This job has expired

This job posting is no longer active and is not accepting applications. Explore similar roles below!

MicroStrategy
Posted 2w ago

Application Security Engineer

MicroStrategy
Tysons Corner, Virginia, United States
$83k-$150k/yrOnsiteFull Time
Responsibilities
  • integrating security
  • conducting testing
  • reviewing code
Requirements
  • 2+ years software development/security experience
  • Bachelor's in CS or related
  • Hands-on SAST/DAST/SCA experience
  • Familiarity with AI/LLM security
  • Secure coding knowledge
  • Strong communication skills
Technical tools mentioned
CopilotCursorClaudeGitHub Copilot AutofixSemgrepCheckmarxFortifyVeracodeSonarQubeBurp SuiteZAPAWSAzureGCPF

Job description

Company Description:

Strategy (Nasdaq: MSTR) is at the forefront of transforming organizations into intelligent enterprises through data-driven innovation. We don't just follow trends—we set them and drive change. As a market leader in enterprise analytics and AI software, we've pioneered the BI and analytics space, empowering people to make better decisions and revolutionizing how businesses operate. We are now also at the forefront of AI disruption, providing data via our enterprise semantic layer to AI agents, tools, and platforms.

But that's not all. Strategy is also leading a groundbreaking shift in digital assets, adopting bitcoin as our primary treasury reserve asset in 2020. Since then, we have issued innovative bitcoin-backed securities and have been the leader in bitcoin treasury companies. This visionary move has helped us build a fortress balance sheet, and is solidifying our position as a forward-thinking, innovative force in the market.

Our people are the core of our success. At Strategy, you'll join a team of smart, creative minds working on dynamic projects with cutting-edge technologies. We thrive on curiosity, innovation, and a relentless pursuit of excellence.

Our corporate values—bold, agile, engaged, impactful, and united—are the foundation of our culture. As we lead the charge into the new era of AI and financial innovation, we foster an environment where every employee's contributions are recognized and valued.

Join us and be part of an organization that lives and breathes innovation every day. At Strategy, you're not just another employee, you're a crucial part of a mission to push the boundaries of analytics and redefine financial investment.Job Description:

Application Security Engineer

Strategy (Nasdaq: MSTR)  •  Tysons Corner, VA  •  Full-time, 5 days/week on-site

Job Description

Join Strategy's IT Security group as an Application Security Engineer and play a crucial role in safeguarding Strategy's software applications by deploying AI-powered security tooling to protect the software development lifecycle at scale. You will be responsible for integrating security practices throughout the SDLC, ensuring our software products are resilient against vulnerabilities.

Responsibilities

  • AI Security Governance: Evaluate and establish guardrails for the secure use of AI coding assistants (e.g., Copilot, Cursor, Claude) within the engineering organization, including policy development around AI-generated code review, training data exposure risks, and prompt injection vulnerabilities in AI-integrated applications.

  • Secure SDLC Integration: Work closely with development teams to integrate security into the SDLC, including threat modeling, secure code reviews, and security testing.

  • Vulnerability Management: Identify, triage, and remediate security vulnerabilities through static and dynamic application security testing (SAST/DAST) and software composition analysis (SCA) tools.

  • Security Assessments & Penetration Testing: Conduct manual and automated penetration testing of web, mobile, and cloud applications to detect security flaws.

  • Secure Code Review: Analyze source code using both manual review and AI-assisted code analysis tools (e.g., GitHub Copilot Autofix, Semgrep, or similar) to surface vulnerabilities earlier in the development cycle and deliver actionable, in-context remediation guidance to developers.

  • Threat Modeling & Risk Analysis: Perform threat modeling to anticipate potential attack vectors and improve security architecture.

  • DevSecOps Enablement: Support and enhance DevSecOps initiatives by integrating AI-assisted security automation within CI/CD pipelines, including AI-powered SAST/DAST tools and LLM-based code scanning to accelerate vulnerability detection at the point of commit.

  • Incident Response & Remediation: Assist in investigating security incidents related to applications and work with engineering teams to remediate threats.

  • Security Awareness & Training: Educate and mentor developers on OWASP Top 10, SANS 25, and other security best practices.

Qualifications

  • Bachelor's degree in Computer Science, Engineering, or related field

  • Minimum 2 years of software development or software security experience in an agile environment

  • Hands-on experience applying Generative AI and/or ML to security use cases—such as vulnerability triage, threat detection, or secure code review automation—and a strong drive to stay current as AI security tooling evolves.

  • Hands-on experience with SAST, DAST, IAST, and SCA tools (e.g., Checkmarx, Fortify, Veracode, SonarQube, Burp Suite, ZAP)

  • Fluent in one or more programming languages, such as Python, Java, JavaScript

  • Strong knowledge of secure coding principles and application security frameworks

  • Familiarity with security tools (e.g., static and dynamic analysis tools, vulnerability scanners)

  • Understanding of security standards and regulations (e.g., OWASP, NIST)

  • Experience with cloud security best practices in AWS, Azure, or GCP

  • Familiarity with AI/LLM-specific security risks including prompt injection, model poisoning, insecure output handling, and the OWASP Top 10 for LLM Applications.

  • Strong work ethic with a commitment to meeting business needs and effectively collaborating with global colleagues

  • Effective interpersonal skills; ability to collaborate successfully with both technical and non-technical stakeholders

  • Ability to articulate complex technical concepts with clarity, supported by effective written and verbal communication skills

Compensation 

The base salary range for this role is $83,100 to $149,500 and represents a good faith estimate of the range at the time of posting.  Strategy maintains broad salary ranges to account for differences in skills, experience, qualifications, internal peer equity, market conditions, and business needs.  

Candidates are typically placed within the range based on these factors, and it is not common for individuals to be hired at or near the top of the range. The posted range reflects base salary only. Eligible employees may also participate in bonus programs, sales incentives, equity awards, and comprehensive benefits, as applicable.

Additional Information:

Strategy is an equal opportunity employer. All applicants will receive consideration for employment without regard to race, creed, color, religion, national origin, gender, sex, sexual orientation, gender identity, disability, veteran status, age, genetic information, or any other legally-protected basis.



Strategy provides reasonable accommodation for qualified individuals with disabilities in the hiring process.  If you have any difficulty using our online system and you need an accommodation due to a disability, you may contact us about your interest in employment at [email protected].

Visit Strategy’s Careers page for additional information.

About MicroStrategy

Develops enterprise analytics software and manages Bitcoin treasury holdings.

Similar jobs

Application Security Engineer roles near Tysons Corner, Virginia
1w
Save
Mark Applied
Hide
Application Security Engineer (Full Scope Poly)
Reston, Virginia, United States
OnsiteFull Time
Concept Plus
Concept Plus: Delivers enterprise IT services for federal government agencies.
8+ YOERequires U.S. citizenship, TS/SCI clearance with polygraph, 8+ years in application security or related fields, bachelor's degree, secure SDLC and cloud-native experience, and proficiency with listed security technologies and standards.
Oracle Cloud, Python, JavaScript, SQL, Shell, PL/SQL, SAST, DAST, SCA, Kubernetes, Docker, REST APIs, CI/CD, Oracle Cloud Infrastructure (OCI), NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, Oracle RDBMS, Agile
1w
Save
Mark Applied
Hide
Application Security Engineer
Tysons, Virginia, United States
$115k-$145k/yr HybridFull Time
Veilant
Veilant: Protecting operations, personnel, and data from emerging surveillance threats.
2+ YOERequires 2+ years of Java development, application security testing, source-code review, web security, CI/CD, containers, cloud platforms, and strong technical communication; must be able to obtain security clearance.
Java, Java Spring Boot, Angular, REST APIs, SQL, PostgreSQL, JWT, OAuth, Entra, Keycloak, GitLab CI, Azure DevOps, GitHub Actions, Kubernetes, Trivy, Kubesec, Azure, AWS, GitLab Secrets Manager, AWS KMS, Azure Key Vault, Ansible Vault, SAST, DAST, SCA, Falco, NeuVector, Burp Suite, CI/CD, IaC
2w
Save
Mark Applied
Hide
Application Security Engineer I
Arlington, Virginia, United States
$90k-$110k/yr OnsiteFull Time
Bloomberg Industry Group
Bloomberg Industry Group: Provides legal, tax, and government intelligence and news services.
1+ YOEAssociate's degree in information security, computer science, or a related field, or equivalent experience; 1–2 years of relevant experience; programming knowledge and application security testing exposure.
Python, Java, JavaScript, GitLab, GitHub Actions, Jenkins, AWS, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), CI/CD
2w
Save
Mark Applied
Hide
Senior Engineer, Application Security
Tysons Corner, Virginia, United States
$120k-$160k/yr HybridFull Time
Cvent
Cvent: Cloud-based software for event and venue management.
5+ YOE5+ years in application security or secure software development; strong scripting in Python, JavaScript/TypeScript, or Bash; CI/CD and SDLC security integration; cloud (AWS preferred) and tool familiarity; end-to-end ownership experience.
Python, JavaScript, TypeScript, Bash, AWS, GCP, Azure, AWS CDK, Burp Suite, Checkmarx, Mend, Veracode, Fortify, ZAP, Wiz, CI/CD, SAST, DAST, SCA
3w
Save
Mark Applied
Hide
Application Security Engineer — Secure Mission Systems
United States or Laurel
RemoteFull Time
Rackner
Rackner: Builds cloud-native software and AI systems for government agencies.
6+ YOE6+ years in SAST/DAST and vulnerability remediation, bachelor’s in cybersecurity, experience with application-security testing, secure SDLC, and working with development teams to remediate findings.
Fortify, X-Ray, OWASP ZAP, GitLab, Artifactory, OpenShift, Kubernetes, WebAssembly (WASM)
1mo
Save
Mark Applied
Hide
(USA) Staff, Application Security Engineer
Bentonville or Herndon
$110k-$264k/yr OnsiteFull Time
Walmart
WalmartNYSE: WMT: Multinational retail operating discount stores and supermarkets.
4+ YOEBachelor's degree plus 4 years in application security, or 6 years of application security experience. Preferred security certifications and project leadership experience.
AI, CI/CD, IDE, CLI, PR bots, WCAG 2.2 AA
1mo
Save
Mark Applied
Hide
(USA) Staff, Application Security Engineer
Bentonville or Herndon
$110k-$220k/yr OnsiteFull Time
Walmart
WalmartNYSE: WMT: Operates a chain of hypermarkets, discount stores, and grocery stores.
4+ YOEBachelor's degree plus 4 years in application security, or 6 years' application security experience. Preferred security certifications, master's degree, and cybersecurity project leadership experience.
Machine Learning, Artificial Intelligence, IDE, CLI, PR bots, SDLC, CI/CD, WCAG 2.2 AA
1mo
Save
Mark Applied
Hide
Application Security Engineer
Fort Meade, Maryland, United States
$87k-$198k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
4+ YOERequires 4+ years supporting DoD enterprise architecture, 4+ years designing/administrating F5 BIG-IP, experience with inline break-and-inspect proxies, TLS/mTLS configuration, knowledge of PKI/cryptography, Secret clearance, HS diploma or GED.
F5 BIG-IP, Office 365, Teams, RDP, SSH, CLI, Linux, UNIX, NIST 800-53, FIPS, DoD STIG, FedRAMP
This job has expired