Application Security Engineer
$115k - $145kVeilant
Company Description We were early to the fight against Ubiquitous Technical Surveillance, and we've been pushing the edge ever since. Our mission is to help government and enterprise organizations understand and manage commercial data risks, shape their digital signatures, and operate with confidence in an increasingly complex information landscape. We build and integrate advanced, tech-forward solutions to problems our customers often don't know they have - until it matters most. We move fast, think critically, and deliver where it counts. What's in it for you? We work hard and do fun things. You'll work on high-impact, technically challenging problems alongside a team that values teamwork over competition. Veilant offers a solid work-life balance and flexible remote work options. At Veilant, you'll work with the most talented software developers, systems engineers, and subject matter experts, building tools and systems that make a real difference. Job Description Veilant is looking for an Application Security Engineer to join our InfoSec team and help validate, secure, and continuously improve software developed by internal and partner engineering teams. This role is ideal for someone who combines a software engineering foundation with an attacker mindset. You will review major and minor software releases before deployment, identify and validate vulnerabilities, create proof-of-concept demonstrations where appropriate, and provide practical remediation guidance that developers can act on. You will not simply file security tickets and move on. You will work closely with engineering teams to understand application architecture, business logic, user workflows, data sensitivity, and production environments so that your findings are accurate, contextualized, and useful. You will work collaboratively across Veilant's software, DevSecOps, and infrastructure teams. In this role, you will:
- Audit software releases across major and minor cycles to intercept and remediate security flaws before deployment.
- Analyze source code to identify, isolate, validate, and contextualize vulnerabilities in complex application codebases.
- Build safe proof-of-concept examples to demonstrate exploitation paths and verify the real-world impact of discovered risks.
- Contextualize findings based on application business logic, user workflows, data sensitivity, and production use cases.
- Author clear remediation guidance and partner with development teams to implement effective patches, controls, or architectural mitigations.
- Intercept and analyze application-layer network traffic using tools such as Burp Suite or similar intercepting proxies to inspect encrypted payloads, API calls, and authentication flows.
- Assess and help secure core architectures across REST APIs, SQL databases, PostgreSQL, JWT/OAuth, identity providers, and token-based authentication mechanisms.
- Perform threat modeling for web applications based on use cases, data flows, user roles, trust boundaries, and production environments.
- Improve DevSecOps pipelines by integrating, tuning, and operationalizing SAST, DAST, SCA, IaC scanning, secrets detection, and container security tooling.
- Support container runtime security efforts using monitoring and runtime protection tools such as Falco, NeuVector, or similar technologies.
- Create standardized security reporting that translates technical findings into clear risk narratives for both engineering teams and executive stakeholders.
- Ability to obtain a Security Clearance
- 2+ years of software development experience in Java.
- Hands-on experience reviewing or securing applications built with Java Spring Boot, Angular, REST APIs, SQL databases, and PostgreSQL.
- Working knowledge of authentication and authorization technologies, including JWT, OAuth, identity providers, Entra, Keycloak, and token-based access models.
- Experience intercepting, decrypting, manipulating, and analyzing web or application network traffic.
- Demonstrated ability to find, validate, and explain vulnerabilities in a real codebase.
- Familiarity with CI/CD tools such as GitLab CI, Azure DevOps, or GitHub Actions.
- Experience with containerized environments and orchestration tools such as Kubernetes.
- Exposure to infrastructure-as-code and container scanning tools such as Trivy, Kubesec, or similar technologies.
- Understanding of cloud hosting environments such as Azure or AWS.
- Familiarity with secrets management tools such as GitLab Secrets Manager, AWS KMS, Azure Key Vault, or Ansible Vault.
- Experience with automated application security testing, including SAST, DAST, and SCA.
- Familiarity with runtime security and monitoring tools for containers, such as Falco, NeuVector, or similar platforms.
- Hands-on web security testing experience using Burp Suite or comparable tooling.
- Strong written communication skills, including the ability to write reports for both technical and non-technical audiences.
- OSWE, OSCP, and/or GXPN certifications are highly desirable.
- Innovative Environment: Work in a setting where your ideas and expertise are valued.
- Collaborative Culture: Be part of a team that supports each other and works toward shared goals.
- Career Growth: Opportunities for professional development and career advancement.
- Flexible PTO + holidays
- Generous 401k match benefit up to 10%, with an automatic 3% safe harbor contribution and additional matching based on employee contributions.
- Medical (HSA & PPO Plans Available), dental, vision, disability, and life insurance
- Employer Contribution to Health Savings Account (HSA)
- Learning & Development opportunities
- Professional coaching services
- Get the technology you want to do your job
- We have free daily snacks & drinks
- Must be able to remain in a stationary position 50% of the time. The person in this position needs to occasionally move about inside the office
- Constantly work with computers and other information technology equipment
- The ability to communicate information and ideas in a classroom style format, may stand at a podium for long periods of time
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Application Security Engineer in McLean, VA vacancy
$155k - $185k
Responsible for leading application security engineering efforts, designing scalable security architectures, performing advanced risk assessments, integrating security across the SDLC, driving AI‑related security controls, evaluating vendor solutions, scaling automation...SuggestedFull time- ...What You'll Do: - Collaborate with a team of engineers to implement *** specific security policies in the CI/CD security tools including but not limited to SAST, DAST and SCA applications. - Work with Development, DevOps and Security teams to identify and develop...SuggestedWork experience placement
$92k - $123.9k
...Job Description Veilant is looking for an Application Security Engineer to join our InfoSec team and help validate, secure, and continuously improve software developed by internal and partner engineering teams. This role is ideal for someone who combines a software...SuggestedFull timeContract workWork at officeFlexible hours$90k - $110k
Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation... ...innovative security tools and a team of dedicated security engineers to protect our products throughout their lifecycle. Job Summary...SuggestedFull time- ...Location- Hybrid in Memphis, TN, Addison, TX, or McLean, VA. Rate- $80-90/hr . ON W2 As Senior Lead Engineer for Application Security Architecture team, you will work closely with application team to help implement security solutions that are tailored...SuggestedWork experience placement
- ...across the disciplines of program/project management, applications development, infrastructure, Cyber security, and enterprise content/data management services.... ...Requirements:Experience in software engineering with specialized experience in designing, developing...
$86.9k - $198k
Application Security EngineerThe Opportunity: Integrate security practices throughout the software development lifecycle to enhance and maintain... ...skillsMaster's degree in Cybersecurity, CS, Software Engineering, Information Assurance, or a related technical fieldCompensationAt...Full timeContract workPart timeWork at officeLocal areaRemote work$146k - $194k
...the military in months, not years.ABOUT THE TEAMThe Technical Security (TechSec) team within Anduril's Corporate Security Program... ...complex global landscape. ABOUT THE JOBThe Technical Security Application Engineer, Secured Spaces, is the technical authority for the design,...Full timeContract workWork experience placementImmediate start- ...Software Guidance & Assistance, Inc., (SGA), is searching for a Senior Application Security Engineer for a CONTRACT assignment with one of our premier Regulatory clients in Rockville, MD. The main function of senior application security engineer is to plan...Contract work
- ...Title: Application Security Engineer Location: Rockville, MD Hybrid local only Duration: 12 months Visa: USC , GC Application Security, Penetration Testing (Burp Suite), SAST/DAST/IAST, DevSecOps, AWS, OWASP, Java/Python/JavaScript, CI/CD...Local area
- ...Application Security Engineer ID 2025-3153 Job Locations US Category Information Technology Type Regular Full-Time Overview DecisionPoint seeks an Application Security Engineer to perform advanced application-layer security...Full timeFor contractorsLocal areaRemote work
- ...Title : Application Security Engineer Location : Rockville, MD or McLean, VA Target Start Date : ASAP Type : contract Pay Rate: DOE The Senior Application Security Engineer is responsible for designing, implementing, and advancing...Contract workImmediate start
- ...Application Security Engineer – Bot Detection & Traffic Routing We are seeking an experienced Application Security Engineer to support the detection, analysis, and mitigation of automated bot traffic across enterprise web applications. This role will focus on web application...
$110k
...Job Seekers can review the Job Applicant Privacy Policy by clicking here ( . Job Description : SUMMARY We seek a highly motivated and experienced Application Security Engineer to join our growing security team. This role is highly technical and candidates must...Full time$160k
...VISA CANDIDATES FOR THIS ROLE! Required Qualifications: Minimum of 5 years experience working "hands-on" in application security engineering Hands-on experience with Fortify, Veracode, Tenable, Black Duck, or similar platforms Hands-on experience with...2 days per week- ...Senior Application Security Engineer Come join our passionate team! Barracuda is a leading cybersecurity company providing complete protection against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed...WorldwideFlexible hours
- ...Job Title Must Have:- • Seeking candidates with solid expertise in manual web application penetration testing and manual secure code review. • Expertise in performing manual test case scenarios is a must. • Identification of vulnerabilities in source codes manually...
$150k - $173k
...resilience, and an unwavering commitment to our mission. About the role The Nuclear Company is searching for an Application Security Engineer to help secure the software, data systems, and developer workflows that power our Nuclear Operating System, internal...Bi-weekly payWork at office- A leading company in IT Services is seeking a Senior Application Security Engineer to enhance application security throughout the software development lifecycle. The role includes performing security assessments, integrating security practices into CI/CD pipelines, and...
- ...solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide.... ...challenges. Credence has an immediate opening for a Senior Applications Engineer who will be primarily responsible for supporting the...Temporary workWorldwide
- Vacancy: Application Engineer Location: Herndon/McLean, VA May 15, 2023General Information Location: Herndon/McLean, VA Salary: Salary range is commensurate with candidate’s qualifications and experience. How to Apply: Send your resume to ****@*****.*** specifying...
$75k - $175k
...Technology, we use Appian to run Appian. Our team builds the internal applications that keep the company moving—streamlining operations,... ...what’s possible on our own platform.As an Appian Application Engineer, you’ll design and deliver enterprise applications on Appian with...Work experience placementWork at officeLocal areaFlexible hours- ...About the job Application Cyber Security Engineer Application Cyber Security Engineer Location: Hybrid - DMV area (DC, MD, VA) | Monthly onsite in Reston, VA Company Overview Glint Tech Solutions is a women-owned global staffing and IT recruiting firm...Remote work
$89.6k - $218.2k
Senior Forward Deployed Application Engineer Position Description CGI Federal is seeking a Senior Forward Deployed Application Engineer... ...existing workflows; the primary focus is building maintainable, secure, integrated solutions. This position is located in...Local area- ...have excellent communication skills, both verbal and written (in English). Good to have experience with working on front end applications using JavaScript, JQuery, AngularJS and Bootstrap. Experience in working with API Management Tools. Experience in working...
- ...not provide sponsorship for this role. Applicants must be authorized to work in the United... ...future sponsorship. The Application Engineer is responsible for the end-to-end ownership... ...to deliver reliable, scalable, and secure solutions that meet organizational needs...InternshipMonday to Friday
$62.9k - $153.3k
Forward Deployed Application Engineer Position Description CGI Federal is looking for a Forward Deployed Application Engineer to deliver... ...upon specific assignment and/or level of US government security clearance held. Dependent upon role and/or federal government...Local area- ...POLY Required **About the Role:** Join our team as a Security Product Reverse Engineer to analyze and audit security products, focusing on... ...implementation of CNE techniques and methodologies, including application and mitigation for BSD/Linux/Unix, Windows, Mac OS,...
- ...not provide sponsorship for this role. Applicants must be authorized to work in the United... ...proficiency, strong operational engineering capabilities, cloud infrastructure expertise... ...resolution, and own the technical health, security posture, and service performance of a...InternshipMonday to Friday
- ...skills and experience managing complex programs in a litigation environment. Responsibilities include developing and maintaining applications, translating requirements, and refining programs to enhance efficiency. The role requires substantial programming experience and...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!
Related searches
- senior application security engineer McLean, VA
- application performance engineer McLean, VA
- application engineering manager McLean, VA
- senior application support engineer McLean, VA
- senior app developer McLean, VA
- software applications developer McLean, VA
- senior application developer McLean, VA
- app developer McLean, VA
- entry level security engineer McLean, VA
- IT security engineer McLean, VA


