147 application security engineer jobs at 87 companies in Gainesville, VA
1mo
Save
Mark Applied
Hide
1mo
Application Security Engineer
Washington, District of Columbia, United States
$180k-$200k/yrRemoteFull Time
Virtru: Provides data-centric encryption and privacy control software for organizations.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
Chicago or California or Colorado or Florida or Georgia or Illinois or Indiana or Minnesota or Missouri or Montana or New Jersey or New York or North Carolina or Ohio or Oregon or Pennsylvania or South Carolina or Texas or Utah or Vermont or Virginia or Washington or Washington or Wisconsin
$210k-$260k/yrHybridFull Time
NinjaTrader: Provides futures brokerage services and a trading software platform.
7+ YOE7+ years in application/product/security engineering; hands-on threat modeling, vulnerability management, secure design, CI/CD integration, automation using Python/Go; experience with cloud-native AWS/GCP environments.
2+ YOEBachelor's in CS/Engineering, minimum 2 years software or security experience, hands-on with AI security use cases, SAST/DAST/SCA tools, cloud security (AWS/Azure/GCPF), and secure coding; strong communication.
Cvent: Cloud-based software for event and venue management.
5+ YOE5+ years in application security or secure software development; strong scripting in Python, JavaScript/TypeScript, or Bash; CI/CD and SDLC security integration; cloud (AWS preferred) and tool familiarity; end-to-end ownership experience.
WalmartNYSE: WMT: Multinational retail operating discount stores and supermarkets.
4+ YOE4+ years application security experience with Bachelor's or 6+ years without; expertise in secure architecture, threat modeling, SAST/SCA, OWASP, automation of security validation, and strong communication skills.
Application Security Engineer — Secure Mission Systems
United States or Laurel
RemoteFull Time
Rackner: Builds cloud-native software and AI systems for government agencies.
6+ YOE6+ years in SAST/DAST and vulnerability remediation, bachelor’s in cybersecurity, experience with application-security testing, secure SDLC, and working with development teams to remediate findings.
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
Bachelor's in engineering/CS, knowledge of system vulnerabilities and remediation, experience with web protocols and threat modeling, coding/scripting experience, penetration testing knowledge.
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions: Provides professional and technical services to government entities.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
3SI Security Systems: Provides GPS tracking and surveillance for asset protection.
4+ YOE4+ years VMS/PSIM experience, team leadership, networking and video streaming expertise, Microsoft SQL Server/SQL skills, active U.S. Secret clearance, and ability to travel up to 50% OCONUS.
Anduril Industries: Defense technology building autonomous military hardware and software.
5+ YOE5+ years progressive technical security experience, active SECRET clearance, knowledge of ICD-705/IC Tech Spec, commissioning IDS/ACS, proficiency with accreditation and AO interaction, strong communication and problem solving.
ASRC Federal: Provides engineering and IT services to federal government agencies.
2+ YOEU.S. citizenship with ability to obtain security clearance; Bachelor's in CS/Engineering; 2+ years software development; proficiency with Java, JavaScript, relational databases, Git, HTML/CSS/JSON/XML; strong analytical and communication skills.
Onyx Government Services: Provides data analytics and IT services for federal agencies.
15+ MgmtSME-level developer with 15+ years leading application development; expert in cloud-native, microservices, containerization, serverless, DevSecOps, CI/CD, IaC, secure coding, and Section 508 compliance; Bachelor’s in CS or related field.
cloud-native, microservices, containerization, serverless, DevSecOps, CI/CD, version control, automated testing, IaC, Section 508, AI/ML, business intelligence, robotic process automation, SAFe
International Monetary Fund: Fosters global monetary cooperation and secures international financial stability.
6+ YOEApply application security knowledge to support vulnerability remediation, integrate security tools into CI/CD, and collaborate with engineering teams; requires experience in application security, familiarity with OWASP/NIST, and programming knowledge.
SAST, DAST, SCA, CI/CD, Java, Python, .NET, ServiceNow, Azure DevOps, Microsoft Azure, Power BI, OWASP Top 10, NIST
Federal Communications Commission: Regulates communications via radio, television, wire, satellite, and cable.
1+ YOEOne year specialized IT experience equivalent to GS-13 designing, developing, testing, deploying, modernizing, and maintaining enterprise applications using low-code, cloud-native, microservices, APIs, CI/CD and DevSecOps; ensures security, accessibility, and operational support; mentors developers.
J5 Consulting: Provides specialized cybersecurity and technical services to government and commercial clients.
Experience developing modern web applications with JavaScript/TypeScript frameworks, Node.js, RESTful APIs, SQL databases (PostgreSQL/MySQL), containerization (Docker/Podman), AWS, Git, Agile, and strong security and problem-solving skills. US citizenship and active Top Secret clearance with Full Scope Polygraph required.