Remote job
Senior Application Security Engineer
Job details
About this role
Role overview Senior Application Security Engineer supporting enterprise-wide digital transformation initiatives for a federal-adjacent organization. The role focuses on integrating and optimizing security tooling across the software development lifecycle while guiding the selection of new technologies and architectures. It is a remote position requiring U.S. citizenship and the ability to obtain and maintain a Public Trust clearance.
Responsibilities - Engineer and optimize integrated application security systems that improve reliability, scalability, and security across enterprise applications. - Lead evaluation of new application security technologies and architectures, providing strategic recommendations to leadership. - Operate and support Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE plug-in environments. - Design and implement enterprise-wide security controls to secure applications, systems, networks, and infrastructure services. - Perform DAST scanning using Burp Enterprise and SAST scanning using Veracode and Burp Professional. - Advise on securing web applications against OWASP Top 10, CVSS, CWE, WASC, and SANS-25 risks. - Troubleshoot application connectivity issues in Linux-based environments and contribute to bash scripting and automation efforts.
Requirements - Bachelor's degree in Systems Engineering, Computer Science, or a related field, plus 4+ years of relevant experience, or equivalent work experience in lieu of degree. - U.S. citizenship and ability to obtain and maintain a Public Trust clearance. - 1+ year of experience supporting SAST, DAST, and IDE plug-in environments using Veracode. - 2+ years of experience with Java, Python, .NET, or C#. - 3+ years of experience designing and implementing enterprise-wide security controls. - Experience with Eclipse, JDeveloper, or Visual Studio, including pipeline development. - Knowledge of federal compliance standards such as NIST 800-53, FIPS, or FedRAMP. - 2+ years working in Linux environments, with coding or scripting experience.
Nice to have - Experience with Interactive Application Security Testing (IAST) tools and capabilities. - Familiarity with HackerOne. - Experience with Selenium. - Experience writing bash scripts. - Experience with OWASP ZAP or Burp Proxy.
Benefits and work setup - Remote work arrangement. - Salary range of $140,000–$145,000 per year. - Benefits package includes health insurance, life insurance, paid time off, holiday pay, short- and long-term disability, retirement contributions, and learning and development opportunities, depending on position.