217 web application security engineer jobs at 158 companies in United States

2mo
Save
Mark Applied
Hide
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions
Essnova Solutions: Minority-owned Alabama small-business government contractor delivering IT, professional, geospatial, healthcare, and environmental services to public and commercial clients.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
2w
Save
Mark Applied
Hide
Web Application Developer
Linthicum, Maryland, United States
$129k-$156k/yr OnsiteFull Time
Quevera
Quevera: Veteran-owned custom software engineering firm serving government customers with mission-critical IT solutions.
7+ YOERequires active TS/SCI clearance with polygraph, 7 years of software engineering experience, a bachelor's in computer science or equivalent experience, IAM certification, and web development, Linux, API, database, and secure coding skills.
Amazon Web Services (AWS), PHP, .NET, C#, Java, Node.js, Python, HTML, CSS, JavaScript, Vue.js, React, Linux, Microsoft Azure, IAM, Amazon EC2, Application Load Balancer, Amazon S3, Amazon RDS, Amazon CloudWatch, Nginx, Apache, Tomcat, Microsoft PowerShell, CI/CD
1mo
Save
Mark Applied
Hide
Web Application Firewall Engineer
United States
$100k-$120k/yr RemoteFull Time
Lightology
Lightology: Contemporary lighting showroom serving architects, designers, contractors, trade professionals, and homeowners.
Experience in application/web security, secure SDLC, vulnerability assessment, WAF configuration, and integrating security into CI/CD/DevSecOps environments.
Barracuda WAF, OWASP Top 10, CI/CD, DevSecOps
2mo
Save
Mark Applied
Hide
Web Application Developer
McLean or United States
OnsiteFull Time
J5 Consulting
J5 Consulting: Minority-owned cybersecurity and IT consulting firm serving commercial businesses and government and defense organizations.
Experience developing modern web applications with JavaScript/TypeScript frameworks, Node.js, RESTful APIs, SQL databases (PostgreSQL/MySQL), containerization (Docker/Podman), AWS, Git, Agile, and strong security and problem-solving skills. US citizenship and active Top Secret clearance with Full Scope Polygraph required.
JavaScript, TypeScript, Angular, React, Vue, Node.js, Express, Koa, Hapi, HTML5, CSS3, ES6+, Sass, PostgreSQL, MySQL, Prisma, Sequelize, Docker, Podman, AWS, Git, ElasticSearch, Terraform, CloudFormation, leaflet.js, Jenkins, JEE, PKI
2mo
Save
Mark Applied
Hide
Application Security Engineer
Washington, District of Columbia, United States
$180k-$200k/yr RemoteFull Time
Virtru
Virtru: Private data security platform providing encryption and access controls for enterprises and government agencies.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
1mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Canada or United States
RemoteFull Time
BioRender
BioRender: Canadian SaaS helping scientists create and share professional scientific figures and communicate research visually.
Proven software engineering experience securing web applications and cloud infrastructure; expertise in Node.js/React/Python, Terraform, AWS, SAST/DAST/SCA integration, threat modeling, and secure SDLC; familiarity with bug bounty programs.
Node.js, React, Python, Terraform, AWS, Cloudflare, SAST, DAST, SCA, HackerOne, OWASP, CI/CD
2w
Save
Mark Applied
Hide
Application Security Engineer
Rensselaer or Albany
$90k-$110k/yr OnsiteFull Time
The Amatriot Group
The Amatriot Group: Service-disabled veteran-owned talent and technology solutions firm serving federal and commercial sectors.
8+ YOERequires 8+ years of IT experience, 3+ years in application security engineering, 5+ years in software development, Java/web development, secure coding, RHEL, JBoss, and application scanning.
Java, Fortify, SonarQube, RHEL, JBoss, CI/CD
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
United States
$114k-$240k/yr OnsiteFull Time
Reltio
Reltio: Cloud-native master-data-management SaaS provider helping enterprises unify, govern, and activate data across SAP and non-SAP systems.
8+ YOE8+ years in application security or software development in cloud-native/SaaS environments; expertise in secure SDLC, CI/CD security, SAST/SCA/DAST, API and AI security; strong cloud and web technology knowledge.
Jenkins, ArgoCD, SAST, SCA, DAST, Model Context Protocol (MCP), LLM, Burp Suite Pro, Java, Java Spring Boot, JavaScript, Node.js, C#, AWS, GCP, Azure, Kubernetes, Wiz, NeMo Guardrails, AWS Bedrock Guardrails, DefectDojo, Wiz Code, Veracode, Checkmarx, Cycode, SonarQube, OWASP
1mo
Save
Mark Applied
Hide
Sr. Application Security Engineer
Redmond, Washington, United States
$170k-$235k/yr OnsiteFull Time
SpaceX
SpaceXNasdaq: SPCX: Designing, manufacturing, and launching advanced rockets and spacecraft.
5+ YOE5+ years security software development experience (or 7+ years without degree), experience with application security for web/mobile, proficiency in Python/C++/Golang/C#, strong communication and networking knowledge.
Python, C++, Golang, C#
3w
Save
Mark Applied
Hide
Web Developer Security Engineer (DC, Washington)
Washington, District of Columbia, United States
$145k-$175k/yr OnsiteFull Time
RiVidium
RiVidium: RiVidium is a privately held federal contractor providing cybersecurity, IT, human-capital, and intelligence services to government agencies.
5+ YOERequires 5+ years of secure software or application security engineering, 3+ years of web application security or SSDLC, a bachelor's degree or equivalent, and active Top Secret clearance.
OWASP Top 10, WAF, FIM, CI/CD, DevSecOps
2mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Spry Methods, Inc.
Spry Methods, Inc.: Minority-owned federal contractor providing cybersecurity, national-security, and IT modernization services to government and commercial clients.
3+ YOE3+ years in web application security or secure software development; hands-on experience with .NET, HTML5, CSS3, JavaScript, REST APIs, and SQL; DevSecOps automation, vulnerability remediation, OWASP Top 10 knowledge, and relevant security certifications.
.NET, HTML5, CSS3, JavaScript, REST APIs, SQL, OWASP Top 10, WAFs
2mo
Save
Mark Applied
Hide
Python Web Application Developer
Tysons Corner or Falls Church
$32-$45/hr HybridFull Time
IntelliDyne
IntelliDyne: Government IT consulting firm delivering technology services to federal and commercial clients.
5+ YOE5+ years Python development, Flask experience, web app deployment and security, authentication and certificate management, REST API and database integration, Git, strong debugging and communication skills.
Python, Flask, Microsoft Entra ID, HTML, CSS, JavaScript, REST APIs, OAuth, SSO, PostgreSQL, SQL Server, MySQL, Git, Azure, AWS, IIS, NGINX, Apache, Docker, Linux, Windows, CI/CD
3w
Save
Mark Applied
Hide
Application Security Engineer
Tysons, Virginia, United States
$115k-$145k/yr HybridFull Time
Veilant
Veilant: Creates control. Advance Undetected in the digital domain.
2+ YOERequires 2+ years of Java development, application security testing, source-code review, web security, CI/CD, containers, cloud platforms, and strong technical communication; must be able to obtain security clearance.
Java, Java Spring Boot, Angular, REST APIs, SQL, PostgreSQL, JWT, OAuth, Entra, Keycloak, GitLab CI, Azure DevOps, GitHub Actions, Kubernetes, Trivy, Kubesec, Azure, AWS, GitLab Secrets Manager, AWS KMS, Azure Key Vault, Ansible Vault, SAST, DAST, SCA, Falco, NeuVector, Burp Suite, CI/CD, IaC
2mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Nationwide IT Services
Nationwide IT Services: Service-disabled veteran-owned IT and management consulting firm serving federal agencies with technology, cybersecurity, and mission support.
3+ YOE3+ years in application security/SSDLC, strong OWASP knowledge, vulnerability lifecycle management, DevSecOps/CI-CD integration, WAF and FIM experience, Tier II security operations, relevant application/offensive/foundational security certification.
C#, ASP.NET MVC, WCF, HTML5, CSS3, JavaScript, React, TypeScript, REST APIs, SQL, Python, Node.js, Java, GitHub Copilot, WAF, File Integrity Monitoring (FIM), SIEM, IDS/IPS, NDR, EDR, AWS, Docker, Kubernetes
5d
Save
Mark Applied
Hide
Application Security Engineer
Atlanta, Georgia, United States
HybridFull Time
Georgia-Pacific
Georgia-Pacific: Privately owned U.S. forest-products manufacturer serving households, businesses, builders, packaging, hygiene, pulp and recycling markets.
Experience securing web applications, analyzing SAST/SCA/DAST findings, programming in listed languages, cloud security in AWS or Azure, and collaborating across teams. Permanent U.S. work authorization required.
React.js, Next.js, ASP.NET, .NET Framework, SAST, SCA, DAST, Python, PowerShell, C#, Java, CI/CD, ServiceNow, SQL, .NET, JavaScript, Go, AWS, Azure, IAM, OWASP, CIS, GHAS, Orca
5d
Save
Mark Applied
Hide
Sr External Web Application & API Security Engineer
Chicago, Illinois, United States
$138k-$173k/yr OnsiteFull Time
McDonald's
McDonald'sNYSE: MCD: Global leader in fast food and quick service restaurants.
5+ YOEBachelor's degree or equivalent experience; 5+ years security engineering, including 3+ years hands-on API security. Requires WAF/API platforms, cloud, security telemetry, scripting, and SIEM/SOAR integrations.
REST, GraphQL, SOAP, gRPC, HTTP, TLS, JSON, OAuth 2.0, OpenID Connect, JWT, AWS, Microsoft Azure, Google Cloud Platform, Terraform, Akamai API Security, Akamai App & API Protector, OpenAPI, SIEM, SOAR, CI/CD, DevSecOps, WAF
4d
Save
Mark Applied
Hide
Application Security Engineer II
Des Moines, Iowa, United States
$102k-$121k/yr HybridFull Time
Federal Home Loan Bank of Des Moines
Federal Home Loan Bank of Des Moines: Federally chartered member-owned cooperative providing mortgage, housing, and community-development funding and liquidity to financial institutions.
3+ YOERequires 3–5 years in application security, information security, or DevSecOps; application assessments, secure SDLC, vulnerability remediation, web security, containers, IaC, programming, and strong communication skills.
SAST, DAST, SCA, Docker, Kubernetes, Python, Java, C#, JavaScript, PowerShell, REST APIs, Azure, AWS, GCP, Web Application Firewalls (WAF), OWASP Top 10, OWASP ASVS, OWASP SAMM, OWASP API Security Top 10, STRIDE, PASTA, SBOM, CI/CD, Git, Infrastructure as Code (IaC), API Security, Secrets Management
3w
Save
Mark Applied
Hide
Application Security Engineer II
United States
$130k-$187k/yr RemoteFull Time
Abnormal Security
Abnormal Security: AI-native cybersecurity SaaS platform that protects enterprise email, identities, and cloud applications from socially engineered attacks.
5+ YOE5+ years in application security, cloud-native security experience, AI/ML security knowledge, programming in Python, Go, Java, or JavaScript/TypeScript, and expertise in web application security and threat modeling.
AWS, Python, Go, Java, JavaScript, TypeScript, OWASP Top 10, Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite, SOC 2, ISO 27001
6d
Save
Mark Applied
Hide
Lead Application Security Engineer
Radnor or Charlotte or Fort Wayne or Greensboro or United States
$120k-$193k/yr RemoteFull Time
Lincoln Financial Group
Lincoln Financial GroupNYSE: LNC: Public financial services providing annuities, life insurance, group protection, and retirement services to individuals and employers.
5+ YOEUndergraduate degree or 4+ years comparable experience; 5–7+ years aligned IT experience; extensive web application security, SDLC, Agile, DevOps security, and application testing experience.
Fortify, Checkmarx, Veracode, AppScan, WebInspect, Burp Suite, OWASP ZAP, WAFs, IPS, LLM, RAG
2mo
Save
Mark Applied
Hide
Python Web Application Developer
Tysons Corner or Falls Church
HybridFull Time
IntelliDyne
IntelliDyne: Government IT consulting firm delivering technology services to federal and commercial clients.
5+ YOE5+ years Python development, Flask experience, web app deployment and security, authentication and certificate management, REST APIs, relational DBs, Git, HTML/CSS/JavaScript, strong debugging and communication skills.
Python, Flask, Microsoft Entra ID, HTML, CSS, JavaScript, REST APIs, PostgreSQL, SQL Server, MySQL, Git, Azure, AWS, IIS, NGINX, Apache, Docker, Linux, Windows, CI/CD