Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Application Security Engineer

CertiPath

Want to energize your career?

At CertiPath, you'll join a fast-moving team with a meaningful mission, delivering high-assurance identity and trust solutions that matter. We are seeking a Senior Application Security (AppSec) Engineer to strengthen our security posture across our TrustSuite products, driving positive customer impact and rapidly innovating and optimizing application security across traditional and cutting-edge AI-enabled environments.

This high-impact role blends advanced offensive security (penetration testing) with adversarial emulation, threat modeling, and AI security expertise. You will serve as a senior technical SME, proactively identifying and exploiting vulnerabilities in applications before adversaries can. You will use both best-of-breed AppSec tooling and frontier AI systems, while defining and driving the strategic direction of application security across our scaling, mission-driven organization.

This role is approximately 60-70% hands-on with AI-enabled advanced penetration testing, 20% strategic planning and reporting, and 10% attack surface mitigation and threat modeling. You will operate autonomously, drive solutions, and think outside the box in a high-touch, high-consciousness environment with senior stakeholder support.


This is not a people-management role, but a deeply technical, hands-on position for senior engineers who love offensive security and advanced penetration testing while influencing application security architecture and strategy at the highest level.

Location : This role is primarily hybrid, based at our Reston, VA headquarters, with an average of 2-3 office days per week.


I've never heard of CertiPath. What do you do?


We are the experts in software and services for high-assurance digital identity verification and management. We are an established organization with a 21-year track record of delivering on our promises with the drive and entrepreneurial spirit of a start-up. CertiPath is focused on bringing facility and network access management for commercial clients and government agencies into the 21st century.


What will my responsibilities include as Senior AppSec Engineer at CertiPath?

  • Perform advanced penetration testing and security assessments on AI-enabled applications and traditional systems, with heavy focus on breaking code rather than writing it.
  • Lead application security strategy, including defining direction, applying and enhancing enterprise security standards, and conducting threat modeling on iterative designs and COTS applications.
  • Critically evaluate system and solution attack surfaces, architectures, and implementations for vulnerabilities.
  • Automate and enhance offensive security testing practices with a focus on Kubernetes environments, Linux systems, and AI-enabled CI/CD pipelines.
  • Deliver strategic reporting and risk assessments to leadership, as well as actionable recommendations to engineering teams.
  • Design and execute creative attacks with an adversarial lens to uncover vulnerabilities, injection attacks, supply chain and model poisoning, data leakage, and AI-specific risks.
  • Collaborate cross-functionally to embed strong application security practices while staying current with emerging technology, cloud, and AI threats.
  • Support go-to-market efforts for highly regulated environments.
What qualifications do you look for?
  • U.S. citizenship and the ability to obtain a government clearance.
  • 7+ years of experience in hands-on application security and penetration testing with recent focus on AI-enabled testing.
  • Senior-level offensive security background with proven comfort breaking applications through advanced penetration testing.
  • Certifications such as OSCP, GPEN, or similar advanced certifications (one or more).
  • Strong expertise in OWASP Top 10 (Web and LLM variants), enterprise security standards, ISO 27001 series, and FedRAMP.
  • Hands-on experience with commercial AppSec tools, including the Kali Linux and Burp Suite Professional tool kits.
  • Experience with Kubernetes, Python, cloud security, and memory-safe language best practices.
  • Demonstrated experience AI-enabled testing tools and technologies, using frontier AI capabilities (e.g. Anthropic Claude, xAI Grok).
  • Proven ability to define and drive high-level application security strategy and plans.
  • Excellent communication skills for reporting findings and influencing outcomes.
We're extra impressed by folks who have:
  • Experience performing security testing and assessments across multiple products and platforms (rather than a single product or system)
  • Prior experience testing in government or regulated environments

What kind of benefits does CertiPath offer?

CertiPath offers outstanding benefits, including health, dental, and vision coverage; a Health Savings Account plan; and a 401(k) plan with a generous employer match. We also believe strongly in maintaining a quality work-life balance, so we offer an unlimited PTO policy, seven company holidays, and a week-long break at the end of each year. All qualified applicants will receive consideration for employment without regard to disability; status as a protected veteran; or any other status protected by applicable federal, state, local, or international law.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior Application Security Engineer in Reston, VA vacancy
  •  ...and our customers' business challenges, Take2 will work as a partner to best resolve client needs.Take2 is hiring a Senior Application Security Engineer. This is a fully remote role.Job Description6+ years of Information Technology experience3+ years of experience with... 
    Senior
    Remote work

    Take2 Consulting, LLC

    Mc Lean, VA
    2 days ago
  •  ...public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a...  ...and more. Who we're looking for: We are seeking an Application Security Engineer with expertise in Static and Dynamic Application Security... 
    Suggested
    Contract work
    Remote work

    ShorePoint Inc

    Herndon, VA
    2 days ago
  • $160k

     ...VISA CANDIDATES FOR THIS ROLE! Required Qualifications: Minimum of 5 years experience working "hands-on" in application security engineering Hands-on experience with Fortify, Veracode, Tenable, Black Duck, or similar platforms Hands-on experience with... 
    Suggested
    2 days per week

    Griffin Global Systems Inc

    Herndon, VA
    12 days ago
  •  ...Design, develop, and optimize software applications that bridge technical teams and end-users...  ...scalable API architecture. Collaborate with engineers, stakeholders, and team members to...  ..., SOAP/XML, SFTP), with strong focus on secure authentication/authorization, robust... 
    Senior
    Internship
    Monday to Friday

    Navy Federal Credit Union

    Vienna, VA
    12 hours ago
  •  ...software solutions that enable military operators, national security agencies, spectrum regulators, and system integrators...  ...Summary CRFS seeks a versatile and proactive Senior Field Applications Engineer (FAE) to serve as the primary technical bridge between... 
    Senior
    Work at office
    Remote work
    Relocation
    Flexible hours

    Motorola Solutions

    Reston, VA
    12 hours ago
  •  ...Senior Product Security Engineer Mountain View, California, United States Company Overview ID.me is the next-generation digital identity...  ...remediation Execute vulnerability remediation workflows for application, container, Cloud, and SaaS vulnerabilities within... 
    Senior
    Full time
    Work at office

    ID.me

    McLean, VA
    3 days ago
  •  .... Since then, we have issued innovative bitcoin-backed securities and have been the leader in bitcoin treasury companies....  ...Description Join Strategy's IT Security group as a Senior Application Security Engineer and play a crucial role in safeguarding Strategy's... 
    Full time
    Work at office
    Shift work

    MicroStrategy

    Sterling, VA
    2 days ago
  •  ...modern technology, responsible AI, and secure infrastructure to some of the most complex...  ...with product managers and QA engineers on functional design and analysis of requirements...  ...clearance at the TS/SCI w/CI Poly level. Applicants must have the ability to obtain and maintain... 
    Senior
    Work experience placement

    Workday

    Reston, VA
    7 hours ago
  • $100k - $155k

    Overview As an Application Security Engineer , you will provide technical expertise and solutions to remediate persistent and challenging portfolio-wide vulnerabilities. We’re looking for someone who has passion for IT, resourceful problem‑solving abilities, and a desire... 

    Steampunk

    Mc Lean, VA
    2 days ago
  • A leading financial institution is seeking a Remote Engineer III for Hogan Applications, responsible for technical analysis, design, and implementation within a critical banking environment. Candidates should have extensive experience in Hogan architecture and application... 
    Senior
    Remote job

    PenFed Credit Union

    Mc Lean, VA
    1 day ago
  • $100k - $155k

    Steampunk is seeking an Application Security Engineer in McLean, Virginia. This role involves providing expertise to remediate vulnerabilities and uphold security practices across enterprise applications. Ideal candidates need to have experience in application security... 

    Steampunk

    Mc Lean, VA
    1 day ago
  • We have open role for " Application Support Engineer" for one our direct clients and it's W2 requirement. Interested candidates please share your resume to ****@*****.*** Location: Hybrid, McLean, VA Duration: Full-time Experience: 10+ years Required... 
    Senior
    Full time

    Zillion Technologies, Inc.

    Mc Lean, VA
    1 day ago
  • $168k - $252k

     ...months, not years. ABOUT THE JOB We're seeking a Product Security Engineer focused on the hardware side, not the digital logic or...  ...paths towards the future of defense technology. All qualified applicants will be treated with respect and receive equal consideration... 
    Senior
    Full time
    Work experience placement
    Local area
    Relocation package

    Anduril Industries

    Reston, VA
    more than 2 months ago
  • $163.8k - $245.8k

     ...modern technology, responsible AI, and secure infrastructure to some of the most complex...  ...with Product Managers and QA Engineers on functional design and analysis of requirements...  ...clearance at the TS/SCI w/CI Poly level. Applicants must have the ability to obtain and maintain... 
    Senior
    Full time
    For contractors
    Work experience placement
    Internship
    Work at office
    Local area
    Remote work
    Home office
    Flexible hours

    Workday

    Reston, VA
    1 day ago
  •  ...Embedded Systems Security Engineer Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both....  ...equivalent combination of related education and work experience. Applicants selected for this position will be subject to a US... 
    Senior
    Work experience placement
    Internship
    Local area
    Immediate start

    MITRE

    McLean, VA
    1 day ago
  • ## Job Description# Sr Applications Engineer**Location:** Falls Church, Virginia (Remote) **Employment Type:** Contract to Perm* Implement and...  ...Active Directory Services and manage application security, including Single-Sign-On and Certificate Management.* Ensure... 
    Senior
    Permanent employment
    Contract work
    Remote work

    Apex Systems

    Falls Church, VA
    4 days ago
  • $172k - $225.7k

     ...platform, Snowflake requires a secure-by-design foundation to...  ...The Security Applied Field Engineering (AFE) organization is at the...  ...than a bottleneck. As a Senior Security Architect on the Applied...  ..., and Infrastructure for applications built on Snowflake. AI... 
    Senior
    Flexible hours

    Snowflake Computing

    McLean, VA
    1 day ago
  •  ...Field Applications Engineer – Special Programs Reston, Virginia TrellisWare launched in 2000 with an innovative culture striving to push...  ...support to sales and business development leads in securing of new business, field troubleshooting of products and integrations... 
    Work experience placement
    Work at office
    Remote work
    Worldwide

    TrellisWare Technologies

    Reston, VA
    7 hours ago
  •  ...that enable military operators, national security agencies, spectrum regulators, and...  ...CRFS is seeking a Junior Field Applications Engineer who will report to the Manager of the...  ...The successful candidate will support senior engineers in technical customer engagement... 
    Permanent employment
    Work at office
    Local area
    Relocation
    Flexible hours

    Motorola Solutions

    Reston, VA
    12 hours ago
  • $3,000 per month

     ...Overview Acuity, Inc. seeks an  Application Engineer (Databricks Apps) to design, develop, and support data-driven applications that combine...  ...that expose analytics, workflows, and data products in a secure and scalable manner.  The Application Engineer translates... 
    Work from home

    Acuity

    Reston, VA
    1 day ago
  • $166.1k - $185.2k

     ...platforms. We leverage leading-edge secure systems and software development, backed...  ...is looking for a highly experienced Senior Navy Design Engineer with expertise in mechanical,...  ...any other characteristic protected by applicable law. If you are a qualified individual... 
    Senior
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Interim role
    Work at office

    Cydecor

    Reston, VA
    8 hours ago
  •  ...Job Description Job Description Senior Research Engineer, Video Compression About Ofinno: Ofinno is a leading research and development...  ...healthcare plans, including employer HSA contributions if applicable.  ~ Free Food -- Our kitchen is always fully stocked,... 
    Senior

    Ofinno

    Reston, VA
    4 days ago
  • $119.32k - $202.85k

     ...The Work: ICF is seeking an experienced and driven Software Security Engineer to lead and oversee mission-critical initiatives in support...  ...Agency (DCSA). In this role, you will help safeguard applications and cloud-based systems by integrating security best practices... 
    Senior
    Full time
    Contract work
    Work experience placement
    Work at office
    Immediate start
    Remote work

    ICF

    Reston, VA
    2 days ago
  •  ...Job Description Job Description Senior Staff Research Engineer, 3D Gaussian Splatting About Ofinno:  Ofinno is a leading research and development...  ...reproducible evidence, standards-ready proposals (as applicable), and patentable inventions. This role is hands-on and... 
    Senior

    Ofinno

    Reston, VA
    4 days ago
  •  ...the United States to intelligently plan and develop their applications, modernize their infrastructure and manage their data....  ...TrueTandem is seeking experienced, skilled, and passionate Senior Cloud Security Engineers to support enterprise-wide cybersecurity modernization... 
    Senior
    Local area

    True Tandem

    Reston, VA
    17 days ago
  •  ...Native owned corporation, our work helps secure an enduring future for our shareholders....  ...and work closely with system owners, engineers, and the ISSM to maintain authorization...  ...Equal Opportunity employers. All qualified applicants will receive consideration for employment... 
    Senior
    For contractors
    Work at office

    ASRC Federal Holding Company

    Reston, VA
    7 hours ago
  •  ...Job Description Job Description Senior Staff Research Engineer, Neural Network Video Coding About Ofinno: Ofinno is a leading research...  ...healthcare plans, including employer HSA contributions if applicable.  ~ Free Food -- Our kitchen is always fully stocked, including... 
    Senior

    Ofinno

    Reston, VA
    4 days ago
  •  ...Technology, we use Appian to run Appian. Our team builds the internal applications that keep the company moving-streamlining operations,...  ...showcasing what's possible on our own platform. As an Application Engineer, you'll design and deliver enterprise applications on Appian... 
    Work at office
    Local area

    Appian

    McLean, VA
    4 days ago
  •  ...commercial markets. Nightwing is seeking an experienced Security Product Reverse Engineer (RE) to support advanced security research and...  ...Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard... 
    Contract work

    Nightwing

    Sterling, VA
    12 hours ago
  • $190k - $235k

     ...seeking a highly skilled Cyber Research Engineer with deep technical expertise in Offensive...  ..., robust, and scalable offensive security software, tools, and frameworks, with an...  ...artificial intelligence concepts and their application to cybersecurity, including adversarial... 
    Full time

    Amatriot Group, LLC

    Reston, VA
    20 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!