Demo

Application Security Engineer

Astyra Corporation
Richmond, VA Full Time
POSTED ON 5/3/2026
AVAILABLE BEFORE 6/2/2026
Application Security Engineer*Local to Richmond, VA only please*This is a primarily remote position with occasional onsite requirements*This is a 6-month contract position Description:The client is seeking an Application Security Engineer (ASE) with 5 years of experience to join the Office of Technology under Joint Security Operations. In this role the ASE serves as a dedicated security partner to application teams providing guidance on secure design vulnerability management and secure development practices. The ASE works collaboratively across the SDLC to ensure security is embedded into application design development testing and deployment. This includes supporting compliance requirements delivering training and education and assisting teams with vulnerability remediation efforts.The successful candidate will identify and recommend improvements to improve the security of all the clients’ applications promote secure coding and development practices and contribute to ongoing initiatives that reduce risk and strengthen the agency’s overall security posture.Responsibilities:Provide security guidance training and best practices for development and operations teams.Support secure software development by applying knowledge of SDLC Agile and Scrum methodologies.Evaluate software architecture and design for security risks and alignment with DevSecOps principles.Promote and enforce secure coding standards and guidelines.Review source code to identify vulnerabilities and recommend remediation strategies.Assess security risks across multiple programming languages e.g. JavaScript C# Java Ruby SQL.Analyze and secure modern web application architectures including cloud APIs microservices and client-server models.Identify and address common vulnerabilities including those outlined in the OWASP Top 10.Support vulnerability remediation patch management and continuous improvement efforts.Utilize application security testing tools such as SAST DAST IAST and platforms like Accunetix Veracode Jenkins Splunk Rapid7 and Tenable.Interpret and act on findings from SIEM systems including Splunk.Apply knowledge of common security controls and frameworks.Ensure compliance with relevant security regulations and standards e.g. NIST 80053 IRS Pub 1075 PCIDSS.Implement and evaluate AWS cloud security controls and best practices.Create maintain and review System Security Plans SSPs.Troubleshoot and resolve complex technical and security-related issues.Stay current with evolving threats technologies and industry trends.Develop detailed plans and communicate risks impacts and recommendations effectively.Collaborate with application teams QA engineers and operations teams to integrate security into workflows.Provide constructive actionable feedback to application teams.Communicate technical concepts clearly to both technical and nontechnical audiences.Work closely with other security analysts and technology teams to support agency and enterprise security initiatives.Manage multiple tasks prioritize effectively and meet deadlines.Apply critical thinking to evaluate and mitigate security risks and vulnerabilities.Skills/Knowledge/Experience:Five or more years experience in application security.Two or more years network or firewall/AWS Security Groups.Experience with log collection vulnerability scans and remediation or privileged access management.Strong understanding of security concepts network protocols and threat vectors.Proficiency in SIEMIDS/IPS EDRand other relevant security tools.Excellent analytical and problem-solving skills.Strong communication collaboration and documentation skills.Ability to work independently and as part of a team in a fast-paced environment.Splunk Insigh tVM Rapid7 Tenable CyberArk Jenkins VeracodeLinux and Windows Operating Systems Baseline hardening of operating systemsIIS and Apache Scripting Languages and SQL PowerShell FirewallAt least one of the following certifications is required:CompTIA SecurityISC2 CC Certified in CybersecurityOffensive Security Certified Professional OSCPCCSP Certified Cloud Security ProfessionalCSSLP Certified Secure Software Lifecycle ProfessionalDesired Certifications:AWS Solutions Architect Associate/ProfessionalAWS Security SpecialtyCompTIA PenTestCertified Ethical Hacker CEH GIAC Certified Intrusion Analyst GCIARequired Skills/Knowledge/Experience:Application Security, Required 5 YearsNetwork or Firewall/AWS security Groups, Required 2 YearsInfrastructure as Code (IaC): Advanced proficiency in Terraform for multi-account landing zones and automated provisioning., Required 2 YearsExperience with log collection, vulnerability scans and remediation, or privileged access management, Required 4 YearsProficiency in SIEM, IDS/IPS, EDR, and other relevant security tools., Required 4 YearsNetworking & Hybrid Connectivity: Solid understanding of routing, firewalls, AWS Direct Connect, and VPNs in a hybrid cloud environment., Required 4 YearsOne REQUIRED: CompTIA Security , ISC2 CC (Certified in Cybersecurity), Offensive Security Certified Professional (OSCP), CCSP, or CCLP. UPLOAD COPY!!, RequiredCI/CD & DevOps: Experience with GitLab CI/CD, Jenkins, or AWS CodePipeline for automated, secure deployments., Highly desired 5 YearsSplunk, InsightVM Rapid7, Tenable, CyberArk, Jenkins, Veracode, Highly desired 2 YearsLinux and Windows Operating Systems, Baseline hardening of operating systems, Highly desired 2 YearsIIS and Apache, Scripting Languages and SQL, PowerShell, Firewall, Highly desired 2 YearsOne highly DESIRED (Independently and or with one of the above): AWS Solutions Architect (Associate/Professional) or AWS Security Specialty, Highly desiredOne of these is DESIRED: CompTIA PenTest , Certified Ethical Hacker (CEH), or GIAC Certified Intrusion Analyst (GCIA), Highly desiredProper email communication will only be done to and from @astyra.com email addresses. Please ensure you are communicating with approved Astyra recruiters by checking this point when receiving offers and messages from us. Please ensure you are communicating within these guidelines and proper channels for the quickest possible interview consideration!#AC

Salary : $66 - $68

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Application Security Engineer?

Sign up to receive alerts about other jobs on the Application Security Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$88,984 - $115,784
Income Estimation: 
$111,369 - $141,168
Income Estimation: 
$117,871 - $153,580
Income Estimation: 
$109,939 - $144,341
Income Estimation: 
$114,500 - $144,633
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Astyra Corporation

  • Astyra Corporation Indianapolis, IN
  • Job Summary The purpose of this position is to utilize clinical expertise to review medical records against established criteria in accordance with contrac... more
  • 1 Day Ago

  • Astyra Corporation Raleigh, NC
  • Lead EDI Specialist *This is an onsite position – Local to Raleigh, NC only please *This is a 4-month contract position Description: The client is seeking ... more
  • 1 Day Ago

  • Astyra Corporation Richmond, VA
  • Systems Administrator *This is an onsite position – local to Richmond, VA only please *This is a 6-month contract position Description: The client seeks 2 ... more
  • 2 Days Ago

  • Astyra Corporation Harrisburg, PA
  • Azure DevOps Engineer *This is a hybrid position with 2 days/week onsite for the first 3 months, followed by 1 day/month onsite, or as needed, for the rema... more
  • 2 Days Ago


Not the job you're looking for? Here are some other Application Security Engineer jobs in the Richmond, VA area that may be a better fit.

  • Virginia Jobs Richmond, VA
  • Title: Application Security Engineer State Role Title: Info Technology Specialist III Hiring Range: Commensurate with experience Pay Band: 6 Agency: Depart... more
  • 2 Days Ago

  • Vector Consulting, Inc Richmond, VA
  • Our government client is looking for an Application Security Engineer on a hybrid 6 months renewable contract role in Richmond, VA. Position – Application ... more
  • 24 Days Ago

AI Assistant is available now!

Feel free to start your new journey!