EngineerJobs.io
← Back to all jobs

Job Description

Join a team focused on building resilient security for business-critical applications. In this onsite role in Washington, DC, you will partner with clients and development teams to strengthen application security across the software development lifecycle through testing, threat modeling, vulnerability remediation, and security guidance.

Working with application owners and security teams, you will help identify risks early, prioritize fixes, and support secure development practices. You will also stay current with emerging threats and help translate security requirements into practical controls that improve the security posture of high-visibility applications.

What You’ll Do

  • Collaborate with clients, application owners, and development teams to maintain a resilient security posture for highly visible, business-critical applications.
  • Partner with application security teams to identify, prioritize, and remediate application security vulnerabilities across the software development lifecycle.
  • Lead security discussions with application teams and provide guidance on secure development practices, security requirements, and application security best practices.
  • Conduct application security testing and assessments, including SAST, DAST, threat modeling, and application-level security assessments using tools such as Veracode and Burp Suite DAST.
  • Apply current OWASP framework, standards, and best practices to identify risks and strengthen application security.
  • Monitor emerging application security threats and vulnerabilities, supporting development teams as they implement security controls and remediation strategies.

Required Qualifications

  • 6+ years of experience with information technology, and cybersecurity or application security.
  • 3+ years of experience with Java, Python, .NET, or C#.
  • 3+ years using Burp Suite DAST to perform DAST.
  • 3+ years designing and implementing enterprise-wide security controls to secure applications, systems, networks, or infrastructure services.
  • 3+ years experience with Linux or UNIX environments, including system navigation and troubleshooting basic website connectivity issues.
  • 2+ years of experience with Veracode and development environments such as Eclipse and JDeveloper, including pipeline development and integration.
  • Experience securing enterprise web applications and frameworks, including OWASP Top 10, CVSS, CWE, WASC, and SANS-25.
  • Knowledge of federal security and compliance standards, including NIST 800-53, FIPS, or FedRAMP.
  • Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements.
  • HS diploma or GED.

Technologies You’ll Use

  • Java, Python, .NET, C#, SAST, DAST
  • Burp Suite DAST, Veracode
  • OWASP, OWASP Top 10, CVSS, CWE, WASC, SANS-25
  • Eclipse, JDeveloper
  • NIST 800-53, FIPS, FedRAMP

Benefits

  • Health, life, disability, financial, and retirement benefits
  • Paid leave
  • Professional development
  • Tuition assistance
  • Work-life programs
  • Dependent care
  • Recognition awards program that acknowledges employees for exceptional performance and superior demonstration of company values
  • Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs

Nice If You Have

  • Experience with Interactive Application Security Testing (IAST) capabilities and tools

Work Model and Eligibility

  • Onsite: work will primarily be performed full-time at a customer facility, collaborating directly with colleagues and customers as required by the role.
  • Employees working virtually are generally expected to have their cameras on during meetings.

Vetting

  • Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client.

Compensation

The projected compensation range is $62,000.00 to $141,000.00 (annualized USD). The estimate represents the typical salary range and is one component of Booz Allen’s total compensation package.

This posting will close within 90 days from the Posting Date.

Additional Candidate Notes

  • Identity verification process may include advanced biometrics and artificial intelligence.
  • You are expected to be on camera during interviews and assessments.
  • AI use to assist with responses during interviews (in-person or virtual) is prohibited unless permission is explicitly provided.
  • Commitment to non-discrimination: qualified applicants will receive consideration without regard to protected statuses under applicable law.

Similar Jobs