1

Web Application Security Jobs (NOW HIRING)

... web application security considerations • Experience with source/version control systems (GIT) • Excellent verbal/written communication skills and strong time management and analytical/problem ...

The Research Architect for Dynamic Application Security Testing (DAST) is responsible for ... Responsibilities • Conduct research and development for automating web application attacks. • ...

Responsibilities · Conduct research and development for automating web application attacks. · ... with the security research community through speaking at industry conferences, publishing ...

Application Security Engineer

Washington, DC · On-site

$66.50 - $89/hr

NET, Java EE, and SQL • 1+ years of experience in web or mobile application security preferred • HTTP protocol knowledge required • Knowledge of authentication mechanisms like SAML, OAuth etc ...

NY · On-site

$54.25 - $72.50/hr

Knowledge of web application security mechanisms and controls (e.g., SOP, CORS, CSP). * Comprehensive understanding of common web vulnerabilities (e.g., OWASP Top 10) and their practical mitigation ...

Joint Base Andrews, MD (On-site) Duration: Long Term Contract Active Secret Security Clearance issued by the U.S. Department of Defense. Position Summary: The Web Application Developer will support ...

Web Applications, Mobile Applications, Databases, APIs, Containers and other domains. * Support and maintain application security testing platforms and develop integrations with automation platforms

Showing results 41-60

Web Application Security information

See salary details

$22K

$98.5K

$153K

How much do web application security jobs pay per year?

As of Sep 10, 2026, the average yearly pay for web application security in the United States is $98,514.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,000.00 and $119,500.00 per year, depending on experience, location, and employer.

What is the difference between Web Application Security vs Web Developer?

AspectWeb Application SecurityWeb Developer
Primary FocusProtecting web applications from security threats and vulnerabilitiesDesigning, coding, and maintaining websites and web applications
Required SkillsSecurity protocols, vulnerability assessment, penetration testingProgramming languages, UI/UX design, front-end/back-end development
CertificationsCertified Ethical Hacker, CSSLP, OSCPCertified Web Developer, Microsoft Certified, JavaScript certifications
Work EnvironmentSecurity teams, IT departments, cybersecurity firmsWeb development agencies, tech companies, freelance

Web Application Security and Web Developer roles overlap in the tech industry but focus on different aspects. Web Application Security specialists concentrate on safeguarding applications from threats, while Web Developers build and maintain the applications themselves. Both roles require technical skills, but their core responsibilities differ significantly, making them complementary in the web development lifecycle.

Is web application security in demand?

Web application security professionals are in high demand due to the increasing frequency and sophistication of cyberattacks targeting online platforms. Organizations seek experts skilled in vulnerability assessment, secure coding, and security tools like firewalls and penetration testing to protect their digital assets, making this a growing and stable career field.

What is web application security?

Web application security involves protecting web applications from threats and vulnerabilities that could lead to data breaches or unauthorized access. It includes implementing security measures such as input validation, authentication, and regular testing with tools like vulnerability scanners. Professionals in this field often work to identify and fix security flaws to ensure safe and reliable online services.

What cities are hiring for Web Application Security jobs?

Cities with the most Web Application Security job openings:

What states have the most Web Application Security jobs?

States with the most job openings for Web Application Security jobs include:

Infographic showing various Web Application Security job openings in the United States as of September 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $98,514 per year, or $47.4 per hour.

Web Application and DDoS Security Admin (Imperva CWAF SME)

Cedar Rapids, IA • On-site

Apex Systems
IT Services • 1 - 5K employees

$75 - $80/hr

Other

Medical, Dental, Vision, Life, Retirement

Posted 9 days ago


Job description

Job#: 3049236
Job Description:
Web Application & DDoS Security Administrator (Imperva CWAF SME)
Location: 100% Remote (U.S.)
Rate: $75-80 an hour
Position Overview
Seeking an experienced Web Application & DDoS Security Administrator with expertise in Imperva Cloud WAF (CWAF). This role is responsible for administering, maintaining, and optimizing web application security and DDoS protection solutions supporting public-facing applications, APIs, and web platforms.
Key Responsibilities
  • Administer and maintain Imperva WAF and DDoS protection platforms.
  • Manage advanced security controls, including:
    • Bot Management
    • API Security
    • Client-Side Protection
    • Account Takeover (ATO) Prevention
  • Implement, monitor, and tune WAF policies, rules, and signatures.
  • Execute security-related changes, service requests, and incident response activities.
  • Partner with application, infrastructure, and security teams to design and implement web security controls.
  • Evaluate applications, APIs, networks, and hosting environments and recommend security improvements.
  • Troubleshoot complex application security, network security, and web performance issues.
  • Support ongoing security reviews, vulnerability remediation, and compliance initiatives.

Required Qualifications
  • Hands-on experience with Imperva Cloud WAF (CWAF) and DDoS mitigation technologies.
  • Strong knowledge of:
    • Web application security
    • API security
    • HTTP/S, DNS, TCP/IP, and networking
    • Web hosting and application architectures
  • Experience analyzing and tuning WAF rules and security policies.
  • Strong troubleshooting and problem-solving skills across application and network security domains.
  • Ability to communicate effectively with technical and non-technical stakeholders.

Preferred Qualifications
  • Security certifications (CISSP, Security+, CEH, GIAC, or equivalent).
  • Experience with AWS, Azure, or Google Cloud.
  • Knowledge of DevSecOps and modern web application architectures.

Ideal Candidate: A security-focused professional with deep expertise in web application protection, WAF administration, and DDoS mitigation who can balance security, performance, and business requirements in a fast-paced environment.
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.
Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at or . Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.
UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.