Application Security Engineer
Application Security
Data Security
DevOps
DevSecOps
Facilities Management
Identity and Access Management
Information Security
InfoSec
Project Management
Risk Management
Secure Software Development Lifecycle
Security
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Software Security
Job Description
Booz Allen Hamilton is hiring an Application Security Engineer to help integrate security throughout the software development lifecycle and strengthen the security posture of software products. The role applies advanced consulting skills to drive security activities such as assessments and architecture reviews, while also mentoring teammates and supervising security workstreams.
Role Focus
- Integrate security practices across the SDLC to enhance and maintain software security posture
- Use advanced consulting skills and extensive technical expertise to support security initiatives end to end
- Develop innovative solutions to complex security problems
- Operate with limited direction while mentoring and supervising team members
Key Responsibilities
- Lead security activities including assessments and architecture reviews
- Mentor and supervise team members during security work
- Apply industry-wide knowledge to improve security outcomes for software
Requirements
- 5+ years of experience in cybersecurity, application security, product security, or software engineering
- Experience implementing or assessing Secure SDLC and application security programs, including leading client engagements, managing multiple priorities, and performing architecture reviews, threat modeling, or security assessments
- Experience with software supply chain security concepts, including SBOMs, dependency management, code signing, artifact integrity, and secure build pipelines
- Experience implementing or evaluating application security tools such as SAST, DAST, SCA, IaC scanning, container security, API security, secrets detection, and software composition analysis
- Experience with Agile, Scrum, and DevSecOps operating models in large-scale software development environments
- Knowledge of secure software development principles and modern application architectures, including cloud-native, microservices, APIs, containers, Kubernetes, and serverless environments
- Knowledge of authentication, authorization, cryptography, API security, and cloud security
- Knowledge of vulnerability management processes, risk prioritization methodologies, and remediation workflows
- Ability to translate complex technical risk into executive-level briefings, business cases, actionable roadmaps, and effective communication with technical and executive stakeholders
- Bachelor's degree in CS, Cybersecurity, Information Systems, or Engineering
Technologies
- SBOMs, SAST, DAST, SCA, IaC scanning
- Container security, API security, secrets detection, software composition analysis
- Agile, Scrum, DevSecOps
- Microservices, Kubernetes, cloud-native, serverless environments
- Authentication, authorization, cryptography, secure build pipelines
Nice If You Have
- Experience designing or maturing enterprise application security and product security programs
- Experience with secure development requirements for regulated industries such as healthcare, financial services, industrial control systems, automotive, aerospace, or critical infrastructure
- Experience with industry frameworks including OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, and MITRE ATT&CK or ATLAS
- Experience developing technical proposals, responding to RFPs, creating Statements of Work (SOWs), and supporting business development initiatives
- Experience leading executive workshops, stakeholder interviews, and technical design sessions
- Ability to mentor junior team members, provide technical leadership, and contribute to practice development and thought leadership
- Ability to travel up to 50% of the time, depending on client needs
- Excellent written and verbal communication skills
- Excellent facilitation skills
- Master's degree in Cybersecurity, CS, Software Engineering, Information Assurance, or a related technical field
Identity and Interview Requirements
- You are expected to be on camera during interviews and assessments
- Booz Allen reserves the right to take your picture to verify your identity and prevent fraud
Candidate AI Usage Policy
- Use of artificial intelligence (AI) or other tools to assist with responses during interviews (in-person or virtual) is prohibited unless permission is explicitly provided
Work Model and Location
- Location: Annapolis Junction, MD (onsite)
- Work is primarily performed at a Booz Allen office or customer facility
- Employees working virtually are generally expected to have their cameras on during meetings
Compensation
- Salary range: USD 86,900 - 198,000 per yearly
Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.