Sr. Application Security Engineer
Environmental Systems Research InstituteSr. Application Security Engineer
Environmental Systems Research InstituteLocation
Vienna, VA, Redlands, CA
Type
Full-time
Posted
9/2/2026
Compensation
$93,600 per year
Job description
As an Application Security Engineer at Esri, you will play a vital role in securing the company's intellectual property and sensitive data. You will collaborate with various teams, including application development and DevSecOps, to integrate security into applications from the outset. The position focuses on application security testing, vulnerability remediation, and providing guidance to development teams. This role offers an opportunity to work in a technology-oriented environment that values collaboration and continuous improvement.
Requirements
- 5+ years of experience in application security, including manual and automated code reviews, manual penetration testing, dynamic application security testing, and false positive analysis.
- Demonstrated experience determining risk based on analysis/findings using a consistent risk management framework.
- Proven ability to develop automations/applications using Python, Typescript, Java, or PowerShell.
- Experience creating and maintaining reusable GitHub Actions workflows, with expertise in all aspects of GitHub workflow management.
- Hands-on experience working in a DevSecOps environment built on Kubernetes with a strong knowledge of Kubernetes security best practices.
- Ability to read and analyze code for security and design vulnerabilities.
- Solid understanding of common web application security standards such as HTTP, OAuth, OIDC, and REST.
- Experience working with cloud platforms, specifically AWS and Azure.
- Willingness to learn new skills and enhance workflows using various AI tools.
- US citizenship and willingness and ability to maintain a US Security Clearance.
- Bachelor’s degree in computer science or related field.
Responsibilities
- Design, operate, and continuously improve application security testing capabilities and pipelines.
- Assess application risks and recommend mitigations.
- Perform application layer security reviews of the code developed by application teams across multiple languages and frameworks.
- Assist with application layer penetration testing to identify potential issues.
- Provide application security guidance and mentorship to development teams as needed.
H-1B filing history
Public USCIS petition and DOL LCA counts · latest USCIS FY2026, LCA FY2026
Filing entity: Environmental Systems Research Institute Inc
As of Aug 23, 2026
Initial approvals
44
FY2026
Approval rate
98.9%
FY2026
LCA certified
67
FY2026
Entry-level share
49.3%
FY2026
Initial approvals YoY
+3%
Trend
LCA certified YoY
-31%
Trend
Initial approvals by fiscal year
Approval rate by fiscal year
Continuing vs initial approvals
LCA certified positions by quarter
LCA certified positions by fiscal year
Based on public USCIS and DOL filings; not a sponsorship guarantee.
Is this posting expired or inaccurate?
