1

Web Application Security Engineer Jobs (NOW HIRING)

Application Security Engineer

Washington, DC · On-site

$66.50 - $89/hr

NET, Java EE, and SQL • 1+ years of experience in web or mobile application security preferred ... programming background with: JavaScript, JSP, PHP, ASP.Net strongly preferred • Knowledge of ...

Application Security Engineer

Washington, DC · On-site

$66.50 - $89/hr

NET, Java EE, and SQL 1+ years of experience in web or mobile application security preferred HTTP ... skills Strong programming background with: JavaScript, JSP, PHP, ASP.Net strongly preferred ...

$54.25 - $72.50/hr

Knowledge of web application security mechanisms and controls (e.g., SOP, CORS, CSP ... Passion about programming. * Technical knowledge of network and operating systems security.

Web Application Firewall Engineer

Charlotte, NC · On-site

$46.75 - $62.50/hr

Web Application Firewall Engineer * Location: Charlotte, NC -- Hybrid preferred; local candidates ... The role requires strong troubleshooting, networking, application security, and enterprise security ...

Showing results 21-40

Web Application Security Engineer information

See salary details

$29

$66

$96

How much do web application security engineer jobs pay per hour?

As of Sep 10, 2026, the average hourly pay for web application security engineer in the United States is $66.40, according to ZipRecruiter salary data. Most workers in this role earn between $56.49 and $75.48 per hour, depending on experience, location, and employer.

What is a web application security engineer?

A Web Application Security Engineer is a specialist responsible for protecting web applications from security threats and vulnerabilities. They analyze code, perform security testing, and implement measures to safeguard applications against attacks like SQL injection, cross-site scripting (XSS), and data breaches. Their work involves collaborating with developers to design secure systems, monitoring for security incidents, and staying updated on the latest cybersecurity trends and threats. Ultimately, they help ensure the confidentiality, integrity, and availability of web-based applications.

How does a web application security engineer typically collaborate with development teams to ensure secure coding practices?

Web Application Security Engineers work closely with software developers throughout the software development lifecycle, often participating in design reviews, code audits, and threat modeling sessions. They provide guidance on secure coding standards, identify potential vulnerabilities early, and recommend remediation strategies. Regular communication and knowledge sharing, such as conducting security training or workshops, help foster a security-first mindset across the team. This collaborative approach ensures that security is integrated from the outset rather than added as an afterthought.

What are the key skills and qualifications needed to thrive as a web application security engineer, and why are they important?

To thrive as a Web Application Security Engineer, you need a solid understanding of web technologies, application vulnerabilities (such as OWASP Top 10), and a background in computer science or cybersecurity. Familiarity with security testing tools like Burp Suite, Nessus, and proficiency in secure coding practices or relevant certifications such as CEH or OSCP are typically required. Outstanding problem-solving skills, attention to detail, and effective communication help in identifying, mitigating, and explaining security risks. These skills and qualities are essential to protect applications from cyber threats and ensure the integrity and confidentiality of sensitive data.

What cities are hiring for Web Application Security Engineer jobs?

Cities with the most Web Application Security Engineer job openings:

What states have the most Web Application Security Engineer jobs?

States with the most job openings for Web Application Security Engineer jobs include:

What are popular job titles related to Web Application Security Engineer jobs?

For Web Application Security Engineer jobs, the most frequently searched job titles are:

Infographic showing various Web Application Security Engineer job openings in the United States as of August 2026, with employment types broken down into 77% Full Time, 18% Part Time, and 5% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $138,117 per year, or $66.4 per hour.

Application Security Engineer

Washington, DC • On-site

Eliassen Group
IT Services • 5 - 10K employees

$66.50 - $89/hr

Full-time

Re-posted 4 hours ago


Job description

Company Description
Demonstrate your expertise and challenge your skills in this exciting IT Security Engineering opportunity! We are seeking an experienced IT Security Engineer for a lead role within our Security Team in our Washington DC IT Department. In this role, you will provide IT security support for applications and software systems in all platforms as well as providing security support to all systems in production, staging and development environments. This Security Engineer role will work closely with Washington DC IT departments and ensures the security and protection of organizational information assets including data, applications, systems, databases, networks, and other resources. We offer a competitive salary and comprehensive benefits, making this a great opportunity for an experienced IT Security Engineer, like you, to take their IT career to the next level!
Job Description
1. Security Engineer works on defining security frameworks for existing and new systems.
2. Represents the IT security team for enterprise projects during development phases like architecture/design review, providing IT security consulting and recommendations, to ensure the implementation of a secure application design.
3. Responsible for supporting the implementation and enforcement of secure application design principles
4. Responsible for explaining and demonstrating vulnerabilities to application/system owners, and provide recommendations for mitigation.
5. Responsible for defining and designing security code analysis tools and framework, Performing code and design reviews of all internal and external software products. Work with application developers ensure adoption of security principals and best practices.
6. Provides direction and support in security management and security architecture standards and documentations.
7. Provides fault resolution and escalation advice.
8. Responsible for defining processes to manage and enforce application security.
9. Conducts active penetration tests; discover vulnerabilities in information systems.
10. Participate in IT security compliance and audit efforts (eg PCI DSS )
Qualifications
• College degree (relevant field) or equivalent experience; 3-5 years of work experience.
• 2+ years of experience in web application development in .NET, Java EE, and SQL
• 1+ years of experience in web or mobile application security preferred
• HTTP protocol knowledge required
• Knowledge of authentication mechanisms like SAML, OAuth etc. along with web service security protocols for SOAP such as WS-Security are nice to have
• Knowledge of information security principles, web applications and a level of familiarity with malicious code and common techniques used by hackers
• Experience with application security code review practices / static analysis and methods, such as OWASP Top Ten
• Detailed knowledge and understanding of the Payment Card Industry (PCI) data security standards (PCI DSS) as well as experience in the implementation of controls to mitigate PCI issues
• Experience with Application Security Firewalls, F5' ASM / Citrix's Teros etc are desirable
• Experience in creating, maintaining, and executing Incident Response Plans
• Strong interpersonal and communications skills along with strong customer service skills
• Strong programming background with: JavaScript, JSP, PHP, ASP.Net strongly preferred
• Knowledge of Security Flaws and its Resolution as listed in sites like OWASP, SANS etc.
• Knowledge and understanding of network and web related protocols (e.g., TCP/IP, UDP, IPSEC, DNS, LTM, GTM) preferred
• Experience in technical security countermeasures, risk management, contingency planning, and data communications networking preferred
Additional Information
All your information will be kept confidential according to EEO guidelines.
http://www.eliassen.com/consulting-services-consultant/agile-consulting-services

Eliassen Group logo

About Eliassen Group

Sourced by ZipRecruiter

Eliassen Group provides strategic consulting and talent solutions to drive our clients' innovation and business results. Our purpose is to positively impact the lives of our employees, clients, consultants, and the communities in which we operate. Leveraging over 30 years of success, our expertise in talent solutions, life sciences consulting, Agile consulting, cloud services, risk management, business optimization, and managed services enables us to partner with our clients to execute their business strategy and scale effectively. Headquartered in Reading, MA, and with offices from coast to coast, Eliassen Group offers local community presence and deep networks, as well as national reach.

Industry

It services

Company size

5,001 - 10,000 Employees

Headquarters location

Reading, MA, US

Year founded

1989