Senior Application Security Engineer
Backend Developer
Senior
Application Security
Data Security
Dynamic Application Security Testing
Engineering
Facilities Management
Information Security
Information Technology (IT)
InfoSec
Programming
Programming Language
Programming Languages
Project Management
Risk Governance
Risk Management
Security
Security Automation
Security Clearance
Security Compliance
Security Operations
Security Standards
Security Testing
Security Testing Tools
Software Security
Job Description
Senior Application Security Engineer role focused on improving application security coverage for high-visibility systems.
Responsibilities
- Partner with the client and application community to maintain a resilient security posture for highly visible applications.
Requirements
- 6+ years of information technology experience.
- 3+ years supporting Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE Plug-in environments using Burp Suite.
- 1+ year supporting SAST, DAST, and IDE Plug-in environments using Veracode.
- 2+ years experience with Java, Python, .NET, or C#.
- 3+ years designing and implementing enterprise-wide security controls to secure applications, systems, network, or infrastructure services.
- Experience with Eclipse, JDeveloper (including pipeline development), or Visual Studio.
- Experience securing enterprise web applications and familiarity with OWASP Top 10, CVSS, CWE, WASC, and SANS-25.
- Knowledge of federal compliance standards, including NIST 800-53, FIPS, or FedRAMP.
- 2+ years in Linux based environments, including navigating and troubleshooting basic website connectivity issues.
- Ability to obtain a security clearance.
- IT-related Bachelor’s Degree.
- Experience with Interactive Application Security Testing (IAST) capabilities and tools.
- Experience with HackerOne.
- Experience with Selenium.
- Experience writing bash scripts.
- Experience with OWASP ZAP or Burp Proxy.
Location & Work Setup
- Washington, DC (onsite)
Benefits
- Robust benefits package (medical, dental, vision, STD, Accident, Life, Hospital Insurance, FSA, HSA, 401K match, professional development stipend, etc.)
- Community Service and Employee Engagement events
- Competitive salary adjusted for candidate qualifications
- Incentive plans with corporate and individual-based performance bonuses
- 401K
- PTO
- Remote work
- Health and wellness programs
- Employee discounts
- Learning and development reimbursement
Relevant Tools & Technologies
- Veracode
- Burp Suite (including Burp Proxy)
- SAST and DAST
- IDE Plug-in environments
- Java, Python, .NET, C#
- Eclipse, JDeveloper, Visual Studio
- OWASP Top 10, CVSS, CWE, WASC, SANS-25
- NIST 800-53, FIPS, FedRAMP
- Linux
- IAST
- HackerOne
- Selenium
- bash scripts
- OWASP ZAP
Military Occupational Specialty (MOS) Codes
- 170A
- 170D
- 17A
- 17B
- 17C
- 17D
- 24B
- 25B
- 47D
- 94F
- IT
- 17 5309
- 6203
- 9735
- 9740
- 9890
- 9891