Senior Application Security Engineer
Job Description
Lead enterprise application security testing and integrated system security improvements in a remote role.
Responsibilities
- Engineer and optimize integrated systems that support enterprise-wide digital transformation initiatives
- Design end-to-end solutions to improve system reliability, scalability, and security
- Evaluate new technologies and system architectures, then provide strategic recommendations to strengthen organizational capabilities
- Focus on Burp Enterprise for DAST scanning to support enterprise-wide application security testing
Requirements
- Ability to obtain and maintain a Public Trust Clearance, requiring U.S. citizenship
- 1+ year experience supporting Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE plug-in environments using Veracode
- 2+ years experience with Java, Python, .NET, or C#
- 3+ years experience designing and implementing enterprise-wide security controls to secure applications, systems, network, or infrastructure services
- Experience with Eclipse and JDeveloper, including pipeline development, or Visual Studio experience securing enterprise web applications
- Working knowledge of OWASP Top 10, CVSS, CWE, WASC, and SANS-25
- Knowledge of federal compliance standards including NIST 800-53, FIPS, or FedRAMP
- 2+ years experience working in Linux environments, including navigating and troubleshooting basic website connectivity issues
- Familiarity in Linux plus coding and/or scripting experience
- Experience with Burp Professional, with a focus on SAST scanning
- Veracode experience performing SAST scanning
Preferred Skills
- Experience with Interactive Application Security Testing (IAST) capabilities and tools
- Experience with HackerOne
- Experience with Selenium
- Experience writing bash scripts
- Experience with OWASP ZAP or Burp Proxy
Required Education
- Bachelor's degree in Systems Engineering, Computer Science, or related field
Experience & Salary
- Minimum experience: 4 years
- Salary: USD 140,000 - 145,000 per year
- Location: Remote (remote)
Benefits
- Health Insurance
- Life Insurance
- Paid Time Off
- Holiday Pay
- Short-term and long-term Disability
- Retirement
- Learning and Development opportunities
Technologies
- Veracode
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Java
- Python
- .NET
- C#
- Eclipse
- JDeveloper
- Visual Studio
- OWASP Top 10
- CVSS
- CWE
- WASC
- SANS-25
- NIST 800-53
- FIPS
- FedRAMP
- Linux
- Burp Enterprise
- Burp Professional