> Markdown version of [/jobs/ext/1238240-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1238240-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** EPICSOFT CORPORATION - **Location:** Reston, VA, United States - **Experience:** Expert - **Salary:** $156,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Amazon Web Services, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, Software Vulnerability Management, Web Applications, Google Cloud, Cloud Platform System, Software Security, Kubernetes, Devsecops, Jenkins, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=903fd690da4bd0f9 ## About the Role * 7+ years of experience in Application Security or DevSecOps. * Strong knowledge of the Software Development Life Cycle (SDLC). * Hands-on experience with DevSecOps and Vulnerability Management. * Experience securing cloud environments (AWS preferred). * Experience with Cloud Security and AI Security. * Working knowledge of Java application development. * Deep understanding of: * OWASP Top 10 * API Security Top 10 * Secure Coding Practices * Common Web Application Vulnerabilities Experience with cloud security platforms such as: * Wiz * CrowdStrike * CNAPP * CSPM * CWPP * KSPM * Experience with Jenkins and CI/CD security. * Hands-on experience with: * SAST * DAST * IAST * SCA * Strong knowledge of: * Kubernetes * Amazon EKS * Container Security Preferred Qualifications AWS, Azure, GCP, or Application Security certifications. CISSP, CSSLP, Security+, or similar security certifications. Experience leading application security programs. * Excellent communication and stakeholder management skills. ## Description We are seeking an experienced Application Security Engineer to lead application security initiatives across modern cloud-native environments. This is a technical leadership role that requires close collaboration with software engineering teams to integrate security throughout the Software Development Life Cycle (SDLC). The ideal candidate will have strong expertise in DevSecOps, Cloud Security, AI Security, Kubernetes, vulnerability management, and application security testing. Responsibilities * Lead application security initiatives across the SDLC. * Partner with development teams to implement secure coding practices. * Identify, assess, and remediate application and cloud security vulnerabilities. * Integrate security into CI/CD pipelines using Jenkins and DevSecOps practices. * Perform application security reviews and threat modeling. * Conduct security testing using SAST, DAST, IAST, and Software Composition Analysis (SCA). * Implement cloud-native security controls for Kubernetes and containerized applications. * Collaborate with engineering teams to improve application and infrastructure security. * Support secure deployment of applications in AWS cloud environments. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)