> Markdown version of [/jobs/ext/1486150-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1486150-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** DecisionPoint Corporation - **Location:** Reston, VA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Amazon Web Services, Business Logic, Software System Penetration Testing, User Authentication, Automation of Tests, Cloud Computing Security, Cloud Engineering, Code Review, Cyber Security, Continuous Integration, Data Security, Identity and Access Management, Key Management, Log Analysis, Open Web Application Security, Secure Coding, Software Engineering, Systems Integration, SSL Certificate Management, Data Processing, Enterprise Software Applications, Software Security, Backend, Build Management, Kubernetes, Information Technology, Devsecops, Static Application Security Testing, Vulnerability Analysis, Web Api, Microservices, Dynamic Application Security Testing - **Published:** July 29, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17736604?backUrl=%2Fcareer%2F17736604%2FApplication-Security-Engineer-Virginia-Reston ## About the Role Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related technical field. Experience (Required) * Minimum 7 years of experience in application security engineering, secure software development, or cybersecurity. * Experience conducting code reviews, application penetration testing, or API security testing. * Experience with static and dynamic testing tools, dependency scanning, and software composition analysis. * Experience supporting secure CI/CD pipeline integration and DevSecOps practices. * Experience implementing secure secrets management, encryption, and authentication protections. Technical Knowledge (Required) * Strong understanding of OWASP Top 10, secure coding principles, and application-layer attack vectors. * Experience with SAST/DAST tools, dependency scanners, and code review workflows. * Knowledge of API security, token-based authentication, and secure data handling. * Familiarity with CMS structures, template security, and module-level risk considerations. * Understanding of identity and access management, certificate management, and secure authentication flows. Technical Knowledge (Preferred) * Experience with AWS cloud-native application security tools. * Familiarity with container security, Kubernetes workload protections, and microservices security. * Experience with modern CI/CD platforms and DevSecOps automation. Certifications Required: * Security+ or CISSP or CCSP Preferred: * AWS Security Specialty * GIAC secure coding or cloud security certifications * Certified Ethical Hacker (CEH) Skills * Strong analytical and problem-solving skills for identifying and remediating application-layer vulnerabilities. * Ability to clearly communicate technical risks, secure coding guidance, and remediation recommendations. * Strong attention to detail when reviewing code, configurations, and test results. * Ability to work collaboratively with developers, cloud engineers, PMO staff, and mission stakeholders. * Commitment to integrating security early and continuously throughout the development lifecycle. ## Description DecisionPoint seeks an Application Security Engineer to perform advanced application-layer security assessments, secure coding reviews, vulnerability analysis, and security integration for enterprise applications supporting a federal and DoD-aligned mission environment. This role ensures secure development practices across CMS components, APIs, integrations, CI/CD pipelines, and custom code. The Application Security Engineer supports secure coding standards, threat modeling, static and dynamic testing, and secure secrets management. This position plays a critical role in strengthening application-level defenses, reducing vulnerabilities, and ensuring mission systems meet stringent DoD security requirements. This position is fully remote., The Application Security Engineer will: Conduct secure code reviews, focusing on application logic, API endpoints, CMS modules, and backend integrations. * Perform API security assessments to validate authentication, authorization, data handling, and boundary protections. * Support CMS hardening by reviewing templates, modules, configurations, and custom components for secure implementation. * Integrate security requirements into CI/CD pipelines including SAST/DAST tools, dependency scanning, and automated controls. * Manage secrets handling, encryption policies, and secure storage of API keys, tokens, and credentials. * Conduct static and dynamic application security testing, vulnerability assessments, and remediation validation. * Provide secure coding guidance to developers, architects, and product teams. * Work with DevSecOps and cloud engineers to ensure secure build and deployment patterns. * Perform threat modeling and recommend mitigations for high-risk application features. * Review and validate authentication flows, SSO integrations, and identity-related protections. * Assist with security documentation including test results, remediation plans, and secure configuration records. * Support continuous monitoring, log analysis, and triage of application-layer security alerts. * Participate in sprint teams, code review cycles, and architecture discussions to embed security early. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Web APIs you might not know about](https://www.wearedevelopers.com/videos/281-web-apis-you-might-not-know-about) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)