APPLICATION SECURITY ENGINEER

3 weeks ago


Rockville, United States Target Labs Full time

The Application Security Engineer (ASE) is responsible for promoting, designing, and evaluating application security in all phases of the application life cycle. The ASE shall ensure that appropriate and effective security techniques and solutions are identified, implemented, and used. Essential Job Functions: Software Security Assessment: - Evaluate applications for appropriate and effective use of security controls using tools and techniques such as source code analysis, vulnerability scanners, and manual testing techniques.. Application Security Control Development: - Provide expert guidance to developers on the appropriate selection and implementation of relevant application security controls. Security Awareness Training: - Design, develop and deliver presentations focused on raising awareness for crucial security relevant considerations and defensive programming techniques. Contract Security Provision Review: - Work with business stakeholders and legal services to evaluate service agreements with Application Service Providers (ASPs), and provide expert guidance related to security provisions necessary to help ensure the necessary visibility and rights needed to protect our data and meet our commitments. Other Job Functions: Participate in research of information security technologies (in the areas of application and application infrastructure components) and propose ideas for new security service development. Participate in all aspects of security service development projects including the following project phases: business case development, requirements gathering, architecture development, product/service selection and procurement, functional & QA testing, detailed technical design, technology infrastructure implementation and deployment, migration from existing services, operational process and procedure documentation, operations staff training, and internal marketing of security services. Advise and consult internal clients on appropriate application of security practices and existing security services to solve problems or enable new business opportunities. Deliver previously developed information security services in support of corporate needs including: requirements gathering, technical design, service deployment and integration, migration, operational transition, end user documentation, user training. In support of various enterprise IT initiatives, recommend, customize, implement, document, and transition to operations reusable technical security service components including application level intrusion detection systems, authentication systems, authorization systems, audit trail management systems, cryptographic systems, and others as defined by management. Research and implement new security technologies to be used as point solutions for IT initiatives unable to take advantage of or needing greater functionality than reusable enterprise security services. Recommend new security service development ideas based on accumulated knowledge of project-specific security requirements. Identify and implement improvements to application security team processes and supporting software tools (Java and C#/ASP based) to continually improve the teams effectiveness and efficiency. Serve as subject matter expert on application and information security technologies and methodologies. Perform other duties and responsibilities as assigned. Essential Education/Experience Requirements: - Bachelor of Science in Computer Science, or equivalent education or experience. Emphasis in software security a plus. At least three (3) years of professional experience, including: - Two (2) or more years in software engineering and development with emphasis on the delivery of secure, Internet-exposed, multi-tier, web-based systems using Java/J2EE and/or C#/ASP/.NET (experience with both a plus).. - At least one (1) year of hands-on experience evaluating the security of applications using both manual and automated techniques. Relevant tool experience should include code security scanners such as Fortify SCA, web vulnerability scanners such as HP WebInspect or IBM Rational AppScan, assessment support tools such as BurpSuite, Metasploit, Core Impact, etc . Strong written and verbal communication skills. Specific relevant experience may include technical reports (especially application security assessment reports), technical whitepapers, presentation development and delivery (for both technical and business audiences), technical training, etc. Candidate should have experience making and defending sound technical arguments that incorporate relevant technical and business considerations, and building consensus among stakeholders Other Desirable Experience: Security-related experience with the following: - Providing software architecture security guidance, including developing application threat models and methodically protecting against business logic and design flaws that could introduce security vulnerabilities. - Web Application Firewalls such as Imperva SecureSphere and Breach WebDefend. - Design patterns and coding standards for secure software. - Secure configuration and operation of Application Servers, Web Servers, Directory Servers, Media/Content Servers, Messaging Servers, Database Servers, and Integration Servers. - Application authentication & authorization systems such as RSA ClearTrust and Netegrity Siteminder. - Application layer intrusion detection systems such as Sanctum AppShield, or Kavado. - Knowledge of PKI systems such as RSA Keon. - Knowledge of cryptographic tool kits for application development such as RSA BSAFE or others. - Knowledge of and experience with built-in and add-on security capabilities of common application infrastructure components such as MS SQLServer, Oracle, MS IIS, iPlanet Directory, MS Active Directory, MQSeries, MSMQ, MS Exchange. - Knowledge of general application security API's and protocols such as: MS CryptoAPI, Kerberos, SSL/TLS, SAML, S/MIME, and PKCS API's. - End-to-end, hands-on experience in security solutions for complex enterprise architectures. - Knowledge of cryptographic solutions for protection of data in use, in transit and at rest, such as: Masking, SSL/TLS, IPSec, format preserving encryption & sanitization, etc. - Knowledge of security considerations related to virtualization and cloud computing. - Mobile Application Security on iOS and/or Android devices; includes experience in secure development of applications and/or analysis. Financial services industry (Insurance, Banking, Investments) experience a plus. #J-18808-Ljbffr



  • Rockville, United States Turning Point Global Solutions Full time

    Applications Support EngineerTurningPoint is seeking a talented and motivated Application Support Engineer to join our dynamic team! This role offers a unique opportunity to work on innovative software solutions, collaborate with top industry professionals, and grow your skills in a supportive environment. If you are passionate about software development,...


  • Rockville, United States Peraton Full time

    3 days ago Be among the first 25 applicants About Peraton Peraton is a next‑generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly...


  • Rockville, United States Peraton Full time

    Network Security Engineer Job Locations: US-MD-Rockville Requisition ID: 2025-161515 Position Category: Information Technology Clearance: Agency Clearance Responsibilities We are seeking a skilled Network Security Engineer to design, implement, maintain, and support our network security infrastructure. In this role, you will ensure that our...


  • Rockville, Maryland, United States BTI Security Full time $40,000 - $60,000 per year

    Job Skills / RequirementsUnarmed Security Officers perform a variety of security-related duties depending on the post.Patrolling and monitoring exterior and community areas on-premises.Access control of entrances and exits and departure of employees and visitors.Monitoring surveillance cameras for any disruptions or unlawful activities.Must have the ability...

  • IT Security Engineer

    17 hours ago


    Rockville, MD, United States National Guard Employment Network Full time

    Job Description ATTENTION MILITARY AFFILIATED JOB SEEKERS - Our organization works with partner companies to source qualified talent for their open roles. The following position is available to Veterans, Transitioning Military, National Guard and Reserve Members, Military Spouses, Wounded Warriors, and their Caregivers. If you have the required skill set,...


  • Rockville, United States Arch Amenities Group Full time

    Senior Engineer, Infrastructure And SecurityPosition Summary:The Senior Engineer, Infrastructure & Security is responsible for designing and executing projects that ensure IT security, infrastructure integrity, and networking effectiveness across the organization.This hands-on role requires strong technical expertise, problem-solving and project management...


  • Rockville, United States X-energy Full time

    Plant Cyber Security Engineer III (Remote) Join to apply for the Plant Cyber Security Engineer III (Remote) role at X-energy X-energy LLC conducts a thorough recruiting process and will never issue offers without interview to discuss qualifications and responsibilities. All applications will be submitted via our company career page www.x-energy.com/careers....

  • Cloud Engineer

    3 weeks ago


    Rockville, United States BLH Technologies, Inc. Full time

    BLH Technologies was founded in 2003 and is headquartered in Rockville, Maryland. BLH provides technology solutions for our Federal and commercial clients in the areas of Artificial Intelligence, Machine Learning, Systems Integrations, Network Infrastructure, Cloud Computing, Web Development and more. We are seeking onsite candidates with education,...

  • Security Engineer

    2 weeks ago


    Rockville, United States TekSynap Full time

    Responsibilities & Qualifications RESPONSIBILITIES Responsible for the architecture, design, implementation, support, maintenance, and expansion of the following security management tools: Palo Alto Networks Firewalls: managing firewalls using Panorama IPSec: configure and troubleshoot IPSec tunnels is essential Managing and maintaining an SD-WAN environment...


  • Rockville, Minnesota, United States cFocus Software Incorporated Full time $120,000 - $150,000 per year

    Security Infrastructure Support Application DeveloperOverviewcFocus Software is seeking a Security Infrastructure Support Application Developer to design, develop, and maintain secure, reliable, and scalable applications across hybrid (on-premises and cloud) environments in support of a federal agency. The Application Developer will develop and modernize...