, ME ยท On-site

$59.75 - $80/hr

IDEXX Laboratories is seeking a Senior Application Security Engineer to join our Product & Application Security team protecting applications across development teams. This role combines hands-on ...

Application Security Engineer

Hanover, MD

$58 - $77.25/hr

The Application Security (AppSec) Engineer will leverage their strong technical background and knowledge to support software assurance and security initiatives for a mission-critical organization ...

next page

Showing results 1-20

Microsoft Application Security Engineer information

See salary details

$29

$66

$96

How much do microsoft application security engineer jobs pay per hour?

As of Jun 9, 2026, the average hourly pay for microsoft application security engineer in the United States is $66.40, according to ZipRecruiter salary data. Most workers in this role earn between $56.49 and $75.48 per hour, depending on experience, location, and employer.

What is the difference between Microsoft Application Security Engineer vs Security Analyst?

AspectMicrosoft Application Security EngineerSecurity Analyst
CertificationsSecurity+, CISSP, Microsoft certificationsSecurity+, CEH, CISSP (optional)
Work EnvironmentFocus on application security within Microsoft ecosystemsBroader security monitoring and incident response
Employer & IndustryTech companies, especially Microsoft-focused environmentsVarious industries, including finance, healthcare, and government
Search & Comparison IntentUnderstanding specialized application security roles in Microsoft contextGeneral security roles and responsibilities

The Microsoft Application Security Engineer specializes in securing Microsoft applications and cloud services, often requiring specific certifications and a focus on application-level security. In contrast, a Security Analyst has a broader role in monitoring, analyzing, and responding to security threats across various systems. Both roles share some certifications but differ in scope and focus, with the Microsoft Application Security Engineer being more specialized in Microsoft environments.

Infographic showing various Microsoft Application Security Engineer job openings in the United States as of May 2026, with employment types broken down into 1% As Needed, 74% Full Time, 24% Part Time, and 1% Contract. Highlights an 90% Physical, 4% Hybrid, and 6% Remote job distribution, with an average salary of $138,117 per year, or $66.4 per hour.
Application Security Engineer

Application Security Engineer

Shorepoint Inc.

Herndon, VA โ€ข On-site

$60.50 - $80.75/hr

Full-time

Medical, Retirement, PTO

Posted 19 days ago


Job description

Who we are:
ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a "work hard, play hard" mentality and celebrates individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion and a focus on giving back to our community.
The Perks:
As recognized members of the Cyber Elite, we work together in partnership to defend our nation's critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individuals technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 144 hours of PTO, 11 holidays, 85% of insurance premium covered, 401k, continued education, certifications maintenance, reimbursement and more.
Who we're looking for:
We are seeking an Application Security Engineer with expertise in Static and Dynamic Application Security Testing (SAST & DAST) methodologies and enterprise-level security controls. Your mission is to fortify our software supply chain by integrating rigorous security testing directly into the development lifecycle to preemptively neutralize vulnerabilities. The Application Security Engineer will be responsible for the end-to-end administration of Burp Suite and Veracode, managing Integrated Development Environment (IDE) plugins and ensuring all enterprise web applications align with federal compliance and OWASP standards. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.
What you'll be doing:
  • Support and operate application security testing capabilities across SAST, DAST and IDE plug-in environments, with primary focus on Burp Suite and Veracode.
  • Configure, maintain and troubleshoot Burp Suite and Veracode integrations to enable consistent application security testing workflows.
  • Partner with development and engineering teams to identify, validate and remediate security vulnerabilities.
  • Apply vulnerability standards and scoring methodologies to findings, including OWASP Top 10, CVSS, CWE, WASC and SANS-25.
  • Navigate and troubleshoot within Linux or UNIX environments, including basic website connectivity issues.
  • Support the design and implementation of enterprise-wide security controls that secure applications, systems, networks or infrastructure services.
  • Use IDEs and development toolchains (Eclipse, JDeveloper, Visual Studio) to support developer workflows, including pipeline development activities where applicable.
  • Support compliance-aligned security activities in federal environments leveraging NIST 800-53, FIPS and/or FedRAMP standards.

What you need to know:
  • Strong understanding of application security testing concepts and operational support for SAST, DAST and IDE plug-in environments.
  • Hands-on capability with enterprise web application security and common vulnerability classes.
  • Familiarity with vulnerability scoring, classification and prioritization frameworks (OWASP Top 10, CVSS, CWE, WASC, SANS-25).
  • Working knowledge of federal compliance standards (NIST 800-53, FIPS, FedRAMP).
  • Ability to work effectively in Linux or UNIX environments for navigation and basic troubleshooting.
  • Ability to communicate findings clearly and work cross-functionally to support remediation.

Must have's:
  • Bachelor's degree in an IT-related field.
  • 6+ years of Information Technology experience.
  • 3+ years of experience supporting SAST, DAST and IDE plug-in environments using Burp Suite, including 3+ years of hands-on Burp Suite experience.
  • 1+ year of experience supporting SAST, DAST and IDE plug-in environments using Veracode.
  • 3+ years of experience using the design and implementation of enterprise-wide security controls to secure applications, systems, networks or infrastructure services.
  • 2+ years of experience with Java, Python, .NET or C#.
  • 2+ years of experience working in Linux-based environments, including navigating and troubleshooting basic website connectivity issues.
  • Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
  • Experience with Eclipse, JDeveloper and/or Visual Studio, including pipeline development experience.
  • Experience securing enterprise web applications, including familiarity with OWASP Top 10, CVSS, CWE, WASC and SANS-25.
  • Knowledge of federal compliance standards, including NIST 800-53, FIPS and/or FedRAMP.
  • Applicants must be a U.S. citizen in compliance with federal contract requirements.

Beneficial to have:
  • Industry recognized certifications.
  • Experience with Interactive Application Security Testing (IAST) tools and capabilities.
  • Experience with HackerOne.
  • Experience with Selenium.
  • Experience writing bash scripts.
  • Experience with OWASP ZAP or Burp Proxy.

Where it's done:
  • Remote (Herndon, VA).