176 application security engineer jobs at 102 companies in Chantilly, VA

1mo
Save
Mark Applied
Hide
Application Security Engineer
Washington, District of Columbia, United States
$180k-$200k/yr RemoteFull Time
Virtru
Virtru: Provides data-centric encryption and privacy control software for organizations.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
2mo
Save
Mark Applied
Hide
Application Security Engineer 3
Arlington, Virginia, United States
OnsiteFull Time
Bloomberg Industry Group
Bloomberg Industry Group: Provides legal, tax, and government intelligence and news services.
5+ YOELead application security engineering, design scalable security architectures, perform risk assessments, integrate security across the SDLC, and drive automation.
Python, Java, JavaScript, SAST, DAST, SCA, IaC, Container, Cloud Security, Kubernetes, DevSecOps
2mo
Save
Mark Applied
Hide
Application Security Engineer
Fort Meade, Maryland, United States
$87k-$198k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
4+ YOE4+ years DoD enterprise security architecture, F5 BIG-IP expertise, DoD IL Clouds/on‑prem, VMware/NSX-T, SD-WAN, Secret clearance, HS diploma or GED.
F5 BIG-IP, VMware NSX-T, LTM, APM, ASM, SD-WAN, RDP, SSH, TLS, PKI
3w
Save
Mark Applied
Hide
Staff Security Engineer, Application Security
Chicago or California or Colorado or Florida or Georgia or Illinois or Indiana or Minnesota or Missouri or Montana or New Jersey or New York or North Carolina or Ohio or Oregon or Pennsylvania or South Carolina or Texas or Utah or Vermont or Virginia or Washington or Washington or Wisconsin
$210k-$260k/yr HybridFull Time
NinjaTrader
NinjaTrader: Provides futures brokerage services and a trading software platform.
7+ YOE7+ years in application/product/security engineering; hands-on threat modeling, vulnerability management, secure design, CI/CD integration, automation using Python/Go; experience with cloud-native AWS/GCP environments.
AWS, GCP, Python, Go, SAST, SCA, DAST, CI/CD, AI/LLMs
11h
Save
Mark Applied
Hide
Application Security Engineer
Tysons Corner, Virginia, United States
$83k-$150k/yr OnsiteFull Time
MicroStrategy
MicroStrategyNasdaq: MSTR: Develops enterprise analytics software and manages Bitcoin treasury holdings.
2+ YOE2+ years software development/security experience, bachelor in CS/engineering, hands-on with SAST/DAST/SCA, experience applying generative AI to security, programming in Python/Java/JavaScript, strong secure coding and communication skills.
Copilot, Cursor, Claude, GitHub Copilot Autofix, Semgrep, Checkmarx, Fortify, Veracode, SonarQube, Burp Suite, ZAP, Python, Java, JavaScript, AWS, Azure, GCPF, SAST, DAST, SCA, IAST, LLM, CI/CD
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
Washington, District of Columbia, United States
$150k-$173k/yr OnsiteFull Time
The Nuclear Company
The Nuclear Company: Deploys standardized nuclear reactors for utility-scale energy generation.
4+ YOE4+ years in application/product/software security; experience with secure SDLC tooling (GitHub Advanced Security, CodeQL, Dependabot, SAST/SCA/DAST), familiarity with AWS security, ability to read code (Python, TypeScript, Go, Java, C#, C++), strong communication and offensive-security mindset.
GitHub, GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, DAST, Palantir Foundry, AWS, IAM, CI/CD, Python, TypeScript, Go, Java, C#, C++, OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, NERC CIP
1d
Save
Mark Applied
Hide
Senior Engineer, Application Security
Tysons Corner, Virginia, United States
$120k-$160k/yr HybridFull Time
Cvent
Cvent: Cloud-based software for event and venue management.
5+ YOE5+ years in application security or secure software development; strong scripting in Python, JavaScript/TypeScript, or Bash; CI/CD and SDLC security integration; cloud (AWS preferred) and tool familiarity; end-to-end ownership experience.
Python, JavaScript, TypeScript, Bash, AWS, GCP, Azure, AWS CDK, Burp Suite, Checkmarx, Mend, Veracode, Fortify, ZAP, Wiz, CI/CD, SAST, DAST, SCA
3d
Save
Mark Applied
Hide
Application Security Engineer
Tysons, Virginia, United States
$92k-$124k/yr HybridFull Time
Veilant
Veilant: Protecting operations, personnel, and data from emerging surveillance threats.
2+ YOE2+ years Java development, hands-on AppSec testing, secure code review, CI/CD and container security experience, ability to obtain security clearance.
Burp Suite, Java Spring Boot, Angular, REST, PostgreSQL, JWT, OAuth, Entra, Keycloak, GitLab CI, Azure DevOps, GitHub Actions, Kubernetes, Trivy, Kubesec, Falco, NeuVector, Azure, AWS, GitLab Secrets Manager, AWS KMS, Azure Key Vault, Ansible Vault, SAST, DAST, SCA, Infrastructure-as-Code (IaC)
2mo
Save
Mark Applied
Hide
Application Security Engineer
Hanover, Maryland, United States
$166k-$295k/yr OnsiteFull Time
ManTech
ManTech: Provides technology solutions for defense and intelligence agencies.
11+ YOETS/SCI with poly required. 11–15+ years experience in systems security, software engineering, or computer science. Hands-on C/C++ or C#, ability to read Java, experience with software assurance tools and source code analysis.
C, C++, C#, Java, Rust, Ada, x86_64, PowerPC, MIPS, ASM, Klocwork, CodeSonar, Fortify, CodePeer, IDA Pro, Fortran-Lint
2mo
Save
Mark Applied
Hide
Staff, Application Security Engineer - Product Security
Bentonville or Herndon
$110k-$220k/yr OnsiteFull Time
Walmart
WalmartNYSE: WMT: Multinational retail operating discount stores and supermarkets.
4+ YOE4+ years application security experience with Bachelor's or 6+ years without; expertise in secure architecture, threat modeling, SAST/SCA, OWASP, automation of security validation, and strong communication skills.
SAST, SCA, OWASP
1w
Save
Mark Applied
Hide
Application Security Engineer — Secure Mission Systems
United States or Laurel
RemoteFull Time
Rackner
Rackner: Builds cloud-native software and AI systems for government agencies.
6+ YOE6+ years in SAST/DAST and vulnerability remediation, bachelor’s in cybersecurity, experience with application-security testing, secure SDLC, and working with development teams to remediate findings.
Fortify, X-Ray, OWASP ZAP, GitLab, Artifactory, OpenShift, Kubernetes, WebAssembly (WASM)
2w
Save
Mark Applied
Hide
Security Engineer, Infrastructure Application Security
Herndon, Virginia, United States
OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
Bachelor's in engineering/CS, knowledge of system vulnerabilities and remediation, experience with web protocols and threat modeling, coding/scripting experience, penetration testing knowledge.
AWS, Python, Perl, Bash, PowerShell, HTTP, DNS, TCP/IP
1mo
Save
Mark Applied
Hide
Application Security Engineer
Fort Meade, Maryland, United States
$87k-$198k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
4+ YOERequires 4+ years supporting DoD enterprise architecture, 4+ years designing/administrating F5 BIG-IP, experience with inline break-and-inspect proxies, TLS/mTLS configuration, knowledge of PKI/cryptography, Secret clearance, HS diploma or GED.
F5 BIG-IP, Office 365, Teams, RDP, SSH, CLI, Linux, UNIX, NIST 800-53, FIPS, DoD STIG, FedRAMP
1mo
Save
Mark Applied
Hide
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions
Essnova Solutions: Provides professional and technical services to government entities.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
2w
Save
Mark Applied
Hide
Lead Security Application Engineer
Alexandria, Virginia, United States
$115k-$150k/yr OnsiteFull Time
3SI Security Systems
3SI Security Systems: Provides GPS tracking and surveillance for asset protection.
4+ YOE4+ years VMS/PSIM experience, team leadership, networking and video streaming expertise, Microsoft SQL Server/SQL skills, active U.S. Secret clearance, and ability to travel up to 50% OCONUS.
Surveill, VMS, PSIM, Microsoft SQL Server, SQL, TCP/IP, h.264, h.265, Multicast, Unicast
3w
Save
Mark Applied
Hide
Security Automation Application Engineer
Linthicum, Maryland, United States
$104k-$218k/yr OnsiteFull Time
CACI
CACINYSE: CACI: Provides information technology and professional services to government clients.
Active TS/SCI with Polygraph; strong analytics development background; proficiency in Python; experience with RMF, system authorization, and vulnerability management (e.g., Nessus); 4+ years experience typical depending on degree.
Python, Pig, PySpark, AWS Lambda, Nessus Vulnerability Scanner
1w
Save
Mark Applied
Hide
Technical Security Application Engineer, Secured Spaces
Washington, District of Columbia, United States
$146k-$194k/yr OnsiteFull Time
Anduril Industries
Anduril Industries: Defense technology building autonomous military hardware and software.
5+ YOE5+ years progressive technical security experience, active SECRET clearance, knowledge of ICD-705/IC Tech Spec, commissioning IDS/ACS, proficiency with accreditation and AO interaction, strong communication and problem solving.
Lattice OS, Lenel OnGuard, Genetec, DMP, Bosch
1w
Save
Mark Applied
Hide
Application Engineer Expert Level
Linthicum, Maryland, United States
$225k-$305k/yr OnsiteFull Time
Integrity Technology Consultants
Integrity Technology Consultants: Provides engineering and management consulting solutions to US national security.
Active Top Secret/SCI with polygraph required; senior experience in cloud security, architecture, and governance; multi-year experience (varies by degree); strong communication and technical skills.
AWS, Azure, Google Cloud, IAM, SCPs, AWS Key Management Service, AWS Config, AWS Security Hub, GuardDuty, Inspector, Risk Management Framework, Zero-Trust
1w
Save
Mark Applied
Hide
APPLICATION ENGINEER LEVEL 4
Fort Meade, Maryland, United States
OnsiteFull Time
EOA Technologies
EOA Technologies: Designs and manages secure IT infrastructure for government agencies.
4+ YOEActive TS/SCI with Polygraph required; 4+ years technical experience (higher experience alternative options listed); cloud computing and virtualization experience; strong communication and architecture skills; knowledge of cloud security and compliance.
AWS, Azure, Google Cloud, IAM, SCPs, AWS Key Management Service, AWS Config, AWS Security Hub, Guard Duty, Inspector
1mo
Save
Mark Applied
Hide
Senior Application Developer
Fort Meade, Maryland, United States
$164k-$200k/yr OnsiteFull Time
Belay Technologies
Belay Technologies: Provides specialized technology and engineering services to the DoD.
12+ YOESecurity clearance TS/SCI with poly; 12+ years software engineering; reverse engineering, development, and analyst skills.
C, C++, Python, Assembly, Reverse Engineering, Networking