Application Security Engineer Jobs in Virginia
Application Security Engineer jobs in Virginia are among the most active in the nation, concentrated in defense contracting, federal civilian agencies, financial services, and cloud infrastructure, with openings from entry-level analysts through principal engineers and architects. Northern Virginia, the Richmond metro, and the Hampton Roads area drive the majority of hiring, anchored by employers such as Booz Allen Hamilton, Leidos, and Northrop Grumman. The most in-demand specialties are cloud security, DevSecOps pipeline integration, and penetration testing with a focus on federal compliance frameworks. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 18+ Application Security Engineer jobs











Application Security Architect
All IT Solutions
United States · Richmond, VA
Workplace Type — Hybrid
Employment Type — Contract
We are currently seeking a qualified Application Security Architect to support this engagement. Please review the complete requirements, work location, employment type, and screening questions before applying. Candidates whose experience closely matches the position will be contacted directly by the AIS recruiting team.
Job Summary
All IT Solutions is seeking an Application Security Architect to join a client engagement.
Responsibilities
- Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem.
- Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs and ensure compliance with the client
- Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls
- Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection
Required Qualifications
- Must be local to the Richmond, VA area (onsite presence required)
- Software engineering, application security, security engineering, or related technical roles (10 Years)
- Experience in designing and implementing security architecture for IT systems (6 Years)
- Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse (6 Years)
- Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365) (6 Years)
- Demonstrated experience with threat modeling and security architecture reviews (6 Years)
- Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads (6 Years)
- Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices (6 Years)
- Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans (10 Years)
Preferred Qualifications
- Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired This role will be responsible for the solution of secure software development lifecycle program across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns.
- Experience in a regulated environment such as financial services, healthcare, government, or payments
- Experience conducting or coordinating penetration testing and translating results into durable architectural improvements
- Experience implementing DevSecOps programs and security automation at scale
- Familiarity with privacy engineering, data classification, and compliance frameworks
- Experience with security architectures in Esri's ArcGIS platform
ABOUT ALL IT SOLUTIONS LLC
Headquartered in Mount Laurel, New Jersey, All IT Solutions LLC is a technology and workforce solutions company serving government and commercial organizations throughout the United States. AIS provides IT staffing and staff augmentation, cybersecurity, IT consulting, custom software development, cloud services, data engineering, artificial intelligence, application development, and related technology solutions.
AIS is an NMSDC/EMSDC-certified Minority Business Enterprise and an NYC Department of Small Business Services-certified M/WBE. We participate in E-Verify and are committed to maintaining professional, transparent, and compliant hiring practices.
EQUAL EMPLOYMENT OPPORTUNITY
All IT Solutions LLC is an equal opportunity employer. Employment decisions are made based on qualifications, merit, performance, and legitimate business requirements without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, military or veteran status, or any other characteristic protected by applicable federal, state, or local law.
Reasonable accommodations are available to qualified applicants with disabilities during the application and interview process.
RECRUITMENT NOTICE
All IT Solutions LLC is a staffing and technology services company and may receive fees or compensation from client organizations for recruiting, staffing, placement, or workforce services. Candidates are never charged an application, recruitment, placement, or interview fee by All IT Solutions LLC.
Any commercial rates, fees, or staffing arrangements are between All IT Solutions LLC and its clients and do not require payment from the candidate.
Official recruiting communications will come from an authorized All IT Solutions representative or an @allitsolutions.us email address.
Apply
Apply Now: https://careers.allitsolutions.net/jobs/application-security-architect-2026-3fab2bd8/apply
See All 18 Application Security Engineer Jobs in Virginia
Find roles in Virginia that match your experience and apply in just a few clicks.
Find JobsApplication Security Engineer Jobs by City in Virginia
Where Virginia roles are concentrated, by current openings.
Application Security Engineer Job Market in Virginia
A snapshot from current Virginia openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Technology & Software
What Virginia Employers Look For
The qualifications that appear most often in application security engineer jobs across Virginia.
- Active security clearance or eligibility for a U.S. government clearance preferred by most Virginia employers
- Bachelor's degree in computer science, cybersecurity, or a closely related technical field
- Professional certification such as CISSP, CEH, or CompTIA Security+ recognized in Virginia federal and commercial roles
- Hands-on experience with SAST, DAST, and SCA tools integrated into CI/CD pipelines
- Working knowledge of NIST, FedRAMP, or CMMC compliance frameworks relevant to Virginia's federal contractor market
- Proficiency in at least one programming or scripting language such as Python, Java, or Go for security automation
Application Security Engineer Jobs in Virginia: Frequently Asked Questions
How do you become a application security engineer in Virginia?
Virginia does not require a state-issued license to work as an application security engineer, so the path runs through education and industry credentials. Most Virginia employers expect a bachelor's degree in computer science, information assurance, or cybersecurity, paired with certifications such as CISSP, CEH, or CompTIA Security+. Because a large share of Virginia roles support federal agencies or defense contractors, obtaining or being eligible for a government security clearance significantly broadens your opportunities in the state.
How much do application security engineers make in Virginia?
Application security engineers in Virginia earn a median of about $136,460 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $83,350 for the lowest 10% to over $211,930 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire application security engineers in Virginia?
Employers hiring application security engineers in Virginia right now include Esri, Cvent, and KPG99, based on current listings on Migrate Mate as of September 2026. Virginia's concentration of defense contractors, federal systems integrators, and financial technology firms means demand for application security engineers is consistent and distributed across multiple industry sectors throughout the state.
Which Virginia cities have the most application security engineer jobs?
Richmond, Reston, and Herndon have the most application security engineer openings in Virginia. Northern Virginia dominates because of its density of federal agencies, defense contractors, and cloud infrastructure campuses, while Richmond and Hampton Roads draw consistent demand from financial institutions, healthcare systems, and military installations that each maintain significant enterprise security teams.
Are there remote application security engineer jobs in Virginia?
Yes, and more than most fields. About 69% of application security engineer openings tied to Virginia are remote or hybrid as of September 2026, reflecting the desk-based and analytical nature of most application security work. Code review, threat modeling, and security tool configuration are the functions most likely to be performed fully remotely, while roles that require hands-on lab access or government facility presence tend to require at least partial on-site attendance.
How can I get hired as a application security engineer in Virginia with little or no experience?
The most realistic entry path is lateral movement from a software development or IT operations role, where existing coding or systems knowledge transfers directly into application security work. Large Virginia federal contractors such as Booz Allen Hamilton, SAIC, and ManTech run associate and junior analyst programs that accept candidates without dedicated security experience. Building a portfolio of CTF challenges and obtaining CompTIA Security+ or AWS Security Specialty gives early-career candidates a concrete credential edge in Virginia's clearance-driven market.
Where can I find and apply to application security engineer jobs in Virginia?
You can find and apply to application security engineer jobs in Virginia on Migrate Mate, which lists current Virginia openings updated regularly. Find the roles that fit your experience and target location, then apply directly to each position through the listing.
See All 18 Application Security Engineer Jobs in Virginia
Find roles in Virginia that match your experience and apply in just a few clicks.
Find Jobs