1

Senior Application Security Engineer Jobs in Virginia

APPLICATION SECURITY ENGINEER

Fairfax, VA ยท On-site

$60 - $80.25/hr

Application Security Engineer Location: Onsite in Fairfax, VA 3 days and in Washington, DC 2 days ... Will be responsible for senior-level leadership in information security, secure SDLC integration ...

Application Security Engineer

Herndon, VA ยท Hybrid

$60.25 - $80.75/hr

Minimum of 5 years experience working "hands-on" in application security engineering * Hands-on experience with Fortify, Veracode, Tenable, Black Duck, or similar platforms * Hands-on experience with ...

Primary Responsibilities Leidos is looking for an Application Security Engineer to support: Application Security Operations and Maintenance, Application Security Configuration Management and ...

Application Security Engineer

Ashburn, VA ยท On-site

$107K - $195K/yr

Primary Responsibilities Leidos is looking for an Application Security Engineer to support: Application Security Operations and Maintenance, Application Security Configuration Management and ...

Senior Security Engineer, Application Position location: Richmond, Va., Lynchburg, Va. This position is available to Virginia residents as Richmond or Lynchburg, Virginia in-office applicants *A ...

next page

Showing results 1-20

Senior Application Security Engineer information

See Virginia salary details

$72.9K

$136K

$184.9K

How much do senior application security engineer jobs pay per year?

As of Aug 9, 2026, the average yearly pay for senior application security engineer in Virginia is $135,955.00, according to ZipRecruiter salary data. Most workers in this role earn between $113,500.00 and $155,700.00 per year, depending on experience, location, and employer.

What is a senior application security engineer?

A Senior Application Security Engineer is responsible for ensuring the security of software applications by identifying vulnerabilities, implementing security best practices, and working with development teams to integrate secure coding principles. They conduct security assessments, perform threat modeling, and use security tools to detect and remediate risks. Additionally, they help establish security policies, oversee compliance with industry standards, and provide guidance to developers and stakeholders on security-related matters. Their goal is to protect applications from cyber threats while enabling business continuity and innovation.

What are the key skills and qualifications needed to thrive as a senior application security engineer?

To thrive as a Senior Application Security Engineer, you need a solid understanding of secure software development, threat modeling, vulnerability assessment, and a degree in computer science or a related field. Familiarity with tools like static and dynamic application security testing (SAST/DAST), code review platforms, and certifications such as CISSP or OSCP are often required. Strong analytical thinking, attention to detail, effective communication, and the ability to collaborate are standout soft skills for this role. These capabilities help ensure robust protection of applications, support safe software delivery, and enable effective teamwork across engineering and security teams.

What are the typical responsibilities of a senior application security engineer on a day-to-day basis?

A Senior Application Security Engineer typically spends their days reviewing application code for security vulnerabilities, performing threat modeling, and collaborating closely with development teams to ensure secure coding practices are followed. They may also lead security assessments, coordinate penetration tests, and work on developing or enforcing security policies within the organization. Regular interaction with cross-functional teams, such as DevOps and IT, is common to address security issues throughout the software development lifecycle. This role also often involves mentoring junior engineers and staying up to date with the latest security threats and technologies.

What are the most commonly searched types of Application Security Engineer jobs in Virginia? The most popular types of Application Security Engineer jobs in Virginia are:
What are popular job titles related to Senior Application Security Engineer jobs in Virginia? For Senior Application Security Engineer jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Senior Application Security Engineer jobs in Virginia look for? The top searched job categories for Senior Application Security Engineer jobs in Virginia are:
What cities in Virginia are hiring for Senior Application Security Engineer jobs? Cities in Virginia with the most Senior Application Security Engineer job openings:
Infographic showing various Senior Application Security Engineer job openings in Virginia as of August 2026, with employment types broken down into 76% Full Time, 18% Part Time, and 6% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $135,955 per year, or $65.4 per hour.

HYBRID::Application Security Engineer at Rockville, MD or McLean, VA

FutureTech Consultants LLC

Mclean, VA โ€ข On-site

$60.25 - $80.50/hr

Other

Posted 3 days ago

New


Job description

Hello,

Greetings.!

This is Hima from Appridat Solutions LLC. I was reviewing your resume online and would like to talk to you regarding an exciting opportunity for Application Security Engineer at Rockville, MD or McLean, VA. We have with one of Appridat Solutions LLC premier clients.

Title: Application Security Engineer

Location: Rockville, MD or McLean, VA (Hybrid 3 days onsite with 2 days remote)

Duration: 6 Months with possible extension

Interview process: Prescreen, Phone, Onsite panel

Job Summary:

The Senior Application Security Engineer is responsible for designing, implementing, and advancing application security practices across the Software Development Life Cycle (SDLC). This role partners closely with engineering, DevOps, and security teams to identify vulnerabilities, support remediation efforts, evaluate security tooling, and strengthen secure development practices.

The ideal candidate brings strong hands-on application security expertise, experience integrating security into CI/CD pipelines, and the ability to leverage modern automation and GenAI technologies to scale secure code review and vulnerability analysis capabilities.

Key Responsibilities

Perform application security assessments, manual penetration testing, and vulnerability validation using tools such as Burp Suite and other proxy/security testing tools.

Analyze and triage findings from SAST, DAST, IAST, IaC, and secrets detection tools to identify, prioritize, and support remediation of security vulnerabilities.

Partner with engineering teams to integrate security controls and testing into CI/CD pipelines in support of DevSecOps initiatives.

Conduct secure code reviews and leverage GenAI-enabled security tooling to improve scalability and efficiency of application security analysis.

Evaluate, recommend, and implement application security tools and technologies, including emerging capabilities related to automated code analysis and cloud security.

Perform AWS configuration and cloud security reviews to ensure adherence to security best practices and compliance standards.

Develop and maintain documentation related to security findings, remediation activities, risk assessments, and compliance requirements.

Contribute to the development, interpretation, and enforcement of application security policies, standards, and procedures.

Support enterprise security compliance initiatives and participate in audit and risk management activities.

Deliver security awareness training and educate developers and QA engineers on common application security risks, secure coding practices, and remediation techniques.

Stay current on emerging threats, vulnerabilities, attack techniques, and security technologies to continuously improve the organization's security posture.

Required Qualifications

Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical field.

5+ years of experience in cybersecurity with a strong focus on application security.

Hands-on experience with SAST, DAST, IAST, and related application security testing methodologies and tools.

Strong understanding of OWASP Top 10 vulnerabilities, secure coding principles, and remediation strategies.

Experience performing manual penetration testing and application vulnerability assessments.

Proficiency in one or more programming or scripting languages such as Java, Python, or JavaScript.

Experience integrating security tooling into CI/CD pipelines using platforms such as Jenkins and GitLab.

Strong knowledge of security engineering concepts including authentication, authorization, cryptography, network security, and secure application architecture.

Experience with AWS cloud security concepts, services, and configuration reviews.

Excellent communication skills with the ability to collaborate effectively across engineering and security teams.

Preferred Qualifications

Background in software engineering or application development.

Familiarity with GenAI-assisted security tooling and automated code analysis solutions.

Experience with Infrastructure as Code (IaC) security scanning and secrets management tools.

Experience conducting infrastructure or application-level vulnerability testing and security auditing.

Industry certifications such as:

GWAPT

OSWE

Burp Suite Certified Practitioner

CISSP

CSSLP

Experience supporting enterprise DevSecOps transformation initiatives.

Technical Environment

Application Security: SAST, DAST, IAST, Secure Code Review

Cloud Platforms: AWS

CI/CD Tools: Jenkins, GitLab

Security Testing Tools: Burp Suite and related proxy/testing tools

Programming Languages: Java, Python, JavaScript

DevSecOps & Automation: Security pipeline integration, GenAI-assisted analysis

Regards,

Hima Bindu

Appridat solutions LLC.

5655 Peachtree Parkway, Suite 212, Peachtree Corners, GA 30092

PHONE:*533 | Fax

Direct:

Email: