> Markdown version of [/jobs/ext/2791841-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2791841-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Maxar Intelligence Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $180,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Software System Penetration Testing, User Authentication, Static Program Analysis, Data Security, Node.Js, Open Source Technology, Systems Development Life Cycle, Reliability Engineering, Secure Coding, Software Vulnerability Management, Data Logging, Software Security, Nessus, Web Architecture, Qualys, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 8, 2026 - **Apply:** https://www.careerjet.com/job/register/us2ac4ca23367be627d54317020f5f4057 ## About the Role automate where we can (even if we have to code and build it). If you are excited rather than scared by highly technical problems, we are offering a security role where you can learn and grow while having direct impact in continuing to harden a security critical mission. As an Application Security Engineer, your responsibilities will include: - Security Engineering - Collaborate with development teams, Site Reliability Engineering, and other stakeholders to strengthen the adoption of security best practices throughout the SDLC. - Independently identify security improvements and implement them. - Vulnerability Management: - Implement, manage, and automate vulnerability management processes. - Prioritize and remediate vulnerabilities discovered through internal scans, penetration tests, and bug bounties. - Security Assessments - Conduct threat modeling, code audits, design reviews with engineers to ensure effective and secure development. - Collaborate in providing actionable recommendations to find workable solutions. - Threat Hunting: - Establish a threat hunting capability and automate where appropriate. - Enhance logging capabilities related to security events. - Security Tools Integration and Management: - Integrate and manage dynamic and static code analysis tools. - Ensure operation of security tools within the development pipeline. Skills that will help you thrive in this role: - 4+ years experience in secure development or application security. - Deep knowledge of security concepts such as authentication, web architecture, etc. - Experience with Nodejs, Go, etc. - Experience running bug-bounty, penetration testing, vulnerability scanning programs. - Experience setting up and maintaining SAST, DAST, IAST and SCA tooling - Experience using assessment tools such as Burp, ZAP, Qualys, Nessus, etc. - Experience building and maintaining WAF solutions. ## Description government agencies discover that true data security means having the freedom to share, collaborate, and innovate - without compromise. Compensation: $180,000 - $200,000/year Team & Position Details: Here at Virtru you'll join an innovative product security team that is helping secure some of the world's most important information. Our platform, built on an open source core, functions in a wide range of threat models. As an application security engineer you will help our engineering teams maintain and develop our product, and directly have impact in a security centric company and product. An ideal candidate is prepared to operate in a public and open source form, in addition to being able to review complex systems and product requirements. You should have a strong foundation in the fundamentals of cryptography, and be able to talk and collaborate with development teams. Our applications are primarily built in Go and Javascript. We use a range of security tools, and aggressively ## Related Videos - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Why Security-First Development Helps You Ship Better Software Faster](https://www.wearedevelopers.com/videos/1568-why-security-first-development-helps-you-ship-better-software-faster) - [Building AI Applications with LangChain and Node.js](https://www.wearedevelopers.com/videos/1512-building-ai-applications-with-langchain-and-node-js) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)