Application Security Engineer

2 weeks ago


Washington, United States Phia LLC Full time
At phia we hire talented and passionate people who are focused on collaborative, meaningful work, providing technical and operational subject matter expertise and support services to our partners and clients.
We are seeking an Application Security Engineer to work hand-in-hand with the Federal client to maintain a resilient security posture for highly visible applications. This position allows you to work remotely from anywhere within the United States. To be considered, U.S. citizenship is required, and you should be able to obtain a Public Trust before starting the position. If you thrive on complex problem-solving, enjoy providing innovative solutions, and want to have a meaningful impact on national security, let‘s explore the possibility of you working for phia What You‘ll Do
  • Collaborate with the federal client and application teams to maintain a robust security posture for high-visibility applications
  • Lead proactive security discussions with development teams to integrate best practices throughout the software development lifecycle
  • Conduct comprehensive application security assessments using dynamic and static testing methodologies
  • Perform threat modeling and security requirements analysis using tools like SD Elements
  • Execute in-depth application penetration testing using industry-standard tools such as Burp Suite
  • Implement and leverage the latest OWASP frameworks to enhance application security
  • Develop and maintain security controls to protect applications, systems, and infrastructure services
  • Provide expert guidance on remediating identified security flaws and vulnerabilities
  • Stay current with evolving security threats and compliance standards to ensure continuous improvement of security measures
Required: Education + Experience
  • 6+ years of Information Technology experience
  • 3+ years of experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE Plug-in environments, particularly using Veracode
  • 2+ years of hands-on experience with Java, Python, .NET, or C#
  • 3+ years of proficiency with Burp Suite for application security testing
  • 3+ years of experience designing and implementing enterprise-wide security controls
  • Expertise in securing enterprise web applications and thorough knowledge of OWASP Top 10, CVSS, CWE, WASC, and SANS-25
  • Familiarity with federal compliance standards, including NIST 800-53, FIPS, and FedRAMP
  • Proficiency in Linux or UNIX environments, including troubleshooting website connectivity issues
  • Experience with development environments such as Eclipse, JDeveloper, or Visual Studio
  • Strong understanding of CI/CD pipeline security integration
  • U.S. citizenship and ability to obtain a Public Trust clearance

Desired Skills and Experience
  • Bachelor‘s degree in Computer Science, Information Technology, Information Security, or a related field
  • Experience with Interactive Application Security Testing (IAST) tools and methodologies
  • Proficiency with Selenium for automated testing
  • Skill in writing bash scripts for security automation
  • Hands-on experience with OWASP ZAP or Burp Proxy
  • Certifications in application security or related fields (e.g., CSSLP, OSCP, GWAPT)
Security Clearance
  • U.S. Citizenship required
  • Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Public Trust determination is required
Who You Are A proactive problem solver that appreciates the challenges of working in a fast-paced, dynamic environment.Intellectually curious with a genuine desire to learn and advance your career.An effective communicator, both verbally and in writing.Customer service-oriented and mission-focused.Critical thinker with excellent problem-solving skills If your experience and qualifications aren‘t a match for this position, you will remain in our database for consideration for future opportunities that may be a better fit.
Who We Arephia, LLC is a Northern Virginia-based, small business established in 2011 with a focus on Cyber Intelligence, Cyber Security/Defense, Intrusion Analysis & Incident Response, Cyber Architecture & Capability Analysis, Cyber Policy & Strategy, and Information Assurance/Security. we proudly support various agencies and offices within the Department of Defense (DoD), Federal government, and private/commercial entities.phia values work-life balance and offers the following benefits to full-time employees: Comprehensive medical insurance to include dental and visionShort Term & Long-Term Disability 401k Retirement Savings Plan with Company MatchTuition and Professional Development Assistance Flex Spending Accounts (FSA)
phia does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity, or any other reason prohibited by law in the provision of employment opportunities and benefits.


  • Washington, United States SourcePro Search, LLC Full time

    Our top rated global client is looking for an experienced Senior Application Security Engineer for their Washington, DC office. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This position collaborates with business units, project management, and...


  • Washington, United States Global Solutions Consulting (GSC) Full time

    Job DescriptionJob DescriptionPosition Title: Senior Application Security EngineerLocation: Washington, DC (Hybrid)Job Requirements:Strong written and verbal communication skills· Must have GitLab CI/CD pipeline experience· Assist in the development and implementation of the DevSecOps strategy to include the definition and goals of the over-arching...


  • Washington, United States Cannon Security Products Full time

    About the job The Integrity, Investigations, Intelligence and Events (i3E) teams at Meta are dedicated to protecting the users of our family of applications (e.g. Facebook, Instagram, WhatsApp, Oculus) from a multitude of threats including criminal organizations, human trafficking and exploitation, and scams/fraud. We are seeking security engineers to...


  • Washington, United States GuidePoint Security, LLC Full time

    GuidePoint Security provides trusted cybersecurity expertise, solutions, and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation's top organizations, such as Fortune 500 companies and U.S. government...


  • Washington, United States SourcePro Search, LLC Full time

    Job Overview:SourcePro Search, LLC is a top-rated global client looking for an experienced Senior Application Security Engineer for their Washington, DC office. The ideal candidate will serve as a subject matter expert integrating secure design for applications and services within the system development lifecycle. This position collaborates with business...


  • Washington, DC, United States Booz Allen Hamilton Full time

    Job Number: R0210035 Application Security EngineerKey Role: Work together with the client and application community to maintain a resilient security posture for highly visible applications. Remediate application security flaws in conjunction with the application security team. Lead security discussions with the application teams to prescribe security best...


  • Washington, United States MBL Technologies Full time

    Secure the Future with MBL TechnologiesWe are seeking a highly skilled Senior Application Security Engineer to join our team at MBL Technologies. As a key member of our application security team, you will play a critical role in enhancing our security initiatives and ensuring the integrity of our applications.The ideal candidate will have a strong background...


  • Washington, DC, United States ZipRecruiter Full time

    Position Title: Senior Application Security Engineer Location: Washington, DC (Hybrid) Job Requirements: Strong written and verbal communication skills Must have GitLab CI/CD pipeline experience Responsibilities: Assist in the development and implementation of the DevSecOps strategy to include the definition and goals of the over-arching framework and...


  • Washington, United States Editech Staffing Full time

    At Editech Staffing, we're seeking a skilled Application Security Specialist to join our team. This role offers a competitive salary of $110,000 annually, reflecting the expertise required for this position.Job OverviewThe successful candidate will be responsible for ensuring the security of cloud-native and microservices-based architectures through thorough...


  • Washington, United States SourcePro Search, LLC Full time

    About the Role\We are looking for an experienced Senior Application Security Engineer to join our team at SourcePro Search, LLC in Washington, DC.Key Responsibilities\\Performing security architecture and design reviews of applications and services;\Integrating security tasks and activities into system development methodologies;\Validating security controls...


  • Washington, United States Iron Vine Security Full time

    Job Requirements: · Strong written and verbal communication skills. · Experience designing, implementing, and maintaining IT security systems to protect digital assets from malicious cyber-attacks. · Experience developing and implementing an annual Incident Response Training and Testing Program · Experience implementing, configuring, and...


  • Washington, Washington, D.C., United States CloudShape Full time

    Job Title:Cloudshape Software Engineer - Secure Web Application ExpertAbout Cloudshape:We are a leading provider of IT infrastructure solutions, helping organizations transform their technology landscapes to meet the changing needs of modern business. Our team is dedicated to delivering secure, scalable, and innovative web applications that exceed our...


  • Washington, DC, United States Cannon Security Products Full time

    About the jobThe Integrity, Investigations, Intelligence and Events (i3E) teams at Meta are dedicated to protecting the users of our family of applications (e.g. Facebook, Instagram, WhatsApp, Oculus) from a multitude of threats including criminal organizations, human trafficking and exploitation, and scams/fraud. We are seeking security engineers to...


  • Washington, DC, United States Global Solutions Consulting LLC. Full time

    Position Summary: GSC is a leading cyber security and information technology company based in Washington, DC. We are looking to hire a Senior Security Application Engineer to support a full range of cyber security services on a long-term contract in Washington DC. The position is full-time/permanent and will support a US Government civilian agency. The...


  • Washington, United States Quadrant Inc Full time

    Job ID: 24-04211 Security Engineer Washington, DC (Hybrid) Pay From: $140,000 per year MUST: Top Secret Clearance required Experienced Security Engineer 3+ years relevant experience as a Security Architect in previous companies with a total of 5 years in Engineering or Architecture Proactive leader, helping to drive cross domain and security maturity...

  • IT Security Engineer

    2 weeks ago


    Washington, United States CipherStaff Full time

    CipherStaff is hiring an IT Security Engineer to join our team in Washington, DC. This role involves troubleshooting systems, implementing cybersecurity tools, and performing system/application analysis in a remote-based position. The ideal candidate will have 1+ years' experience in IT Linux/Unix support and a Bachelor's degree in Information...


  • Washington, United States Quadrant Inc Full time

    Job ID: 24-04211Security EngineerWashington, DC (Hybrid)Pay From: $140,000 per yearMUST:Top Secret Clearance requiredExperienced Security Engineer3+ years relevant experience as a Security Architect in previous companies with a total of 5 years in Engineering or ArchitectureProactive leader, helping to drive cross domain and security maturity throughout the...


  • Washington, United States Quadrant Full time

    Security Engineer Washington, DC (Hybrid) Pay From: $140,000 per yearMUST: Top Secret Clearance required Experienced Security Engineer 3+ years relevant experience as a Security Architect in previous companies with a total of 5 years in Engineering or Architecture Proactive leader, helping to drive cross domain and security maturity throughout the...


  • Washington, United States VISTRADA Full time

    Job Posting: Security System Engineer (Junior/Intermediate/Senior Level) Vistrada is currently seeking highly skilled and motivated Security System Engineers to join our esteemed team. As a Security System Engineer, you will play a crucial role in identifying and mitigating vulnerabilities, ensuring the secure integration and operation of systems, and...


  • Washington, United States VISTRADA Full time

    Job Posting: Security System Engineer (Junior/Intermediate/Senior Level) Vistrada is currently seeking highly skilled and motivated Security System Engineers to join our esteemed team. As a Security System Engineer, you will play a crucial role in identifying and mitigating vulnerabilities, ensuring the secure integration and operation of systems, and...