190 application security engineer jobs at 104 companies in Alexandria, VA
1d
Save
Mark Applied
Hide
1d
Application Security Engineer
Annapolis Junction, Maryland, United States
$87k-$198k/yrRemoteFull Time
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
5+ YOERequires 5+ years in cybersecurity, application or product security, or software engineering; Secure SDLC, security tools, cloud architectures, frameworks, communication, and a relevant bachelor's degree.
Virtru: Provides data-centric encryption and privacy control software for organizations.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
5+ YOERequires 5+ years in cybersecurity, application security, product security, or software engineering; Secure SDLC, application security tools, cloud-native architectures, risk management, and client leadership experience; bachelor's degree.
Microsoft Internet Explorer, Google Chrome, Mozilla Firefox, Microsoft Edge, Apple Safari, Opera Browser, Blackberry Browser, SAST, DAST, SCA, IaC, API, Agile, Scrum, DevSecOps, Kubernetes, SBOM, OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, MITRE ATT&CK, ATLAS
Veilant: Protecting operations, personnel, and data from emerging surveillance threats.
2+ YOERequires 2+ years of Java development, application security testing, source-code review, web security, CI/CD, containers, cloud platforms, and strong technical communication; must be able to obtain security clearance.
Chicago or California or Colorado or Florida or Georgia or Illinois or Indiana or Minnesota or Missouri or Montana or New Jersey or New York or North Carolina or Ohio or Oregon or Pennsylvania or South Carolina or Texas or Utah or Vermont or Virginia or Washington or Washington or Wisconsin
$210k-$260k/yrHybridFull Time
NinjaTrader: Provides futures brokerage services and a trading software platform.
7+ YOE7+ years in application/product/security engineering; hands-on threat modeling, vulnerability management, secure design, CI/CD integration, automation using Python/Go; experience with cloud-native AWS/GCP environments.
WalmartNYSE: WMT: Multinational retail operating discount stores and supermarkets.
4+ YOEBachelor's degree plus 4 years in application security, or 6 years of application security experience. Preferred security certifications and project leadership experience.
Cvent: Cloud-based software for event and venue management.
5+ YOE5+ years in application security or secure software development; strong scripting in Python, JavaScript/TypeScript, or Bash; CI/CD and SDLC security integration; cloud (AWS preferred) and tool familiarity; end-to-end ownership experience.
ManTech: Provides technology solutions for defense and intelligence agencies.
11+ YOETS/SCI with poly required. 11–15+ years experience in systems security, software engineering, or computer science. Hands-on C/C++ or C#, ability to read Java, experience with software assurance tools and source code analysis.
Application Security Engineer — Secure Mission Systems
United States or Laurel
RemoteFull Time
Rackner: Builds cloud-native software and AI systems for government agencies.
6+ YOE6+ years in SAST/DAST and vulnerability remediation, bachelor’s in cybersecurity, experience with application-security testing, secure SDLC, and working with development teams to remediate findings.
Concept Plus: Delivers enterprise IT services for federal government agencies.
8+ YOERequires U.S. citizenship, TS/SCI clearance with polygraph, 8+ years in application security or related fields, bachelor's degree, secure SDLC and cloud-native experience, and proficiency with listed security technologies and standards.
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
Bachelor's in engineering/CS, knowledge of system vulnerabilities and remediation, experience with web protocols and threat modeling, coding/scripting experience, penetration testing knowledge.
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions: Provides professional and technical services to government entities.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
CACINYSE: CACI: Provides information technology and professional services to government clients.
Active TS/SCI with Polygraph; strong analytics development background; proficiency in Python; experience with RMF, system authorization, and vulnerability management (e.g., Nessus); 4+ years experience typical depending on degree.
CACI InternationalNYSE: CACI: Provides information technology and engineering services for government agencies.
Active TS/SCI with polygraph, strong analytics development background, proficiency in Python, experience with system authorization, RMF, and vulnerability management; multi-year technical experience as specified by education.
Anduril Industries: Defense technology building autonomous military hardware and software.
5+ YOE5+ years progressive technical security experience, active SECRET clearance, knowledge of ICD-705/IC Tech Spec, commissioning IDS/ACS, proficiency with accreditation and AO interaction, strong communication and problem solving.
Integrity Technology Consultants: Provides engineering and management consulting solutions to US national security.
Active Top Secret/SCI with polygraph required; senior experience in cloud security, architecture, and governance; multi-year experience (varies by degree); strong communication and technical skills.
EOA Technologies: Designs and manages secure IT infrastructure for government agencies.
4+ YOEActive TS/SCI with Polygraph required; 4+ years technical experience (higher experience alternative options listed); cloud computing and virtualization experience; strong communication and architecture skills; knowledge of cloud security and compliance.