Application Security Engineer

Leidos

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
Ashburn, VA
Salary
$107,900–$195,050 / yr
Posted
60 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $177k
This role $151k
$95k most similar roles pay here $229k

This role pays less than 69% of similar roles. Most pay $145,525–$208,800 — the shaded band above. At the midpoint, this role pays about $151k versus about $177k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 264 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 245 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Application Security Engineer

The Application Security Engineer joins the Cyber Security Directorate Security Operations Center to protect enterprise-wide information systems from cyber threats across networks, cloud environments, and mobile devices. This role involves managing application security operations, configuration management, and vulnerability remediation while integrating security best practices into the software development life cycle. Key responsibilities include monitoring applications for critical incidents, conducting market research for new solutions, and integrating machine learning and artificial intelligence into the security tool suite. The candidate will utilize SAST tools to analyze source code, perform DAST assessments using Microfocus WebInspect, and manage container security via Anchore. Required skills include experience with SCA, secure coding practices, and programming or scripting. Technical competencies involve Kubernetes, Rancher, Cloudera, Salt, Ansible, Elasticsearch, and Gitlab within an Agile environment to ensure systems comply with Security Technical Implementation Guides.

What you'll do

  • Monitor managed applications and implement alerting systems for critical security incidents.
  • Integrate Machine Learning and Artificial Intelligence into the existing security tool suite.
  • Embed security best practices into the software development life cycle from design to deployment.
  • Analyze source code using SAST tools and conduct dynamic assessments using DAST tools.
  • Manage container security tools and provide recommendations for secure container orchestration.
  • Ensure systems and applications comply with Security Technical Implementation Guides.
  • Maintain configuration management for application systems and their associated configuration items.
  • Tune logging capabilities to improve efficiency and identify necessary technology improvements.

What we're looking for

  • Must have a Top Secret clearance with SCI.
  • Bachelor's degree in Information Technology, Software Engineering, or a related field.
  • 8 to 12 years of prior relevant experience.
  • At least 3 years of experience in application security focusing on SAST, SCA, and DAST.
  • Knowledge of secure coding practices and integration into the software development life cycle (SDLC).
  • Familiarity with common security frameworks and standards.
  • Strong programming and scripting skills.
  • Ability to work in an Agile project management environment.

More like this

Similar roles

Senior Application Security Engineer

AbbVie

Chicago, IL 42 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation OWASP Top 10 CWE CSPM Snyk Endor Labs
7+ yrs exp

Senior Application Security Engineer

AbbVie

Irvine, CA 42 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation CSPM Snyk Endor Labs OWASP Top 10 CWE
7+ yrs exp

Application Security Engineer

State Street

Quincy, MA +4 14 days ago $120,000$202,500
AppSec DevSecOps SAST DAST SCA CI/CD Python Java .Net Node.js AWS Azure Kubernetes Terraform Ansible Infrastructure as Code Agile SDLC API Security Container Scanning
6+ yrs exp

Application Security Engineer

State Street

Quincy, MA 45 days ago $100,000$167,500
AppSec DevSecOps SAST SCA DAST CI/CD Python Java .Net Node.js AWS Azure Kubernetes Terraform Ansible Infrastructure as Code Agile SDLC Container Security
6+ yrs exp

Application Security Engineer

Opendoor

Toronto, Canada 85 days ago
Go Python TypeScript Ruby Terraform AWS GCP Azure Kubernetes GraphQL Apollo GitHub Advanced Security CodeQL Semgrep HackerOne Burp Suite Cloudflare WAF Claude OpenAI REST gRPC Threat Modeling
5+ yrs exp Hybrid

Application Security Engineer

Opendoor

Miami, FL 85 days ago
Go Python TypeScript Ruby Terraform AWS GCP Azure Kubernetes GraphQL Apollo GitHub Advanced Security CodeQL Semgrep HackerOne Burp Suite Cloudflare WAF Claude OpenAI REST gRPC Threat Modeling
5+ yrs exp Hybrid