1

Web Application Security Jobs (NOW HIRING)

Web Application Firewall Engineer

Charlotte, NC · On-site

$46.75 - $62.50/hr

Web Application Firewall Engineer * Location: Charlotte, NC -- Hybrid preferred; local candidates ... The role requires strong troubleshooting, networking, application security, and enterprise security ...

Identify, analyze, and remediate web application vulnerabilities, insecure dependencies, misconfigurations, and security weaknesses. * Support vulnerability management activities throughout the ...

Application Security

Bethesda, MD · On-site

$63 - $84/hr

... web application security issues, such as those outlined in OWASP Top 10 Strong knowledge of application security throughout the software lifecycle Experience developing secure coding practices with ...

Application Security Engineer

Torrance, CA · On-site

$61.25 - $82/hr

Strong knowledge of secure development practices Deep knowledge of common web application vulnerabilities (e.g. XSS, CSRF, clickjacking) and their mitigation strategies Knowledge of system security ...

Showing results 21-40

Web Application Security information

See salary details

$22K

$98.5K

$153K

How much do web application security jobs pay per year?

As of Sep 10, 2026, the average yearly pay for web application security in the United States is $98,514.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,000.00 and $119,500.00 per year, depending on experience, location, and employer.

What is the difference between Web Application Security vs Web Developer?

AspectWeb Application SecurityWeb Developer
Primary FocusProtecting web applications from security threats and vulnerabilitiesDesigning, coding, and maintaining websites and web applications
Required SkillsSecurity protocols, vulnerability assessment, penetration testingProgramming languages, UI/UX design, front-end/back-end development
CertificationsCertified Ethical Hacker, CSSLP, OSCPCertified Web Developer, Microsoft Certified, JavaScript certifications
Work EnvironmentSecurity teams, IT departments, cybersecurity firmsWeb development agencies, tech companies, freelance

Web Application Security and Web Developer roles overlap in the tech industry but focus on different aspects. Web Application Security specialists concentrate on safeguarding applications from threats, while Web Developers build and maintain the applications themselves. Both roles require technical skills, but their core responsibilities differ significantly, making them complementary in the web development lifecycle.

Is web application security in demand?

Web application security professionals are in high demand due to the increasing frequency and sophistication of cyberattacks targeting online platforms. Organizations seek experts skilled in vulnerability assessment, secure coding, and security tools like firewalls and penetration testing to protect their digital assets, making this a growing and stable career field.

What is web application security?

Web application security involves protecting web applications from threats and vulnerabilities that could lead to data breaches or unauthorized access. It includes implementing security measures such as input validation, authentication, and regular testing with tools like vulnerability scanners. Professionals in this field often work to identify and fix security flaws to ensure safe and reliable online services.

What cities are hiring for Web Application Security jobs?

Cities with the most Web Application Security job openings:

What states have the most Web Application Security jobs?

States with the most job openings for Web Application Security jobs include:

Infographic showing various Web Application Security job openings in the United States as of September 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $98,514 per year, or $47.4 per hour.

Web Application Firewall Engineer

Charlotte, NC • On-site

$46.75 - $62.50/hr

Other

Re-posted 11 days ago


Job description

  • Job Title: Web Application Firewall Engineer
  • Location: Charlotte, NC — Hybrid preferred; local candidates only
  • Tax Term (W2, C2C): W2 / C2C
  • Job Type (Permanent/Contract): Contract
  • Duration: Long Term
  • Pay Range: DOE
  • Description:
    We are seeking an experienced Web Application Firewall Engineer to support, monitor, troubleshoot, and engineer enterprise web application firewall and application security technologies. The ideal candidate will have strong hands-on experience with F5 BIG-IP, F5 ASM/AWAF, and Akamai Kona, including experience migrating applications from legacy BIG-IP environments to newer F5 platforms. The role requires strong troubleshooting, networking, application security, and enterprise security engineering capabilities.

    Role and Responsibilities:

  • Operate, monitor, maintain, and troubleshoot enterprise Web Application Firewalls, including F5 and Akamai.
  • Perform expert-level troubleshooting of WAF and application security technologies.
  • Support architecture, engineering, deployment, and migration activities for security technologies.
  • Migrate applications from legacy BIG-IP environments to modern F5 platforms.
  • Perform regular health checks, configuration reviews, and user activity audits.
  • Analyze packet captures, CLI output, application logs, and network traffic to troubleshoot security issues.
  • Work closely with application developers and infrastructure teams to resolve security and connectivity issues.
  • Develop and maintain technical documentation covering security architecture, configurations, operations, and management.
  • Support additional network security technologies such as firewalls and Network Access Control when required.
  • Participate in security projects, incident response, and on-call support.
  • Use scripting and automation to improve operational efficiency.
  • Required Skills:

  • 5+ years of hands-on experience with enterprise Web Application Firewall (WAF) technologies.
  • Strong hands-on experience with F5 BIG-IP.
  • Strong experience with F5 ASM/AWAF.
  • Experience with Akamai Kona / Akamai WAF.
  • Proven experience migrating applications from legacy BIG-IP to F5 environments.
  • Strong understanding of Layer 7/application-layer security and TCP/IP fundamentals.
  • Strong troubleshooting skills with packet captures, CLI commands, network protocols, and application logs.
  • Experience supporting enterprise security infrastructure and security projects.
  • Knowledge of application security and secure coding practices.
  • Python or PowerShell scripting experience is a plus.
  • Strong communication and documentation skills.
  • Ability to work with technical and business teams at different organizational levels.
  • Ability to participate in on-call and flexible support schedules.
  • Qualifications:

  • Bachelor''s degree in Information Systems, Computer Science, Cybersecurity, or a related technical field.
  • 5+ years of relevant WAF/security engineering experience.
  • Local to Charlotte, NC and available for a hybrid work arrangement.
  • Must be available for an in-person client interview.