Sr. IT Application Security Engineer
Job Description
Career Developers is seeking a Sr. IT Application Security Engineer (SME) to support enterprise application security in a hybrid role based in Reston, VA. The position focuses on administering BIG-IP WAF, performing container image security scanning, and embedding security controls into SDLC and CI/CD workflows with Development and DevOps teams.
Key Responsibilities
- Administer and enhance enterprise BIG-IP WAF capabilities, including building security policies, tuning rules, investigating false positives, troubleshooting application traffic issues, and maintaining effective web application protections.
- Design, implement, and operate application security controls across enterprise applications and supporting platforms.
- Perform container image security scanning and analyze vulnerabilities identified within application and container images.
- Assess container vulnerability severity and business risk, then partner directly with development teams to prioritize and remediate findings.
- Collaborate with Development and DevOps teams to integrate security controls into the SDLC and CI/CD pipelines.
- Design and operate web application and API security protections, including policy configuration, rule tuning, automation, and ongoing improvement.
- Identify application security vulnerabilities, conduct risk assessments, and recommend practical mitigation and remediation strategies.
- Develop and maintain application security policies, standards, procedures, and controls.
- Develop security monitoring and telemetry for the application stack to improve proactive detection.
- Conduct technical investigations related to application security incidents and vulnerabilities.
- Support container security activities including image scanning, vulnerability risk assessments, and runtime security and hardening.
- Operate and support security technologies across cloud and/or on-premises environments.
- Troubleshoot security, application, and network-related issues, and clearly communicate technical findings and recommended actions.
- Partner with senior IT stakeholders to interpret application security risks, priorities, and remediation needs.
Required Qualifications
- 6–8 years of Application Security experience designing, implementing, and operating security controls within enterprise application environments.
- Hands-on BIG-IP WAF administration experience, including building WAF policies, configuring protections, tuning rules or policies, troubleshooting production issues, reducing false positives, and maintaining WAF controls in a production environment.
- Hands-on container image security scanning experience, including reviewing scan results, evaluating vulnerabilities, determining risk and remediation priorities, and working directly with development teams to resolve findings.
- Experience with a container security and scanning platform (specific tool not critical). Relevant examples include Prisma Cloud, Wiz, Snyk, or comparable technologies.
- Strong web application security knowledge, including OWASP Top 10 vulnerabilities and practical security control implementation.
- Experience conducting web application security scans, vulnerability assessments, and/or penetration testing.
- Experience partnering directly with Development and DevOps teams to integrate security into the SDLC and CI/CD pipelines.
- Experience with authentication and authorization technologies such as OAuth and OpenID.
- Strong troubleshooting and communication skills, including the ability to explain security risks and remediation requirements to both technical teams and senior IT stakeholders.
- Bachelor’s degree in Information Security, Computer Science, Computer/Electrical Engineering, or a related discipline, and/or equivalent relevant professional experience.
- Demonstrated production experience administering BIG-IP WAF, particularly building and tuning WAF policies.
- Demonstrated hands-on experience with container image scanning and vulnerability management.
- Experience personally reviewing container vulnerabilities and collaborating with developers on remediation, not limited to operating or monitoring a scanning tool.
- Experience with Prisma Cloud, Wiz, Snyk, or another comparable container/application security platform (specific platform experience not required if strong transferable hands-on experience is demonstrated).
- Experience securing APIs and working with OAuth and OpenID.
- Experience integrating security practices and controls into CI/CD and secure software development processes.
- Experience operating cloud-based and/or on-premises security platforms.
- Ability to investigate and troubleshoot security and network-related issues using established security methodologies and best practices.
- Proof of eligibility to work in the United States.
Relevant Technologies
- BIG-IP WAF
- OWASP Top 10
- OAuth
- OpenID
- Prisma Cloud
- Wiz
- Snyk
- CI/CD
- SDLC
Location and Work Model
Hybrid in Reston, VA 20190. Role requires 3 days on-site per week (Tues and Wed in the office each week).
Compensation
USD 150,000 - 180,000 per year, plus 7% bonus.
Benefits
- 150–180K + 7% Bonus