1

Web Application Security Engineer Jobs in Spring, TX

ECOM is a company looking for an experienced full-stack web application developer capable of ... security • Knowledge of the back-end setup for databases, API end-points, and application hosting ...

Embed security controls at the application level, including authentication, authorization, input ... Collaborate with DevOps teams to seamlessly integrate security automation tools within CI/CD ...

ECOM is seeking an experienced full-stack web application developer to develop cloud-based ... security • Knowledge of the back-end setup for databases, API end-points, and application hosting ...

... application security, network security, security operations, systems engineering, or network ... engineering * Experience using industry‑standard SIEMs * Experience with security operations ...

CloudFlare WAF Support Engineer Type : 6-month contract Location : Houston Downtown- Need to be ... Exposure to web application security and WAF policy management * Ability to support an existing ...

This role requires strong offensive security skills combined with cloud and application ... Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web ...

This role requires strong offensive security skills combined with cloud and application ... Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web ...

Showing results 21-40

Web Application Security Engineer information

See Spring, TX salary details

$26

$59

$85

How much do web application security engineer jobs pay per hour?

As of Sep 10, 2026, the average hourly pay for web application security engineer in Spring, TX is $59.09, according to ZipRecruiter salary data. Most workers in this role earn between $50.29 and $67.16 per hour, depending on experience, location, and employer.

What is a web application security engineer?

A Web Application Security Engineer is a specialist responsible for protecting web applications from security threats and vulnerabilities. They analyze code, perform security testing, and implement measures to safeguard applications against attacks like SQL injection, cross-site scripting (XSS), and data breaches. Their work involves collaborating with developers to design secure systems, monitoring for security incidents, and staying updated on the latest cybersecurity trends and threats. Ultimately, they help ensure the confidentiality, integrity, and availability of web-based applications.

How does a web application security engineer typically collaborate with development teams to ensure secure coding practices?

Web Application Security Engineers work closely with software developers throughout the software development lifecycle, often participating in design reviews, code audits, and threat modeling sessions. They provide guidance on secure coding standards, identify potential vulnerabilities early, and recommend remediation strategies. Regular communication and knowledge sharing, such as conducting security training or workshops, help foster a security-first mindset across the team. This collaborative approach ensures that security is integrated from the outset rather than added as an afterthought.

What are the key skills and qualifications needed to thrive as a web application security engineer, and why are they important?

To thrive as a Web Application Security Engineer, you need a solid understanding of web technologies, application vulnerabilities (such as OWASP Top 10), and a background in computer science or cybersecurity. Familiarity with security testing tools like Burp Suite, Nessus, and proficiency in secure coding practices or relevant certifications such as CEH or OSCP are typically required. Outstanding problem-solving skills, attention to detail, and effective communication help in identifying, mitigating, and explaining security risks. These skills and qualities are essential to protect applications from cyber threats and ensure the integrity and confidentiality of sensitive data.

What cities near Spring, TX are hiring for Web Application Security Engineer jobs?

Cities near Spring, TX with the most Web Application Security Engineer job openings:

Infographic showing various Web Application Security Engineer job openings in Spring, TX as of August 2026, with employment types broken down into 77% Full Time, 19% Part Time, and 4% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $122,909 per year, or $59.1 per hour.

Cyber - AWS Forward Deployed Security Engineer (FDE) - Senior Consultant

Houston, TX • On-site

Deloitte
Finance and Insurance • 10K+ employees

$109K - $149K/yr

Full-time

Posted 24 days ago


Key responsibilities

  • Embed directly with client cloud and platform engineering teams to design, build, deploy, and operate automated security controls across AWS environments.

  • Design and implement security guardrails for AWS generative AI and machine learning services, containerized, and serverless workloads.

  • Build automated data protection and data loss prevention capabilities using AWS security services and encryption patterns.


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 93 frontline employees who took The Breakroom Quiz


Job description

Join Deloitte's Cloud Cyber Risk practice as a Forward Deployed Security Engineer and help organizations secure their Amazon Web Services (AWS) cloud and AI workloads at scale while working directly with client engineering teams. This is not an assessment-and-handoff role. You will design, build, deploy, and operate secure-by-default AWS environments and automated security controls across generative AI services, container and data platforms, infrastructure-as-code, and secure delivery pipelines. This role is designed for a hands-on engineer who enjoys solving complex cloud security challenges, building working automation, and supporting security outcomes in production environments.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As an Engineering and Product Engineer III on the Cloud Cyber Risk team, you will be responsible for:

  • Embed directly with client cloud and platform engineering teams to design, build, deploy, and operate automated security controls across AWS environments from initial design through production support.
  • Design and implement security guardrails for AWS generative artificial intelligence (AI) and machine learning services, including Amazon Bedrock, Amazon Bedrock AgentCore, and Amazon SageMaker, as well as containerized and serverless workloads on Amazon Elastic Kubernetes Service (EKS).
  • Build automated data protection and data loss prevention capabilities using Amazon Macie, AWS Key Management Service (KMS), and encryption and tokenization patterns across Amazon Simple Storage Service (S3), databases, and analytics platforms.
  • Deploy and maintain AWS-native security services, including AWS Security Hub, Amazon GuardDuty, AWS Config, AWS Identity and Access Management (IAM) Access Analyzer, and AWS CloudTrail, within client monitoring and security operations workflows.
  • Write and maintain production infrastructure-as-code using Terraform and/or AWS CloudFormation, integrate security scanning into continuous integration / continuous deployment (CI/CD) pipelines, and contribute reusable modules, runbooks, and reference implementations for future engagements.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

The team

Deloitte's Cloud Cyber Risk team helps organizations pursue growth, innovation, and performance through proactive management of cyber risk. Our Forward Deployed Security Engineers work directly within client teams, combining risk, regulatory, and technology capabilities with hands-on engineering to design, build, and operate scalable, automated AWS cloud security solutions. This team works closely with clients to implement controls in production environments and support security outcomes at scale.

Qualifications

Required:

  • 5+ years of experience in cloud security, cybersecurity, technology risk, or technology consulting; and a bachelor's degree in computer science, cybersecurity, information technology, engineering, or a technical field
  • 3+ years of hands-on experience designing, building, or operating security solutions in Amazon Web Services (AWS) production environments, including AWS Security Hub, Amazon GuardDuty, AWS Config, AWS Identity and Access Management (IAM), AWS Key Management Service (KMS), and AWS CloudTrail
  • 2+ years of experience using Terraform and/or AWS CloudFormation to deploy infrastructure and security controls through production deployment pipelines
  • Experience securing at least one of the following in a production environment: Amazon Elastic Kubernetes Service (EKS) / containers, Amazon SageMaker or Amazon Bedrock workloads, or data protection using Amazon Macie
  • Experience integrating security controls into continuous integration / continuous deployment (CI/CD) pipelines, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and infrastructure-as-code (IaC) scanning; experience scripting in Python, Bash, or Go to automate enforcement or remediation; and experience working directly with client or customer engineering teams in onsite or virtual delivery environments
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Experience securing generative AI and agentic workloads on Amazon Bedrock, Amazon Bedrock AgentCore, or Amazon SageMaker in production environments
  • Experience using policy-as-code and guardrail tools, including AWS Service Control Policies, Open Policy Agent, Checkov, or tfsec
  • Experience with AWS Control Tower, secure landing zones, and multi-account governance
  • Experience with Kubernetes security tooling and runtime protection
  • Experience implementing security controls aligned to International Organization for Standardization (ISO) 27001, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), National Institute of Standards and Technology Special Publication 800-53 (NIST SP 800-53), Payment Card Industry Data Security Standard (PCI DSS), or System and Organization Controls 2 (SOC 2)
  • Prior experience in a forward-deployed, startup, or professional services delivery model; AWS Certified Security - Specialty, AWS Certified Solutions Architect, or Certified Cloud Security Professional (CCSP)

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Qualifications:

Join Deloitte's Cloud Cyber Risk practice as a Forward Deployed Security Engineer and help organizations secure their Amazon Web Services (AWS) cloud and AI workloads at scale while working directly with client engineering teams. This is not an assessment-and-handoff role. You will design, build, deploy, and operate secure-by-default AWS environments and automated security controls across generative AI services, container and data platforms, infrastructure-as-code, and secure delivery pipelines. This role is designed for a hands-on engineer who enjoys solving complex cloud security challenges, building working automation, and supporting security outcomes in production environments.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As an Engineering and Product Engineer III on the Cloud Cyber Risk team, you will be responsible for:

  • Embed directly with client cloud and platform engineering teams to design, build, deploy, and operate automated security controls across AWS environments from initial design through production support.
  • Design and implement security guardrails for AWS generative artificial intelligence (AI) and machine learning services, including Amazon Bedrock, Amazon Bedrock AgentCore, and Amazon SageMaker, as well as containerized and serverless workloads on Amazon Elastic Kubernetes Service (EKS).
  • Build automated data protection and data loss prevention capabilities using Amazon Macie, AWS Key Management Service (KMS), and encryption and tokenization patterns across Amazon Simple Storage Service (S3), databases, and analytics platforms.
  • Deploy and maintain AWS-native security services, including AWS Security Hub, Amazon GuardDuty, AWS Config, AWS Identity and Access Management (IAM) Access Analyzer, and AWS CloudTrail, within client monitoring and security operations workflows.
  • Write and maintain production infrastructure-as-code using Terraform and/or AWS CloudFormation, integrate security scanning into continuous integration / continuous deployment (CI/CD) pipelines, and contribute reusable modules, runbooks, and reference implementations for future engagements.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

The team

Deloitte's Cloud Cyber Risk team helps organizations pursue growth, innovation, and performance through proactive management of cyber risk. Our Forward Deployed Security Engineers work directly within client teams, combining risk, regulatory, and technology capabilities with hands-on engineering to design, build, and operate scalable, automated AWS cloud security solutions. This team works closely with clients to implement controls in production environments and support security outcomes at scale.

Qualifications

Required:

  • 5+ years of experience in cloud security, cybersecurity, technology risk, or technology consulting; and a bachelor's degree in computer science, cybersecurity, information technology, engineering, or a technical field
  • 3+ years of hands-on experience designing, building, or operating security solutions in Amazon Web Services (AWS) production environments, including AWS Security Hub, Amazon GuardDuty, AWS Config, AWS Identity and Access Management (IAM), AWS Key Management Service (KMS), and AWS CloudTrail
  • 2+ years of experience using Terraform and/or AWS CloudFormation to deploy infrastructure and security controls through production deployment pipelines
  • Experience securing at least one of the following in a production environment: Amazon Elastic Kubernetes Service (EKS) / containers, Amazon SageMaker or Amazon Bedrock workloads, or data protection using Amazon Macie
  • Experience integrating security controls into continuous integration / continuous deployment (CI/CD) pipelines, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and infrastructure-as-code (IaC) scanning; experience scripting in Python, Bash, or Go to automate enforcement or remediation; and experience working directly with client or customer engineering teams in onsite or virtual delivery environments
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Experience securing generative AI and agentic workloads on Amazon Bedrock, Amazon Bedrock AgentCore, or Amazon SageMaker in production environments
  • Experience using policy-as-code and guardrail tools, including AWS Service Control Policies, Open Policy Agent, Checkov, or tfsec
  • Experience with AWS Control Tower, secure landing zones, and multi-account governance
  • Experience with Kubernetes security tooling and runtime protection
  • Experience implementing security controls aligned to International Organization for Standardization (ISO) 27001, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), National Institute of Standards and Technology Special Publication 800-53 (NIST SP 800-53), Payment Card Industry Data Security Standard (PCI DSS), or System and Organization Controls 2 (SOC 2)
  • Prior experience in a forward-deployed, startup, or professional services delivery model; AWS Certified Security - Specialty, AWS Certified Solutions Architect, or Certified Cloud Security Professional (CCSP)

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom