Senior Application Security Engineer

2 weeks ago


Washington, United States Global Solutions Consulting (GSC) Full time
Job DescriptionJob Description

Position Title: Senior Application Security Engineer

Location: Washington, DC (Hybrid)

Job Requirements:

  • Strong written and verbal communication skills

· Must have GitLab CI/CD pipeline experience

· Assist in the development and implementation of the DevSecOps strategy to include the definition and goals of the over-arching framework and methodologies

· Assist customers with implementing a secure CI/CD pipeline utilizing DevSecOps principles and practices to increase automation and reduce human involvement in the process

· Reviewing source code for potential security vulnerabilities

· Strong analytical skills to assess risks and vulnerabilities in complex systems

· Writing security test cases to check for vulnerabilities or broken/missing security controls.

· Implement automated security controls as part of CI/CD pipelines

· Support development teams with secure code (DAST, SAST, Dependency, Secret Detection, Container scans, etc.) reviews and other assessments to identify security weaknesses and vulnerabilities

· Establish and maintain secure coding standards and best practices to provide guidance and training to development teams on security best practices

· Recommend cyber defense and vulnerability assessment tools

· Review and research monthly continuous monitoring controls documentation tasks that is required by OIS

· Continuous Process Improvement, actively contribute to the development of standardized operating procedures (SOPs) for API security testing

· Collaborate closely with cross-functional teams, including system administrators and Information System Security Officers (ISSOs)

 

Security Clearance Requirement:

· Active Public Trust and eligible to obtain a Secret clearance

 

Certifications/Licenses:

  • At least Ten (10) years of experience working in cybersecurity or information technology with a bachelor’s degree. Minimum of 5 years’ experience in vulnerability management, application and software security team, Malware analysis, digital forensics, data/network analysis, penetration testing, information assurance, leading incident handling
  • Solid experience in application security and software development in one or more programming languages such as C#, Java, Python, etc
  • Experience with security tools such as SAST, DAST, IAST, SCA and other security tools

· Familiarity with industry-standard security frameworks such as OWASP, NIST, BSIMM etc

· Experience with CICD pipeline, security tools integration and secure SDLC

  • Knowledge of current and emerging threats and techniques for exploiting security vulnerabilities
  • CISSP, OSCP, any DevSecOps or other related Information Security certification
  • Experience with cloud-based infrastructure (AWS, Azure, or GCP)
Company DescriptionGSC is a leading cyber security and information technology company based in Washington, DC. We are looking to hire a Senior Security Application Engineer to support a full range of cyber security services on a long-term contract in Washington DC. The position is full-time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background and security clearance.Company DescriptionGSC is a leading cyber security and information technology company based in Washington, DC. We are looking to hire a Senior Security Application Engineer to support a full range of cyber security services on a long-term contract in Washington DC. The position is full-time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background and security clearance.

  • Washington, United States SourcePro Search Full time

    SourcePro Search is conducting a search for an experienced Senior Application Security Engineer in Washington, DC. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This position collaborates with business units, project management, and engineering teams...


  • Washington, United States SourcePro Search Full time

    SourcePro Search is conducting a search for an experienced Senior Application Security Engineer in Washington, DC. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This position collaborates with business units, project management, and engineering teams...


  • Washington, United States TalentRemedy Full time

    The Sr. Application Security Engineer is a technology and process focused security professional with extensive experience in Development Operations, Software Engineering, Application Security and/or Information Security disciplines. This individual will be at the forefront of our security efforts, partnering closely with product and application developers to...


  • Washington, United States TalentRemedy Full time

    The Sr. Application Security Engineer is a technology and process focused security professional with extensive experience in Development Operations, Software Engineering, Application Security and/or Information Security disciplines. This individual will be at the forefront of our security efforts, partnering closely with product and application developers to...


  • Washington, United States Iron Vine Security Full time

    Job Requirements: · Strong written and verbal communication skills. · Experience designing, implementing, and maintaining IT security systems to protect digital assets from malicious cyber-attacks. · Experience developing and implementing an annual Incident Response Training and Testing Program · Experience implementing, configuring, and...


  • Washington, United States 3M Consultancy Full time

    Job DescriptionJob DescriptionThis is a remote position. Job Title: Senior Security Engineer. Location: Washington, DC (Remote) Duration: Full-Time. Role Specific Duties: Provide network IDS monitoring, cyber threat intelligence, security log analysis and forensics, and web application security scanning and analysis. Protect users by performing internal...


  • Washington, United States MDS (Micro-Data Systems) Full time

    Senior Security EngineerRemote, but prefer candidates to be located in the Washington, DC Metro AreaJob DescriptionYou will provide guidance and technical support to clients deploying security integrations. You'll act as the technical partner, providing strategic guidance around complex systems to secure a digital environment. Interacting directly with the...


  • Washington, United States MDS (Micro-Data Systems) Full time

    Senior Security EngineerRemote, but prefer candidates to be located in the Washington, DC Metro AreaJob DescriptionYou will provide guidance and technical support to clients deploying security integrations. You'll act as the technical partner, providing strategic guidance around complex systems to secure a digital environment. Interacting directly with the...


  • Washington, United States MDS (Micro-Data Systems) Full time

    Senior Security EngineerRemote, but prefer candidates to be located in the Washington, DC Metro AreaJob DescriptionYou will provide guidance and technical support to clients deploying security integrations. You'll act as the technical partner, providing strategic guidance around complex systems to secure a digital environment. Interacting directly with the...


  • Washington, United States Latitude, Inc. Full time

    Job DescriptionJob DescriptionNew Job Opportunity - Senior Network Security Engineer:New and exciting job opportunity with a client based out of Washington, DC. Looking to hire an experienced Sr. Network Security Engineer with at least 8 years of prior related professional experience (High level Network Security Engineer / Cybersecurity support experience)....


  • Washington, United States VISTRADA Full time

    Job DescriptionJob DescriptionJob Posting: Security System Engineer (Junior/Intermediate/Senior Level)Vistrada is currently seeking highly skilled and motivated Security System Engineers to join our esteemed team. As a Security System Engineer, you will play a crucial role in identifying and mitigating vulnerabilities, ensuring the secure integration and...


  • Washington, United States Gridiron IT Solutions LLC Full time

    Job DescriptionJob DescriptionGridIron IT is hiring a Senior Security Engineer to work on a remote basis.This role offers the exciting opportunity to manage vulnerabilities, conduct security scans using leading tools, and oversee the security infrastructure. You'll gain a strong understanding of FedRAMP and compliance frameworks to maintain high-security...


  • Washington, United States Vantage Point Consulting Inc. Full time

    The Senior Applications Engineer, Cloud Solutions acts as IT owner of various applications and productivity tools tied to the M365 platform and other cloud vendors. These include MS Teams, Copilot and IntApp Workspaces. This is a highly skilled technical position responsible for strategy, day-to-day oversight and support of assigned systems. This is an...

  • Senior Cloud Engineer

    2 weeks ago


    Washington, United States Cordia Resources by Cherry Bekaert Full time

    Our client has a Senior Cloud Engineer opening. This position may work 100% virtual/remote in a firm approved U.S. state. The Senior Cloud Engineer is responsible for partnering and working with IT engineering teams in the review and implementation of the firm's infrastructure and transition to hybrid cloud technology that includes compute, storage...

  • DHS HSEN

    3 weeks ago


    Washington, United States Versar, Inc. Full time

    Job DescriptionJob DescriptionPosition SummaryBayFirst Solutions, a subsidiary of Versar, Inc., is seeking a Senior Security Engineer (DevSecOps) to support the Department of Homeland Security’s Enterprise Engineering Division (EED) within the Office of the Chief Information Officer (OCIO). This candidate will be a member of a high functioning team...

  • DHS HSEN

    3 weeks ago


    Washington, United States Versar, Inc. Full time

    Job DescriptionJob DescriptionPosition SummaryBayFirst Solutions, a subsidiary of Versar, Inc., is seeking a Senior Security Tools Engineer to support the DHS’ Homeland Security Enterprise Network (HSEN) within the Office of the Chief Information Officer (OCIO), IT Operations, Enterprise Engineering Division (EED). This Security Tools Engineer will be a...


  • Washington, United States Versar, Inc. Full time

    Job DescriptionJob DescriptionPosition SummaryVersar, Inc., is seeking a Senior Security Engineer (Compliance) to support the Department of Homeland Security’s Enterprise Engineering Division (EED) within the Office of the Chief Information Officer (OCIO). This candidate will be a member of a high functioning team supporting cybersecurity countermeasures...


  • Seattle, Washington, United States Block Full time

    Job Description The Cloud Security Risk and Insights team is responsible for discovering, tracking and enabling the business to remediate the biggest security risks we face across Block’s cloud ecosystems. We drive the creation of security policy and best practices. We measure and aggregate deviations from these policies. We develop capabilities to...


  • Washington, United States Dynamis, Inc. Full time

    Job DescriptionJob DescriptionDynamis is seeking a Sr. Applications Software Programmer/Senior Engineer to support a data analytics contract in support of a US government client's mission. In this role the ideal candidate will develop information systems by studying operations; designing, developing, and installing software solutions; support and develop...


  • Washington, United States UPSLOPE ADVISORS, INC Full time

    Job DescriptionJob DescriptionSalary: UpSlope Advisors is seeking an exceptional candidate to serve as an Application Engineer SME.  The customer requires support to provide enterprise-level service desk and incidental information technology services. Services include: Help Desk Support, IT Operations Management and Support, Mobile Support, IT Asset...