217 web application security engineer jobs at 158 companies in United States
2mo
Save
Mark Applied
Hide
2mo
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions: Minority-owned Alabama small-business government contractor delivering IT, professional, geospatial, healthcare, and environmental services to public and commercial clients.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
Quevera: Veteran-owned custom software engineering firm serving government customers with mission-critical IT solutions.
7+ YOERequires active TS/SCI clearance with polygraph, 7 years of software engineering experience, a bachelor's in computer science or equivalent experience, IAM certification, and web development, Linux, API, database, and secure coding skills.
J5 Consulting: Minority-owned cybersecurity and IT consulting firm serving commercial businesses and government and defense organizations.
Experience developing modern web applications with JavaScript/TypeScript frameworks, Node.js, RESTful APIs, SQL databases (PostgreSQL/MySQL), containerization (Docker/Podman), AWS, Git, Agile, and strong security and problem-solving skills. US citizenship and active Top Secret clearance with Full Scope Polygraph required.
Virtru: Private data security platform providing encryption and access controls for enterprises and government agencies.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
The Amatriot Group: Service-disabled veteran-owned talent and technology solutions firm serving federal and commercial sectors.
8+ YOERequires 8+ years of IT experience, 3+ years in application security engineering, 5+ years in software development, Java/web development, secure coding, RHEL, JBoss, and application scanning.
Reltio: Cloud-native master-data-management SaaS provider helping enterprises unify, govern, and activate data across SAP and non-SAP systems.
8+ YOE8+ years in application security or software development in cloud-native/SaaS environments; expertise in secure SDLC, CI/CD security, SAST/SCA/DAST, API and AI security; strong cloud and web technology knowledge.
SpaceXNasdaq: SPCX: Designing, manufacturing, and launching advanced rockets and spacecraft.
5+ YOE5+ years security software development experience (or 7+ years without degree), experience with application security for web/mobile, proficiency in Python/C++/Golang/C#, strong communication and networking knowledge.
RiVidium: RiVidium is a privately held federal contractor providing cybersecurity, IT, human-capital, and intelligence services to government agencies.
5+ YOERequires 5+ years of secure software or application security engineering, 3+ years of web application security or SSDLC, a bachelor's degree or equivalent, and active Top Secret clearance.
Spry Methods, Inc.: Minority-owned federal contractor providing cybersecurity, national-security, and IT modernization services to government and commercial clients.
3+ YOE3+ years in web application security or secure software development; hands-on experience with .NET, HTML5, CSS3, JavaScript, REST APIs, and SQL; DevSecOps automation, vulnerability remediation, OWASP Top 10 knowledge, and relevant security certifications.
IntelliDyne: Government IT consulting firm delivering technology services to federal and commercial clients.
5+ YOE5+ years Python development, Flask experience, web app deployment and security, authentication and certificate management, REST API and database integration, Git, strong debugging and communication skills.
Veilant: Creates control. Advance Undetected in the digital domain.
2+ YOERequires 2+ years of Java development, application security testing, source-code review, web security, CI/CD, containers, cloud platforms, and strong technical communication; must be able to obtain security clearance.
Nationwide IT Services: Service-disabled veteran-owned IT and management consulting firm serving federal agencies with technology, cybersecurity, and mission support.
3+ YOE3+ years in application security/SSDLC, strong OWASP knowledge, vulnerability lifecycle management, DevSecOps/CI-CD integration, WAF and FIM experience, Tier II security operations, relevant application/offensive/foundational security certification.
Georgia-Pacific: Privately owned U.S. forest-products manufacturer serving households, businesses, builders, packaging, hygiene, pulp and recycling markets.
Experience securing web applications, analyzing SAST/SCA/DAST findings, programming in listed languages, cloud security in AWS or Azure, and collaborating across teams. Permanent U.S. work authorization required.
Sr External Web Application & API Security Engineer
Chicago, Illinois, United States
$138k-$173k/yrOnsiteFull Time
McDonald'sNYSE: MCD: Global leader in fast food and quick service restaurants.
5+ YOEBachelor's degree or equivalent experience; 5+ years security engineering, including 3+ years hands-on API security. Requires WAF/API platforms, cloud, security telemetry, scripting, and SIEM/SOAR integrations.
REST, GraphQL, SOAP, gRPC, HTTP, TLS, JSON, OAuth 2.0, OpenID Connect, JWT, AWS, Microsoft Azure, Google Cloud Platform, Terraform, Akamai API Security, Akamai App & API Protector, OpenAPI, SIEM, SOAR, CI/CD, DevSecOps, WAF
Federal Home Loan Bank of Des Moines: Federally chartered member-owned cooperative providing mortgage, housing, and community-development funding and liquidity to financial institutions.
3+ YOERequires 3–5 years in application security, information security, or DevSecOps; application assessments, secure SDLC, vulnerability remediation, web security, containers, IaC, programming, and strong communication skills.
SAST, DAST, SCA, Docker, Kubernetes, Python, Java, C#, JavaScript, PowerShell, REST APIs, Azure, AWS, GCP, Web Application Firewalls (WAF), OWASP Top 10, OWASP ASVS, OWASP SAMM, OWASP API Security Top 10, STRIDE, PASTA, SBOM, CI/CD, Git, Infrastructure as Code (IaC), API Security, Secrets Management
Abnormal Security: AI-native cybersecurity SaaS platform that protects enterprise email, identities, and cloud applications from socially engineered attacks.
5+ YOE5+ years in application security, cloud-native security experience, AI/ML security knowledge, programming in Python, Go, Java, or JavaScript/TypeScript, and expertise in web application security and threat modeling.
AWS, Python, Go, Java, JavaScript, TypeScript, OWASP Top 10, Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite, SOC 2, ISO 27001
Radnor or Charlotte or Fort Wayne or Greensboro or United States
$120k-$193k/yrRemoteFull Time
Lincoln Financial GroupNYSE: LNC: Public financial services providing annuities, life insurance, group protection, and retirement services to individuals and employers.
5+ YOEUndergraduate degree or 4+ years comparable experience; 5–7+ years aligned IT experience; extensive web application security, SDLC, Agile, DevOps security, and application testing experience.
IntelliDyne: Government IT consulting firm delivering technology services to federal and commercial clients.
5+ YOE5+ years Python development, Flask experience, web app deployment and security, authentication and certificate management, REST APIs, relational DBs, Git, HTML/CSS/JavaScript, strong debugging and communication skills.