1

Web Application Security Jobs in Virginia (NOW HIRING)

Demonstrated experience with and strong understanding of web application security best practices and usability principles. * Demonstrated experience with Git version control and collaborative ...

Demonstrated experience with and strong understanding of web application security best practices and usability principles. * Demonstrated experience with Git version control and collaborative ...

Demonstrated experience with and strong understanding of web application security best practices and usability principles. * Demonstrated experience with Git version control and collaborative ...

Sr. Application Security Engineer

Vienna, VA · On-site

$59 - $78.75/hr

Solid understanding of common web application security standards (HTTP, OAuth, OIDC, REST, and more) * Experience working with cloud platforms, specifically AWS and Azure * Willingness to learn new ...

Sr. Application Security Engineer

Vienna, VA · On-site

$59 - $78.75/hr

Solid understanding of common web application security standards (HTTP, OAuth, OIDC, REST, and more) * Experience working with cloud platforms, specifically AWS and Azure * Willingness to learn new ...

Sr Security Engineer

Reston, VA · On-site

$140K - $202K/yr

Primary focus is Application Security-embedding security into the SDLC and CI/CD pipelines, strengthening web/API protections, and enabling proactive detection, while contributing broadly to Security ...

New

Sr Security Engineer

Reston, VA · On-site

$140K - $202K/yr

Primary focus is Application Security-embedding security into the SDLC and CI/CD pipelines, strengthening web/API protections, and enabling proactive detection, while contributing broadly to Security ...

New

Solid understanding of common web application security standards (HTTP, OAuth, OIDC, REST, and more) * Experience working with cloud platforms, specifically AWS and Azure * Willingness to learn new ...

next page

Showing results 1-20

Web Application Security information

What is the difference between Web Application Security vs Web Developer?

AspectWeb Application SecurityWeb Developer
Primary FocusProtecting web applications from security threats and vulnerabilitiesDesigning, coding, and maintaining websites and web applications
Required SkillsSecurity protocols, vulnerability assessment, penetration testingProgramming languages, UI/UX design, front-end/back-end development
CertificationsCertified Ethical Hacker, CSSLP, OSCPCertified Web Developer, Microsoft Certified, JavaScript certifications
Work EnvironmentSecurity teams, IT departments, cybersecurity firmsWeb development agencies, tech companies, freelance

Web Application Security and Web Developer roles overlap in the tech industry but focus on different aspects. Web Application Security specialists concentrate on safeguarding applications from threats, while Web Developers build and maintain the applications themselves. Both roles require technical skills, but their core responsibilities differ significantly, making them complementary in the web development lifecycle.

Is web application security in demand?

Web application security professionals are in high demand due to the increasing frequency and sophistication of cyberattacks targeting online platforms. Organizations seek experts skilled in vulnerability assessment, secure coding, and security tools like firewalls and penetration testing to protect their digital assets, making this a growing and stable career field.

What is web application security?

Web application security involves protecting web applications from threats and vulnerabilities that could lead to data breaches or unauthorized access. It includes implementing security measures such as input validation, authentication, and regular testing with tools like vulnerability scanners. Professionals in this field often work to identify and fix security flaws to ensure safe and reliable online services.
Infographic showing various Web Application Security job openings in Virginia as of September 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution.

Security Engineer (Web Application)

Arlington, VA

gTANGIBLE
Business Consulting Services • 11 - 50 employees

$67.50 - $90.25/hr

Full-time

Re-posted 9 days ago


Job description

gTANGIBLE Corporation (gTC), www.gtangible.com, is a C corporation and a registered Government contractor that provides services and solutions in:

  • National Security Programs
  • Professional, Administrative, and Management Support
  • Mission and Warfighter Support

We are a Service-Disabled Veteran-Owned Small Business (SDVOSB) and the founder has years of successful experience in the Government contracting arena. Our leadership team is an exceptional group of Government contracting professionals. gTANGIBLE is in the process of identifying candidates for the following position.

Requisition Type: Full Time

Position Status: Contingent

Position Title: Security Engineer (Web Application)

Location: Arlington, VA

Security Clearance: Secret

Duties and Responsibilities

The Security Engineer (Web Application) supports this Transportation Security Administration Information Technology (TSA IT) Task Order (TO) by web application testing that require testing both via automated tools and with manual testing techniques. Application testing will require authenticated and non-authenticated testing to ensure full evaluation of the cybersecurity controls for the applications. Off hours testing conducted on a as needed basis. Periodic travel required. Duties include the following:

  • Identifies flaws in business logic, programmatic vulnerabilities and weaknesses, and ensures appropriate and consistent risk levels are assigned to such findings.
  • Identifies policy gaps, deficiencies and recommends updates, additions, and modification to TSA security policy.
  • Conducts security testing of web applications, web services, end points, (and other web-related assets) using both Information Assurance & Cybersecurity Division (IAD)-provided automated testing tools and manual testing techniques.
  • Analyzes and validates test results and removes false positives and submits to stakeholders.
  • Participates with stakeholders regarding findings meetings and responses.
  • Provides Subject Matter Expertise on emerging web and mobile technologies, languages, and frameworks. In addition, also provide and support on external security audits conducted of the TSA.

Knowledge and Qualifications

  • At least ten (10) years of technical IT security experience.
  • At least five (5) years of experience performing web application security testing, software development and/or testing.
  • At least three (3) years of experience performing web application security testing using manual techniques and vulnerability testing tools and/or code review tools for Federal IT systems.
  • Ability to work independently/minimal oversight.
  • Experience with manual web security testing techniques.
  • Strong understanding of NIST SP 800-53 and DISA STIGS.
  • Required Certifications: CISSP, CEH, GWAPT or other relevant certifications.
  • Experience with WebInspect, AppScan, BurpSuite, SmartBear SoapUI, Nessus Professional, HP Fortify, Apple Developers Toolkit, Eclipse, and Wireshark.
  • Strong organizational, analytical, and technical writing skills to be able to document findings in reports.

gTANGIBLE Corporation is an equal opportunity employer and does not discriminate against any employee or applicant because of race, age, sex, color, physical or mental disability, religion, sexual orientation, marital status, national origin, or political affiliation.

Employment Type: Full-Time