55 appsec jobs at 43 companies in Washington, DC

PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yr On-SiteFull Time
HiringCafe
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
Node.js, Python, Elasticsearch, Redis
2mo
Save
Mark Applied
Hide
Lead AppSec Engineer
Los Angeles or Washington or United States
$150k-$220k/yr RemoteFull Time
Virtualitics
Virtualitics: Provides an AI-native platform for readiness and analytics.
Technical leadership in application security with hands-on AI/ML experience, threat modeling, cloud and container security (AWS/GCP/Azure, Docker, Kubernetes), familiarity with SAST/DAST/container scanning and security platforms (Wiz, Snyk, GitHub Advanced Security), and experience designing secure AI workflows.
Claude Code, Cursor, AWS, GCP, Azure, Docker, Kubernetes, Wiz, Snyk, GitHub Advanced Security, SAST, DAST, container scanning, CI/CD
1mo
Save
Mark Applied
Hide
Staff AppSec Engineer
Washington or United States
$210k-$230k/yr RemoteFull Time
Upside
Upside: Personalized cashback rewards platform for everyday brick-and-mortar purchases.
6+ YOE6+ years in application/product security, hands-on Python code review, vulnerability management, deep AWS security experience (Lambda, Control Tower), experience integrating AI tools, strong communication; Bachelor's preferred.
GitHub Advanced Security, GitHub Actions, GitHub Copilot, Python, Terraform, AWS, AWS Lambda, DynamoDB, S3, SNS, SQS, IAM, VPCs, AWS Control Tower, ChatGPT, Snowflake, SQL
1mo
Save
Mark Applied
Hide
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions
Essnova Solutions: Provides professional and technical services to government entities.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
2w
Save
Mark Applied
Hide
Web Developer / Application Security (AppSec) Engineer
Washington, District of Columbia, United States
OnsiteFull Time
ASSYST
ASSYST: An IT firm specializing in digital transformation, DevSecOps, cybersecurity, and AI integration for government agencies.
Experience with secure SDLC, DevSecOps automation, vulnerability remediation, and protecting web applications; development experience with REST APIs, SQL, .NET/C#, JavaScript, Python, Node.js, React, TypeScript; familiarity with SIEM, IDS/IPS, EDR/NDR, Wireshark; U.S. citizenship required; security certifications preferred.
REST APIs, SQL, .NET/C#, JavaScript, Python, Node.js, React, TypeScript, SIEM, IDS/IPS, EDR/NDR, Wireshark, WAF, NIST, FISMA, FedRAMP
1w
Save
Mark Applied
Hide
Sr AWS Application Security Engineer, ADC AppSec
Arlington or Seattle
$178k-$227k/yr OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
4+ YOE4+ years troubleshooting systems and security issues, experience identifying vulnerabilities and remediation, mentoring or tech lead experience; threat modeling and service/microservices security preferred.
1w
Save
Mark Applied
Hide
Sr. Manager, Application Security
Bethesda or United States
$110k-$190k/yr HybridFull Time
Marriott International
Marriott InternationalNASDAQ: MAR: Operates and franchises a global network of hotels and resorts.
7+ YOE4+ Mgmt7+ years IT/security experience with 4+ years security leadership, bachelor\u0002s degree or equivalent, experience with AppSec testing (SAST/DAST/IAST), SCA, release management, and GitHub/JIRA/ServiceNow/Jenkins/Harness.
GitHub, JIRA, ServiceNow, Jenkins, Harness, SAST, DAST, IAST, SCA, OWASP, MITRE CVE/CWE
2w
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
OnsiteFull Time
MicroTech
MicroTech: Provider of IT integration, cloud, and managed services.
3+ YOEBachelor's degree, 3+ years in web application or application security engineering, experience with AppSec tooling, DevSecOps, WAF/FIM, vulnerability management, and federal compliance (NIST/FISMA/FedRAMP).
.NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, SQL, Python, Node.js, TypeScript, Java, React.js, Web Application Firewall (WAF), File Integrity Monitoring (FIM), SIEM, IDS/IPS, EDR, NDR, Wireshark, Docker, Kubernetes, AWS, CI/CD
1mo
Save
Mark Applied
Hide
Enterprise Cybersecurity Product Analyst
McLean, Virginia, United States
$87k-$198k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOE3+ years in product/security/appsec roles; experience with architecture/design reviews, threat modeling, secure-by-design principles; ability to obtain Secret clearance; Bachelor's degree required; strong communication and tracking skills.
4w
Save
Mark Applied
Hide
Security Architect
Washington or Cleveland or California or Colorado or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or New Jersey or New York or Vermont or Virginia or Washington
$135k-$279k/yr OnsiteFull Time
Accenture Federal Services
Accenture Federal ServicesNYSE: ACN: Provides technology and consulting services to U.S. federal agencies.
12+ YOE12+ years progressive cybersecurity experience with leadership across SOC, incident response, detection, vulnerability management, engineering, and AppSec; enterprise security program experience; US citizenship and clearance eligibility; up to 25% travel.
NIST, RMF, Zero Trust, AWS, Microsoft Azure, GCP, SOAR, AI, ML
2w
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
CMT Services
CMT Services: Provides management and technology consulting to government entities.
3+ YOE3+ years in web application security/AppSec/SSDLC, hands-on secure development, DevSecOps automation, WAF and FIM management, log/SIEM analysis, OWASP Top 10 mitigation, scripting for automation, and compliance with NIST/FedRAMP.
GitHub Copilot, OpenAI API/Codex, Python, JavaScript/Node.js, Java, React.js, TypeScript, .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, SQL, Wireshark, SIEM, IDS/IPS, NDR, EDR, WAF, File Integrity Monitoring (FIM)
2w
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
OnsiteFull Time
MicroTech
MicroTech: Provides IT, network, and cybersecurity solutions for government agencies.
3+ YOE3+ years in web application security or AppSec, bachelor's degree, experience with secure SDLC/DevSecOps, web dev tech (.NET, C#, HTML5, JavaScript), scripting (Python, Node.js), WAF/FIM, SIEM/EDR, and federal compliance knowledge.
.NET, C#, WCF, HTML5, CSS3, JavaScript, REST APIs, SQL, Python, Node.js, TypeScript, Java, React.js, WAF, FIM, SIEM, IDS/IPS, EDR, NDR, Wireshark, AWS, Docker, Kubernetes
1mo
Save
Mark Applied
Hide
NLM Bioinformatics Specialist and Developer (SME) I - III
Bethesda, Maryland, United States
$90k-$135k/yr OnsiteFull Time
Lexical Intelligence
Lexical Intelligence: Develops NLP software for biomedical research and portfolio analysis.
4+ YOESME I-III with Python, ML/NLP, biomedical informatics; experience in software development and data analytics.
Python, Java, C++, R, JavaScript, SQL, MATLAB, NLP, ML, DL, SDLC, OWASP, US-CERT
3mo
Save
Mark Applied
Hide
SR Cloud Engineer – Space Programs
Herndon or Aurora
$135k-$216k/yr OnsiteFull Time
Peraton
Peraton: National security and mission-critical government technology services provider.
10+ YOEBachelor’s with 10+ years; TS/SCI with poly; 4+ years cloud engineering; IAT Level II; cloud platforms (AWS/Azure/GCP); IaC and automation; Docker/Kubernetes/OpenShift; CI/CD experience
Docker, Kubernetes, OpenShift, Rancher, Ansible, Git/GitLab, Jenkins, AWS, Azure, GCP, CI/CD, PKI, Active Directory/FreeIPA, OWASP, STIG
1mo
Save
Mark Applied
Hide
Software Engineer II - Front End/ Back End
Columbia, Maryland, United States
$100k-$110k/yr RemoteFull Time
Ad Hoc
Ad Hoc: Builds user-centered digital services and platforms for government agencies.
5+ YOEBachelor's degree and 5+ years software engineering experience; strong React, TypeScript, JavaScript, accessibility, REST API, testing, Git, and US citizenship with DHS Public Trust eligibility.
JavaScript, TypeScript, React, React Hooks, RESTful APIs, Git, USWDS, Redux, Context API, React Query, GraphQL, Vite, Webpack, Jest, React Testing Library, Cypress, Playwright, Docker, Kubernetes, AWS, Figma, Lighthouse, Core Web Vitals, OWASP
2d
Save
Mark Applied
Hide
Cybersecurity Lead - ISSM
Chantilly or Beale Air Force Base or Flexwork
HybridFull Time
SAIC
SAICNASDAQ: SAIC: Provides government and defense clients with technology and engineering services.
9+ YOEAdvanced RMF expertise, experience with Xacta/STIGs/OWASP/ACAS/Nessus, DoD 8140-aligned certs (CISSP/CCSP/GSE/CASP+), and 9+ years of relevant experience (varies by degree).
Xacta, STIG, OWASP, ACAS, Nessus, SAST, DAST
3mo
Save
Mark Applied
Hide
Penetration Tester III
Washington, District of Columbia, United States
HybridFull Time
SOSi
SOSi: Provides technology and mission solutions for national security.
5+ YOE5-7 years pentest experience; red team; IoT/mobile/cloud testing; MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, ISSAF; Bachelor's; Certifications: GPEN or GXPN; CISA with AES HVA Lead/Technical Lead plus one of GRTP/CRTL/OSCP/CRTP/CMWAPT/CEPT/CPT/LPT; Secret clearance.
MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, ISSAF, GPEN, GXPN, CISA, GRTP, CRTL, OSCP, CRTP, CMWAPT, CEPT, CPT, LPT
1mo
Save
Mark Applied
Hide
Penetration Tester (Part Time & Remote)
Sterling or United States
$50-$85/hr RemotePart Time, Contract
TestPros
TestPros: Provides independent IT assessment and cybersecurity compliance services.
5+ YOEMinimum 5 years penetration testing experience; proficiency with CLI, scripting (Python, Bash, PowerShell, C/C++), commercial and open-source pentest tools; desired Security+, CEH, GPEN, OSCP, AWS certifications; strong communication and consulting skills.
Windows, macOS, Linux, Python, Bash, PowerShell, C/C++, Metasploit, Nikto, SQLMAP, Responder, Nessus, Netcat, Burp Suite, OWASP, OSSTMM, PTES, FedRAMP, NIST
1mo
Save
Mark Applied
Hide
Senior Microelectronics Engineer
Alexandria, Virginia, United States
OnsiteFull Time
Modern Technology Solutions, Inc.
Modern Technology Solutions, Inc.: Provides engineering, technology, and cybersecurity services for national security.
10+ YOE10+ years technical leadership in semiconductor R&D; experience in integrated circuit and embedded system design, micro-electronics analysis, system security, cryptography/key management, testing and evaluation; current TS/SCI clearance and MS in related field.
Field-programmable gate array (FPGA), ASIC verification, Microcode, Software Security
2mo
Save
Mark Applied
Hide
Staff, Application Security Engineer - Product Security
Bentonville or Herndon
$110k-$264k/yr OnsiteFull Time
Walmart
WalmartNYSE: WMT: Multinational retail operating discount stores and supermarkets.
4+ YOE4+ years application security experience with bachelor's degree or 6+ years without; expertise in OWASP, SAST/SCA tooling, threat modeling, secure architecture, and audit-ready governance.
SAST, SCA, OWASP, Web Content Accessibility Guidelines (WCAG) 2.2
2w
Save
Mark Applied
Hide
Senior Penetration Tester
Washington, District of Columbia, United States
OnsiteFull Time
Tharros
Tharros: Provides specialized cybersecurity defense and vulnerability research services.
10+ YOEActive TS/SCI clearance, 10+ years cybersecurity assessment experience, CEH or CISSP, expertise in penetration testing, software assurance, vulnerability assessment, cloud/DevSecOps, and producing technical and executive reports.
MITRE ATT&CK, OWASP, NIST 800-115, NIST SP 800-161, CNSSI 1253, DHS 4300C, SBOM, Archer, eMASS, Xacta, CI/CD, DevSecOps