> Markdown version of [/jobs/ext/1039359-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1039359-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** US Tech Solutions, Inc. - **Location:** Arlington, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Burp Suite, Code Review, Cyber Security, Continuous Delivery, Continuous Integration, DevOps, Gradle, Mobile Application Software, Apache Maven, Objective-C (Programming Language), Open Source Technology, Open Web Application Security, Systems Development Life Cycle, Cloud Services, Fortify (Software), Secure Coding, Web Application Security, Security Software, Software Engineering, Scripting, ReactJS, Sonatype, Software Security, Swift (Programming Language), Veracode, Kotlin, Kubernetes, Tenable Nessus, Checkmarx, Puppet, Devsecops, Docker, Jenkins, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** June 22, 2026 - **Apply:** https://dejobs.org/x/x/DAC342456DD341C890B1A70661A2726E/job/ ## About the Role * Bachelor's degree with minimum 8 years of work experience in the IT field * 3+ years software development experience using Java, JavaScript * 3+ years of experience in the following: * OWASP Secure Coding Practices * Common software and web application security vulnerabilities * Application security scanning tools * Continuous Integration/Continuous Deployment (CI/CD) processes and concepts using relevant technologies and tools (e.g., Jenkins) * Experience in Python scripting Even Better If You Have * A degree in Cybersecurity or CISSP/CSSLP certification or keen desire to move to security field * Business acumen to support the implementation of SAST or DAST or IAST across the enterprise * Ability to perform code reviews with minimal assistance * A self-starter, with a strong desire for learning new technologies and applying them to solve problems * Experience with two or more of the application build environments like Jenkins, Gradle, Maven. * Familiarity with public cloud services a plus * Experience with two or more of the Secure SDLC tools like Burp Suite, Fortify, Checkmarx, AppSec SE, Veracode, WhiteSource, Sonatype * Experience with Threat Analysis. * Experience with DevSecOps, Secure SDLC. * DevOps container/orchestration tools (Kubernetes, Docker, Puppet, etc) is a plus * Experience with evaluation, integration and onboard of security tools such as RASP, WAF, vulnerability scanner results, container analyzers, open source scanning etc is a plus ## Description * Collaborate with a team of engineers to implement *** specific security policies in the CI/CD security tools including but not limited to SAST, DAST and SCA applications. * Work with Development, DevOps and Security teams to identify and develop automated security and compliance capabilities in support of DevOps processes. * Define the security rules that needs to be adhered to at a code level in web and mobile applications written in Java, React, Objective C, SWIFT, Kotlin etc. * With your development background and security knowledge, provide security guidance to developers in the form secure coding standards and guidelines. * Support security standards, create templates and patterns to increase the efficiency and adoption of security program. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Modular Secrets to Lightning-Fast Android Builds](https://www.wearedevelopers.com/videos/1428-modular-secrets-to-lightning-fast-android-builds) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Kotlin Multiplatform - True power of native code reuse](https://www.wearedevelopers.com/videos/4-kotlin-multiplatform-true-power-of-native-code-reuse) - [Moving from Java to Kotlin](https://www.wearedevelopers.com/videos/384-moving-from-java-to-kotlin) - [Introducing Kotlin Multiplatform in an existing project](https://www.wearedevelopers.com/videos/276-introducing-kotlin-multiplatform-in-an-existing-project) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers)