1

Product Security Engineer Jobs in Virginia (NOW HIRING)

... to the production FO FISMA Systems. • Recommend and implement technologies/changes that will ... IAD Security Engineers, as needed. • Develop integrated system test requirement, strategies ...

Nightwing is seeking an experienced Security Product Reverse Engineer (RE) to support advanced security research and development efforts. The ideal candidate will bring deep expertise in reverse ...

Security Engineers are integral to this mission, combining deep technical review expertise with a ... with AWS products and services - Experience performing security activities across one or more ...

Experience with security engineering, computer and network security and security protocols ... You will bridge the boundary between Google Cloud Platform (GCP) and production (network, data ...

Join us as a Database Security Engineer to play your part in that transformation. It's an ... Identifying weak links in information security products and determine how to mitigate the control ...

Partner with engineering and product teams to ensure security and resilience requirements are embedded throughout the full product lifecycle, from design through end‑of‑life. * Ensure product ...

Utilize AI tools to improve research, scripting, documentation, troubleshooting, and engineering productivity. * Recommend and implement improvements to security processes, detections, workflows, and ...

Security Engineer

Springfield, VA · On-site

$150K - $268K/yr

MANTECH seeks a motivated, career and customer-oriented Security Engineer to join our team in ... production environment. Minimum Qualifications: * High School Diploma/GED with 10+ years of ...

Security Engineer

Springfield, VA · On-site

$150K - $268K/yr

MANTECH seeks a motivated, career and customer-oriented Security Engineer to join our team in ... production environment. Minimum Qualifications: * High School Diploma/GED with 10+ years of ...

AppSec Security Engineer

Arlington, VA · On-site

$67.50 - $90.25/hr

In this role, you will embed directly with our Product and Engineering teams to secure both our third-party SaaS applications and our home-grown applications. You will serve as a trusted security ...

Showing results 41-60

Product Security Engineer information

See Virginia salary details

$52.5K

$142.8K

$203.2K

How much do product security engineer jobs pay per year?

As of Aug 9, 2026, the average yearly pay for product security engineer in Virginia is $142,836.00, according to ZipRecruiter salary data. Most workers in this role earn between $87,200.00 and $203,200.00 per year, depending on experience, location, and employer.

What are the typical day-to-day responsibilities of a product security engineer?

As a Product Security Engineer, your daily responsibilities often include assessing software designs for vulnerabilities, conducting code reviews, analyzing security risks, and supporting product teams in implementing secure coding best practices. You may also develop automated security testing solutions, coordinate with developers to resolve discovered issues, and stay updated on the latest security trends impacting your industry. Additionally, you’ll frequently collaborate with cross-functional teams such as developers, DevOps, and quality assurance to drive a culture of security from the earliest stages of product development. Expect a blend of hands-on technical work and consultative guidance that ensures products remain secure at every phase of development.

What is a product security engineer?

A Product Security Engineer is responsible for ensuring the security of a company's software, hardware, or products throughout their development and lifecycle. They identify vulnerabilities, conduct security assessments, and collaborate with development teams to implement best practices. Their role includes threat modeling, code reviews, penetration testing, and incident response. By integrating security into the product development process, they help protect against cyber threats and ensure compliance with industry standards.

What are the key skills and qualifications needed to thrive in the product security engineer position, and why are they important?

To thrive as a Product Security Engineer, you need strong knowledge of application security principles, software development, threat modeling, and vulnerability management, often supported by a degree in computer science or a related field. Familiarity with tools like static/dynamic code analysis tools, penetration testing frameworks, and certifications such as CISSP, CEH, or OSCP is common. Excellent problem-solving abilities, attention to detail, and strong communication skills help navigate complex projects and collaborate across teams. These abilities ensure the security and reliability of products throughout the development lifecycle, protecting both users and organizations from evolving threats.

What are the most commonly searched types of Product Security Engineer jobs in Virginia? The most popular types of Product Security Engineer jobs in Virginia are:
What job categories do people searching Product Security Engineer jobs in Virginia look for? The top searched job categories for Product Security Engineer jobs in Virginia are:
What cities in Virginia are hiring for Product Security Engineer jobs? Cities in Virginia with the most Product Security Engineer job openings:
Infographic showing various Product Security Engineer job openings in Virginia as of August 2026, with employment types broken down into 78% Full Time, 18% Part Time, 3% Contract, and 1% Nights. Highlights an 89% Physical, 3% Hybrid, and 8% Remote job distribution, with an average salary of $142,836 per year, or $68.7 per hour.

Sr. Software Security Engineer

Alphalogic, Inc.

Reston, VA • On-site

Full-time

Re-posted 7 days ago


Job description

Company Description
Alphalogic is a global technology solutions company headquartered in the Washington, DC metropolitan area. Alphalogic offers a wide range of technology and consulting services; predictive analytics, data warehousing & BI, cloud consulting, web & mobile application development.
Cutting-edge Technologies
Our company's core competencies are cloud and mobile computing; healthcare solutions and services; data warehousing-analytics- business intelligence; and enterprise collaboration-content management. Alphalogic teams are continually deploying emerging technologies to meet our clients' current challenges.
Industry Best Practices
Alphalogic specializes in the effective use of industry-standard frameworks such Agile, for helping our clients achieve quick wins and reduce cycle times.
Job Description
The Senior Software Security Engineer will work within the software engineering organization to translate and define security requirements, use and mature practices for building secure applications; and suggest and support remediation activities for identified vulnerabilities. This position requires interest and expertise in defining and executing on a software engineering security practice; strong proven software development skills; expertise with major software infrastructures (J2EE, .NET, Oracle) and architectures (Web, SOA); an ability to build rapport and credibility with management and software development teams; and the ability to document and communicate the results of code reviews and penetration tests. Successful candidates must be action-oriented self-starters, capable of solving complex technical problems both independently and in a team environment. Candidates must also be able to communicate clearly and effectively to both technical and executive level audiences, both verbally and in written form.
  • Defines and mentors software engineering teams on processes that build security in, such as security related programming standards, use of APIs that support secure coding, code review, use of automated scanning tools, and penetration testing.
  • Works with software engineering teams and Enterprise Architecture (EA) to build out formal product security plans that put in place controls to build security in during the software development life cycle.
  • Stays current with emerging software security technologies, trends, and attack vectors, with a primary focus on internal reference architectures and security standards.
  • Performs/participates in architectural reviews that are meant to identify and remedy architectural security flaws.
  • Responsible for the use of security-related code analysis tools and takes the lead on tuning, enhancements, upgrades, and tool integration.
  • Develops threat models in conjunction with architects and software engineering staff.
  • Oversees the development of misuse/abuse cases in conjunction with requirements analysts.
  • Works with the Information Security Office on incident response and operational/strategic initiatives.

Qualifications
Qualifications
Education/Experience
Bachelor's Degree in a related field plus additional related college courses or professional training. Four to seven years of progressively responsible directly-related experience.
Related Skills & Other Requirements:
  • Strong and evolving competence in several programming languages and technologies, mastery of one or more tools sets, technologies, and implementation environments.
  • Advanced knowledge of programming languages, relational database management systems, networking technology, multiple desk operating systems and multiple server operating systems.
  • Must have strong knowledge in one or more of the following: HTML, JavaScript, DOM, AJAX, CSS/CSS2, XML, XHTML, DHTML, etc.
  • Must have adequate knowledge of J2EE and/or .NET technologies.
  • Experience writing automated unit tests.
  • Experience in performing code reviews.
  • Knowledge of TCP/IP, HTTP/S and other protocols.
  • Knowledge of cross-site scripting (XSS), session hijacking, SQL injection, CSRF (Cross-Site Request Forgery), OWASP Top 10, and other attack vectors a plus.
  • Knowledge of OWASP Web Security Certification Criteria, OWASP testing guidelines and PCI Data Security Standards is a plus.
  • Experience with one or more of the following tools is a plus: nmap, Nessus, Metasploit, TCPDump, Burp Suite, ZAProxy.
  • Experience with IBM AppScan Source Edition, IBM AppScan Standard, and/or HP Fortify is a plus.
  • Experience with the following source code repositories is a plus: SVN, GIT, IBM ClearCase
  • Any knowledge of one or more of the following is a plus -- Python, Ruby, PHP or other scripting languages.
  • Reverse engineering experience is a plus.
  • Protocol analysis and forensic analysis experience is a plus.
  • Experience installing, configuring and maintaining continuous integration (CI) environment(s) using tools such as Cruise Control, Cruise Control.NET, Hudson, Jenkins, Bamboo, Gauntlet, in a test driven development (TDD) process is a plus.
  • Experience with one or more of the following static analysis tools is a plus: FindBugs, FxCop, and PMD.
  • Additional certifications such as CISSP, CSSLP, CEH, ENCE, CCE, GCFA, GCIA, GCIH, CHFI and/or QSA are highly desired.

Additional Information
No C2C or Agency candidates. Local candidates are strongly encouraged to apply.