160 application security engineer jobs at 92 companies in Brunswick, MD

10h
Save
Mark Applied
Hide
Application Security Engineer
Annapolis Junction, Maryland, United States
$87k-$198k/yr RemoteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
5+ YOERequires 5+ years in cybersecurity, application or product security, or software engineering; Secure SDLC, security tools, cloud architectures, frameworks, communication, and a relevant bachelor's degree.
Secure SDLC, SBOM, SAST, DAST, SCA, IaC, Kubernetes, OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, MITRE ATT&CK, MITRE ATLAS, Artificial Intelligence
2mo
Save
Mark Applied
Hide
Application Security Engineer
Washington, District of Columbia, United States
$180k-$200k/yr RemoteFull Time
Virtru
Virtru: Provides data-centric encryption and privacy control software for organizations.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
2mo
Save
Mark Applied
Hide
Application Security Engineer 3
Arlington, Virginia, United States
OnsiteFull Time
Bloomberg Industry Group
Bloomberg Industry Group: Provides legal, tax, and government intelligence and news services.
5+ YOELead application security engineering, design scalable security architectures, perform risk assessments, integrate security across the SDLC, and drive automation.
Python, Java, JavaScript, SAST, DAST, SCA, IaC, Container, Cloud Security, Kubernetes, DevSecOps
22h
Save
Mark Applied
Hide
Application Security Engineer
Annapolis Junction or Bethesda
$87k-$198k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
5+ YOERequires 5+ years in cybersecurity, application security, product security, or software engineering; Secure SDLC, application security tools, cloud-native architectures, risk management, and client leadership experience; bachelor's degree.
Microsoft Internet Explorer, Google Chrome, Mozilla Firefox, Microsoft Edge, Apple Safari, Opera Browser, Blackberry Browser, SAST, DAST, SCA, IaC, API, Agile, Scrum, DevSecOps, Kubernetes, SBOM, OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, MITRE ATT&CK, ATLAS
5d
Save
Mark Applied
Hide
Application Security Engineer
Tysons, Virginia, United States
$115k-$145k/yr HybridFull Time
Veilant
Veilant: Protecting operations, personnel, and data from emerging surveillance threats.
2+ YOERequires 2+ years of Java development, application security testing, source-code review, web security, CI/CD, containers, cloud platforms, and strong technical communication; must be able to obtain security clearance.
Java, Java Spring Boot, Angular, REST APIs, SQL, PostgreSQL, JWT, OAuth, Entra, Keycloak, GitLab CI, Azure DevOps, GitHub Actions, Kubernetes, Trivy, Kubesec, Azure, AWS, GitLab Secrets Manager, AWS KMS, Azure Key Vault, Ansible Vault, SAST, DAST, SCA, Falco, NeuVector, Burp Suite, CI/CD, IaC
1mo
Save
Mark Applied
Hide
Staff Security Engineer, Application Security
Chicago or California or Colorado or Florida or Georgia or Illinois or Indiana or Minnesota or Missouri or Montana or New Jersey or New York or North Carolina or Ohio or Oregon or Pennsylvania or South Carolina or Texas or Utah or Vermont or Virginia or Washington or Washington or Wisconsin
$210k-$260k/yr HybridFull Time
NinjaTrader
NinjaTrader: Provides futures brokerage services and a trading software platform.
7+ YOE7+ years in application/product/security engineering; hands-on threat modeling, vulnerability management, secure design, CI/CD integration, automation using Python/Go; experience with cloud-native AWS/GCP environments.
AWS, GCP, Python, Go, SAST, SCA, DAST, CI/CD, AI/LLMs
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
Washington, District of Columbia, United States
$150k-$173k/yr OnsiteFull Time
The Nuclear Company
The Nuclear Company: Deploys standardized nuclear reactors for utility-scale energy generation.
4+ YOE4+ years in application/product/software security; experience with secure SDLC tooling (GitHub Advanced Security, CodeQL, Dependabot, SAST/SCA/DAST), familiarity with AWS security, ability to read code (Python, TypeScript, Go, Java, C#, C++), strong communication and offensive-security mindset.
GitHub, GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, DAST, Palantir Foundry, AWS, IAM, CI/CD, Python, TypeScript, Go, Java, C#, C++, OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, NERC CIP
3w
Save
Mark Applied
Hide
(USA) Staff, Application Security Engineer
Bentonville or Herndon
$110k-$264k/yr OnsiteFull Time
Walmart
WalmartNYSE: WMT: Multinational retail operating discount stores and supermarkets.
4+ YOEBachelor's degree plus 4 years in application security, or 6 years of application security experience. Preferred security certifications and project leadership experience.
AI, CI/CD, IDE, CLI, PR bots, WCAG 2.2 AA
1w
Save
Mark Applied
Hide
Senior Engineer, Application Security
Tysons Corner, Virginia, United States
$120k-$160k/yr HybridFull Time
Cvent
Cvent: Cloud-based software for event and venue management.
5+ YOE5+ years in application security or secure software development; strong scripting in Python, JavaScript/TypeScript, or Bash; CI/CD and SDLC security integration; cloud (AWS preferred) and tool familiarity; end-to-end ownership experience.
Python, JavaScript, TypeScript, Bash, AWS, GCP, Azure, AWS CDK, Burp Suite, Checkmarx, Mend, Veracode, Fortify, ZAP, Wiz, CI/CD, SAST, DAST, SCA
2w
Save
Mark Applied
Hide
Application Security Engineer — Secure Mission Systems
United States or Laurel
RemoteFull Time
Rackner
Rackner: Builds cloud-native software and AI systems for government agencies.
6+ YOE6+ years in SAST/DAST and vulnerability remediation, bachelor’s in cybersecurity, experience with application-security testing, secure SDLC, and working with development teams to remediate findings.
Fortify, X-Ray, OWASP ZAP, GitLab, Artifactory, OpenShift, Kubernetes, WebAssembly (WASM)
1d
Save
Mark Applied
Hide
Application Security Engineer (Full Scope Poly)
Reston, Virginia, United States
OnsiteFull Time
Concept Plus
Concept Plus: Delivers enterprise IT services for federal government agencies.
8+ YOERequires U.S. citizenship, TS/SCI clearance with polygraph, 8+ years in application security or related fields, bachelor's degree, secure SDLC and cloud-native experience, and proficiency with listed security technologies and standards.
Oracle Cloud, Python, JavaScript, SQL, Shell, PL/SQL, SAST, DAST, SCA, Kubernetes, Docker, REST APIs, CI/CD, Oracle Cloud Infrastructure (OCI), NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, Oracle RDBMS, Agile
3w
Save
Mark Applied
Hide
Security Engineer, Infrastructure Application Security
Herndon, Virginia, United States
OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
Bachelor's in engineering/CS, knowledge of system vulnerabilities and remediation, experience with web protocols and threat modeling, coding/scripting experience, penetration testing knowledge.
AWS, Python, Perl, Bash, PowerShell, HTTP, DNS, TCP/IP
1mo
Save
Mark Applied
Hide
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions
Essnova Solutions: Provides professional and technical services to government entities.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
2w
Save
Mark Applied
Hide
Technical Security Application Engineer, Secured Spaces
Washington, District of Columbia, United States
$146k-$194k/yr OnsiteFull Time
Anduril Industries
Anduril Industries: Defense technology building autonomous military hardware and software.
5+ YOE5+ years progressive technical security experience, active SECRET clearance, knowledge of ICD-705/IC Tech Spec, commissioning IDS/ACS, proficiency with accreditation and AO interaction, strong communication and problem solving.
Lattice OS, Lenel OnGuard, Genetec, DMP, Bosch
2mo
Save
Mark Applied
Hide
Senior Application Developer
Fort Meade, Maryland, United States
$164k-$200k/yr OnsiteFull Time
Belay Technologies
Belay Technologies: Provides specialized technology and engineering services to the DoD.
12+ YOESecurity clearance TS/SCI with poly; 12+ years software engineering; reverse engineering, development, and analyst skills.
C, C++, Python, Assembly, Reverse Engineering, Networking
1mo
Save
Mark Applied
Hide
Application Developer
Reston, Virginia, United States
OnsiteFull Time
ASRC Federal
ASRC Federal: Provides engineering and IT services to federal government agencies.
2+ YOEU.S. citizenship with ability to obtain security clearance; Bachelor's in CS/Engineering; 2+ years software development; proficiency with Java, JavaScript, relational databases, Git, HTML/CSS/JSON/XML; strong analytical and communication skills.
Java, JavaScript, PostgreSQL, Oracle, Git, HTML, CSS, JSON, XML, XSLT, XSD, Python, Android, Jenkins, Jira, Confluence, REST, SOAP
2mo
Save
Mark Applied
Hide
Senior Security Engineer
Austin or Bochum or Dubai or Geneva or London or Singapore or Tokyo or Washington
OnsiteFull Time
Sonar
Sonar: Provides automated tools for code quality and security analysis.
Senior-level security engineering experience with cloud (AWS), application security, vulnerability management, DLP, scripting/automation (Python or Bash), and experience assessing SaaS/security tools (Wiz, CrowdStrike). Strong communication skills.
AWS, Python, Bash, Wiz, CrowdStrike, Google Workspace, GitHub Copilot, Claude Code, Codex, Cursor, Gemini, Devin, SonarQube, SonarQube Foundation Agent, SonarSweep, Sonar Context Augmentation, DLP
1w
Save
Mark Applied
Hide
Application Developer/Programmer
Alexandria, Virginia, United States
$120k-$250k/yr OnsiteFull Time
B&A
B&A: Provides IT systems integration and data services to federal agencies.
0+ YOEDevelop, test, implement, and maintain web and database applications; proficiency with Java/J2EE stack and related frameworks; security clearance (TS/SCI) required; bachelor’s degree and relevant certifications preferred.
Java, J2EE, JSP, HTML, XML, Spring, Hibernate, CSS, JavaScript, Apache Tomcat, Git
5d
Save
Mark Applied
Hide
Web Developer Security Engineer (DC, Washington)
Washington, District of Columbia, United States
$145k-$175k/yr OnsiteFull Time
RiVidium
RiVidium: Provides cybersecurity software and IT services to federal agencies.
5+ YOERequires 5+ years of secure software or application security engineering, 3+ years of web application security or SSDLC, a bachelor's degree or equivalent, and active Top Secret clearance.
OWASP Top 10, WAF, FIM, CI/CD, DevSecOps
1mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Nationwide IT Services
Nationwide IT Services: Provides IT and management consulting services to federal government agencies.
3+ YOE3+ years in application security/SSDLC, strong OWASP knowledge, vulnerability lifecycle management, DevSecOps/CI-CD integration, WAF and FIM experience, Tier II security operations, relevant application/offensive/foundational security certification.
C#, ASP.NET MVC, WCF, HTML5, CSS3, JavaScript, React, TypeScript, REST APIs, SQL, Python, Node.js, Java, GitHub Copilot, WAF, File Integrity Monitoring (FIM), SIEM, IDS/IPS, NDR, EDR, AWS, Docker, Kubernetes