Reston, VA

Salary
—
Posted
Aug 9, 2026
Location
Reston, VA
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

An Application Security Engineer role embedded in a cloud-native platform team delivering end-to-end budget traceability for a federal agency. The position integrates security across the full software development lifecycle — threat modeling, code review, SAST/DAST/SCA testing, vulnerability remediation, and DevSecOps pipeline automation — working alongside developers and cloud engineers on Oracle Cloud Infrastructure. Requires an active TS/SCI with polygraph and is fully onsite in Reston, VA.

Senior level · 8+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required · TS/SCI clearance · Contract

Must have (17)
PythonJavaScriptSQLShell scriptingPL/SQLSASTDASTKubernetesDockerRESTCI/CDOracle Cloud InfrastructureNIST RMFOWASPDISA STIGsOracle RDBMSAgile
Nice to have (4)
CISSP, Csslp, Giac, Ceh or OscpSecurity+IAMAI

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
Oracle Cloud Infrastructure4%PL/SQL6%Oracle RDBMS12%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
JavaScript62%Docker53%Python51%SQL51%CI/CD45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $152,225 (middle half $125,286–$177,673).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 11, 2026. It is a model, not a headcount.

Why we read it this way (10)

This role sits at the intersection of application security and software engineering; the SOC classification is Medium confidence. The primary day-to-day work is security analysis, testing, and DevSecOps integration (15-1212), but the strong hands-on coding requirements (Python, JavaScript, PL/SQL, secure code review) make 15-1252 Software Developers a credible alternative.

The posting describes this as 'an exciting new contract,' indicating a contract engagement rather than direct hire.

OCI experience is explicitly called 'desired' within the Required Qualifications section — a mild softener, but it remains in a required block; it is marked as required accordingly. OCI certifications appear separately under Preferred Qualifications and are marked preferred.

The NIST Secure Software Development Framework is listed alongside NIST RMF and OWASP; it is captured under NIST RMF as the closest canonical name rather than emitted as a separate entry, since it is part of the NIST family.

Master's degree is listed as preferred, not required; the hard minimum is a Bachelor's degree.

Secrets scanning and container/infrastructure vulnerability scanning are captured under SAST/DAST/SCA as part of the same application security testing requirement block rather than as separate skill entries, since they are listed as part of the same compound requirement.

AI experience (securing AI-enabled applications) appears only under Preferred Qualifications and is marked preferred.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secrets management.

Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗