1

Senior Application Security Engineer Jobs in Virginia

Sr. Application Security Engineer

Vienna, VA · On-site

$59 - $78.75/hr

As an Application Security Engineer at Esri, you will fill a critical role in helping secure Esri's intellectual property and sensitive data against a variety of complex threats with support from all ...

As an Application Security Engineer at Esri, you will fill a critical role in helping secure Esri's intellectual property and sensitive data against a variety of complex threats with support from all ...

APPLICATION SECURITY ENGINEER

Fairfax, VA · On-site

$60 - $80.25/hr

Application Security Engineer Location: Onsite in Fairfax, VA 3 days and in Washington, DC 2 days ... Will be responsible for senior-level leadership in information security, secure SDLC integration ...

Application Security Engineer

Ashburn, VA · On-site

$107K - $195K/yr

Primary Responsibilities Leidos is looking for an Application Security Engineer to support: Application Security Operations and Maintenance, Application Security Configuration Management and ...

Application Security Engineer

Ashburn, VA · On-site

$107K - $195K/yr

Primary Responsibilities Leidos is looking for an Application Security Engineer to support: Application Security Operations and Maintenance, Application Security Configuration Management and ...

Master's with 1-2 years of prior experience in application security with a focus on SAST, SCA, DAST * Experience with data engineering tools such as Kubernetes/Rancher, Cloudera * Experience with ...

next page

Showing results 1-20

Senior Application Security Engineer information

See Virginia salary details

$72.9K

$136K

$184.9K

How much do senior application security engineer jobs pay per year?

As of Sep 6, 2026, the average yearly pay for senior application security engineer in Virginia is $135,955.00, according to ZipRecruiter salary data. Most workers in this role earn between $113,500.00 and $155,700.00 per year, depending on experience, location, and employer.

What is a senior application security engineer?

A Senior Application Security Engineer is responsible for ensuring the security of software applications by identifying vulnerabilities, implementing security best practices, and working with development teams to integrate secure coding principles. They conduct security assessments, perform threat modeling, and use security tools to detect and remediate risks. Additionally, they help establish security policies, oversee compliance with industry standards, and provide guidance to developers and stakeholders on security-related matters. Their goal is to protect applications from cyber threats while enabling business continuity and innovation.

What are the key skills and qualifications needed to thrive as a senior application security engineer?

To thrive as a Senior Application Security Engineer, you need a solid understanding of secure software development, threat modeling, vulnerability assessment, and a degree in computer science or a related field. Familiarity with tools like static and dynamic application security testing (SAST/DAST), code review platforms, and certifications such as CISSP or OSCP are often required. Strong analytical thinking, attention to detail, effective communication, and the ability to collaborate are standout soft skills for this role. These capabilities help ensure robust protection of applications, support safe software delivery, and enable effective teamwork across engineering and security teams.

What are the typical responsibilities of a senior application security engineer on a day-to-day basis?

A Senior Application Security Engineer typically spends their days reviewing application code for security vulnerabilities, performing threat modeling, and collaborating closely with development teams to ensure secure coding practices are followed. They may also lead security assessments, coordinate penetration tests, and work on developing or enforcing security policies within the organization. Regular interaction with cross-functional teams, such as DevOps and IT, is common to address security issues throughout the software development lifecycle. This role also often involves mentoring junior engineers and staying up to date with the latest security threats and technologies.

What are the most commonly searched types of Application Security Engineer jobs in Virginia?

The most popular types of Application Security Engineer jobs in Virginia are:

What are popular job titles related to Senior Application Security Engineer jobs in Virginia?

For Senior Application Security Engineer jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Senior Application Security Engineer jobs in Virginia look for?

The top searched job categories for Senior Application Security Engineer jobs in Virginia are:

What cities in Virginia are hiring for Senior Application Security Engineer jobs?

Cities in Virginia with the most Senior Application Security Engineer job openings:

Infographic showing various Senior Application Security Engineer job openings in Virginia as of August 2026, with employment types broken down into 71% Full Time, 25% Part Time, and 4% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $135,955 per year, or $65.4 per hour.

Sr. Application Security Engineer

Esri

Vienna, VA • On-site

$59 - $78.75/hr

Full-time

Posted 4 days ago


Esri rating

9.6

Company rating: 9.6 out of 10

Based on 14 frontline employees who took The Breakroom Quiz

6th of 247 rated software companies


Job description

Overview

As someone experienced with securing a wide variety of applications, you are looking for an opportunity to use your skills in an innovative and technology-oriented environment. As an Application Security Engineer at Esri, you will fill a critical role in helping secure Esri's intellectual property and sensitive data against a variety of complex threats with support from all levels of leadership. Our Application Security team collaborates closely with the application development, DevSecOps, and information security departments to design security into our applications up front, perform application layer security testing, and assist developers with vulnerability remediation. We value collaboration, pragmatic security, and continuous improvement. We welcome you to join Esri, where you can make a real difference every day! 

Responsibilities

  • Design, operate, and continuously improve application security testing capabilities and pipelines 
  • Assess application risks and recommend mitigations 
  • Perform application layer security reviews of the code developed by our application teams, across multiple languages and frameworks used internally 
  • Assist with application layer penetration testing to identify potential issues 
  • Provide application security guidance and mentorship to development teams as needed 

Requirements

  • 5+ years of experience in application security, including manual and automated code reviews, manual penetration testing, dynamic application security testing, and false positive analysis of code, pen test, and open-source security findings 
  • Demonstrated experience determining risk based on analysis/findings using a consistent risk management framework 
  • Proven ability to develop automations/applications using Python, Typescript, Java, or PowerShell 
  • Experience creating and maintaining reusable GitHub Actions workflows, with expertise in all aspects of GitHub workflow management 
  • Hands-on experience working in a DevSecOps environment built on Kubernetes with a strong knowledge of Kubernetes security best practices 
  • Ability to read and analyze code for security and design vulnerabilities 
  • Solid understanding of common web application security standards (HTTP, OAuth, OIDC, REST, and more) 
  • Experience working with cloud platforms, specifically AWS and Azure 
  • Willingness to learn new skills and enhance workflows using various AI tools 
  • US citizenship and willingness and ability to maintain a US Security Clearance
  • Bachelor's degree in computer science or related field

Recommended Qualifications

  • Proficiency in any of the following languages: C#, Python, Bash/Shell, PowerShell, JavaScript, SQL, Java 
  • Familiarity with AI-assisted coding practices, including tools such as GitHub Copilot, and an understanding of the security implications and risks introduced by AI-generated code 
  • Practical experience interpreting findings from application pen testing, code scanning and open-source scanners to determine the risk and collaborate with developers to resolve them 
  • Understanding of layer 2-7 communication protocols, common encoding and encryption schemes, and algorithms 

#LI-TM1

#LI-onsite


What Esri employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


ESRI logo

About ESRI

Sourced by ZipRecruiter

Our passion for improving quality of life through geography is at the heart of everything we do. Esri's geographic information system (GIS) technology inspires and enables governments, universities, and businesses worldwide to save money, lives, and our environment through a deeper understanding of the changing world around them.

Industry

Scientific research and development services

Company size

1,001 - 5,000 Employees

Headquarters location

Redlands, CA, US

Year founded

1969