Application Security Engineer

2 weeks ago


Fairfax, United States Dunhill Professional Search Full time

Application Security Engineer

*Full-Time Telework

*U.S. Citizenship

Evaluates application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and remediation of vulnerabilities across a variety of applications, programming languages, and platforms.

  • Requires one of the following certifications: CEH, Security+, or equivalent.
  • Defines best practices, performs software security architecture, and design reviews, and supports the identification, interpretation, and remediation of vulnerabilities across various applications, programming languages and platforms.
  • Supports development of technical security safeguards to protect information systems from intentional or accidental access/destruction
  • Liaison between development teams and stakeholders to understand and formulate security requirements
  • Defines, maintains, and enforces application security best practices.
  • Conduct vulnerability assessment and manual/automated code reviews
  • Demonstrate vulnerabilities to application owners and provide mitigation recommendations
  • Experience with SAST, DAST, and OSA tools.
  • Performs and conducts penetration tests and manual/automated code reviews
  • Experience with any programming language like Java, .NET, C#, etc.
  • Knowledge about Secure Coding best practices and OWASP top 10, SANS 25, CVE, etc.
  • Identify AppSec related tools/conduct tool analysis, and provide recommendations
  • Apply technical knowledge to analyze/develop, create, and implement process improvements, trouble shooting, and operational support

Minimum Qualifications

  • Bachelor's Degree in Computer Science, Engineering, or other Engineering or Technical discipline or equivalent relevant experience.
  • 5-10 years of experience as an Application Security Developer, Application Security Analyst, or equivalent.

Other Job Specific Skills

  • Expertise with application server technologies such as Spring Framework, Spring Security, Web Services, REST, and Hibernate.
  • In-depth knowledge of and experience with security technologies, single-sign-on and identity management technologies.
  • Expertise with web system security concepts, including authentication, authorization (RBAC), encryption/hashing, SAML, and LDAP.
  • Knowledge of web application vulnerabilities such as cross-site scripting (XSS), sessions hijacking, SQL injection, CSRF (Cross-Site Request Forgery), OWASP Top 10, and other attack vectors.
  • Hands-on experience with encryption, hashing, secure random number generation, key derivation, digital signatures, etc.
  • Knowledge of network based, system level and application layer attacks and mitigation methods, and TCP/IP, HTTP/S, and related protocols.
  • Experience with static code analysis tools including HP Fortify.
  • Familiarity with JavaScript, NodeJS, or other scripting languages and BurpSuite or other intercepting proxy tools.
  • Experience working with GIT source code management.
  • Must have solid working experience and knowledge of Unix/Linux operating system.
  • Experience with one or more of the following technologies: Vagrant, Chef, Rake, Gradle, Jenkins, and Cache DB is preferred.
  • Understanding of Agile/Scrum methodologies is preferred.
  • Experience with Axiomatics is a plus.

#cjpost



  • Fairfax, United States Dunhill Professional Search & Government Solutions Full time

    Application Security Engineer*Full-Time Telework*U.S. CitizenshipEvaluates application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and remediation of...


  • Fairfax, United States Dunhill Professional Search & Government Solutions Full time

    Application Security Engineer*Full-Time Telework*U.S. CitizenshipEvaluates application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and remediation of...


  • Fairfax, United States Dunhill Professional Search & Government Solutions Full time

    Application Security Engineer*Full-Time Telework*U.S. CitizenshipEvaluates application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and remediation of...


  • Fairfax, United States Dunhill Professional Search & Government Solutions Full time

    Application Security Engineer*Full-Time Telework*U.S. CitizenshipEvaluates application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and remediation of...


  • Fairfax, United States Charter Global Full time

    Job Title: Senior Application Security Engineer Location: Fairfax, VA (Remote Need Only From DC, VA , MD , West VA) Job Type: W2 Duration: 3+ Months Job ID: 41329 Purpose: We are interested in candidates with a strong development background and sizable exposure to Cybersecurity functions and environments. Additionally, we value experience and adaptability to...


  • Fairfax, United States Charter Global Full time

    Job Title: Senior Application Security Engineer Location: Fairfax, VA (Remote Need Only From DC, VA , MD , West VA)Job Type: W2Duration: 3+ MonthsJob ID: 41329Purpose:We are interested in candidates with a strong development background and sizable exposure to Cybersecurity functions and environments. Additionally, we value experience and adaptability to...


  • Fairfax, United States Charter Global Full time

    Job Title: Senior Application Security Engineer Location: Fairfax, VA (Remote Need Only From DC, VA , MD , West VA)Job Type: W2Duration: 3+ MonthsJob ID: 41329Purpose:We are interested in candidates with a strong development background and sizable exposure to Cybersecurity functions and environments. Additionally, we value experience and adaptability to...


  • Fairfax, United States ClearanceJobs Full time

    Company Overview At ValidaTek, we modernize and optimize IT services to solve some of the most critical challenges facing federal civilian and defense agencies. From customers to partners to top-talent employees, ValidaTek puts people first, empowering them to exceed expectations and transform government organizations. Our success starts and ends with our...


  • Fairfax, United States Dunhill Professional Search & Government Solutions Full time

    Security Reporting Engineer*Full Time Telework*U.S. Citizenship RequiredAbout the Role: Enforces application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and...

  • Security Engineer

    1 month ago


    Fairfax, United States NiyamIT Inc. Full time

    Join Our Team at Niyam IT: Embrace Diversity, Excel Together Are you ready to be part of a dynamic, inclusive, and fearless team that values your well-being and individuality? At Niyam, we're not just a company; we're a close-knit community of experts and leaders dedicated to providing IT solutions for esteemed clients. Niyam provides IT solutions to improve...


  • Fairfax, United States Avid Technology Professionals Full time

    Participate in capacity planning, disaster recovery planning, and security audits. - Create detailed documentation of network designs and configurations. - Continuously monitor and analyze network performance metrics. - Stay abreast on latest cloud services, features, trends, and best practices and provide recommendations on their adoption. MANDATORY SKILLS:...


  • Fairfax, United States TLA Inc Full time

    Description TLA-LLC is currently seeking a talented Ruby Web Applications Developer to join our team. As a Ruby Web Applications Developer, you will be responsible for designing, developing, and maintaining robust web applications using Ruby and Angular Rails. You will collaborate with a cross-functional team to implement innovative solutions that meet our...


  • Fairfax, United States TRICORPS SECURITY Full time

    TriCorps is seeking highly qualified armed security officers to work in a school setting in Fairfax, VA area. We have part-time openings available. **Requirements**: - Valid Armed Security License - Valid Driver's License - Must be reliable, have a positive attitude, and uphold ethical behavior. - Provide assistance to employees and visitors in a courteous...


  • Fairfax, United States Concept Plus, LLC Full time

    Concept Plus is seeking a Corporate Security Engineer (CSE) will work as part of the corporate security team to maintain and continuously mature the organization's information security program.Primary ResponsibilitiesSupport the maintenance of corporate compliance and adherence to cybersecurity-related policies, procedures and compliance standards aligned...


  • Fairfax, United States Concept Plus, LLC Full time

    Concept Plus is seeking a Corporate Security Engineer (CSE) will work as part of the corporate security team to maintain and continuously mature the organization's information security program.Primary ResponsibilitiesSupport the maintenance of corporate compliance and adherence to cybersecurity-related policies, procedures and compliance standards aligned...


  • Fairfax, United States Mission Essential Full time

    You will need to login before you can apply for a job. Information Systems Security Engineer with Security Clearance DESCRIPTION Position Description: The Mission Essential Group, LLC (MEG) is a premier service provider of information management solutions for complex, mission–critical needs. MEG has earned a reputation as an innovator and pioneer....


  • Fairfax, United States Highlight Technologies Full time

    Overview The software security engineer plays a critical role in a DevSecOps team modernizing and improving critical software by ensuring that security practices are baked into the teams' policies, processes and pipelines. Responsibilities The overall responsibility of the Software Security Engineer is to implement, test, and operate advanced software...


  • Fairfax, United States Highlight Technologies Full time

    Overview The software security engineer plays a critical role in a DevSecOps team modernizing and improving critical software by ensuring that security practices are baked into the teams' policies, processes and pipelines. Responsibilities The overall responsibility of the Software Security Engineer is to implement, test, and operate advanced software...


  • Fairfax, United States Tevora Full time

    Information Security Consultant (Mobile and Web Application Penetration) About Us Tevora is a tight-knit community of professionals with a shared passion for our craft. Every day, we combine in-depth knowledge of cybersecurity, technology, and compliance to help create more secure digital environments. To Tevorans, every problem is a puzzle in need of...


  • Fairfax, United States Tevora Full time

    Information Security Consultant (Mobile and Web Application Penetration) About Us Tevora is a tight-knit community of professionals with a shared passion for our craft. Every day, we combine in-depth knowledge of cybersecurity, technology, and compliance to help create more secure digital environments. To Tevorans, every problem is a puzzle in need of...