Remote job
Application Security Engineer
Job details
About this role
Role overview
This role supports a federal government technology services program, helping mission teams operate more safely through practical cybersecurity engineering work. The engineer will assess risk across applications, networks, endpoints, cloud platforms, and enterprise systems while guiding teams toward systems that earn federal accreditation. Day-to-day work blends hands-on hardening, stakeholder communication, and continuous improvement of security processes and controls.
Responsibilities
- Identify, assess, and prioritize vulnerabilities and risks across applications, networks, endpoints, cloud environments, and enterprise systems - Partner with Information System Security Officers (ISSOs) and Controls Assessors to capture Risk Management Framework (RMF) artifacts and validate the effectiveness of security controls - Collaborate with engineers to design secure systems that can quickly and cleanly achieve FISMA accreditation - Review, advise on, and refine security Control Statements so systems are correctly hardened and accurately represented in assessment documentation - Drive compliance with federal regulations and policies, including NIST special publications, OMB guidance, and Binding Operational Directives (BODs) - Communicate risks clearly to stakeholders, recommend effective mitigation strategies, and contribute to ongoing improvements in security processes and controls
Requirements
- 4–6 years of experience performing security engineering or secure systems engineering - Strong working knowledge of the FISMA Risk Management Framework (RMF) - Hands-on experience hardening applications and operating systems - Understanding of OS-level vulnerabilities and hardening practices - Familiarity with core network protocols and components (TCP/IP, DNS, firewalls, routers, switches) - Experience configuring and working with Identity Providers (IdP) - Experience with patch management tools and processes - Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent practical experience - U.S. Citizenship and eligibility to obtain a Public Trust security clearance
Nice to have
- Strong experience working with major Cloud Service Providers (AWS, Azure, GCP) and cloud-native security policies
Benefits and work setup
- Posted pay range for this position, in listed U.S. states and the District of Columbia, is $106,300 to $221,100 USD, with actual compensation varying by office location, skill set, and experience level - Applications are accepted on a rolling basis with no fixed deadline