Application Security Engineer

2 weeks ago


Pasco, Washington, United States Phia Full time

At phia we hire talented and passionate people who are focused on collaborative, meaningful work, providing technical and operational subject matter expertise and support services to our partners and clients.

phia is seeking an Application Security Engineer withhands-on experience using Veracode for application security testing and vulnerability management. The ideal applicant should be proficient in utilizing Veracode's static and dynamic analysis tools and interpreting scan results, and able to provide clear and actionable remediation guidance. This individual will work with the Federal client to maintain a resilient security posture for highly visible applications. This position allows you to work remotely from anywhere within the United States.

U.S. citizenship is required, and able to obtain Public Trust approval.

What You'll Do

  • Collaborate with the federal client and application teams to maintain a robust security posture for high-visibility applications
  • Lead proactive security discussions with development teams to integrate best practices throughout the software development lifecycle
  • Conduct comprehensive application security assessments using dynamic and static testing methodologies
  • Perform threat modeling and security requirements analysis using tools like SD Elements
  • Execute in-depth application penetration testing using industry-standard tools such as Burp Suite
  • Implement and leverage the latest OWASP frameworks to enhance application security
  • Develop and maintain security controls to protect applications, systems, and infrastructure services
  • Provide expert guidance on remediating identified security flaws and vulnerabilities
  • Stay current with evolving security threats and compliance standards to ensure continuous improvement of security measures
Required: Education + Experience
  • Veracode experience is a must
  • 6+ years of Information Technology experience
  • 3+ years of experience with supporting Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE Plug-in environments using Veracode
  • 2+ years of experience with Java, Python, .NET, or C#
  • 3+ years of experience with Burp Suite
  • 3+ years of experience using the design and implementation of enterprise-wide security controls to secure applications, systems, network, or infrastructure services
  • Experience with Eclipse, JDeveloper, including pipeline development, or Visual Studio
  • Experience with securing enterprise web applications and OWASP Top 10, CVSS, CWE, WASC, and SANS-25
  • Knowledge of federal compliance standards, including NIST 800-53, FIPS, or FedRAMP
  • Knowledge of Linux or UNIX environments, including navigating and troubleshooting basic website connectivity issues
  • Ability to obtain a security clearance
  • HS diploma or GED
  • U.S. citizenship and ability to obtain a Public Trust clearance
> Desired Skills and Experience
  • Bachelor's degree in Computer Science, Information Technology, Information Security, or a related field
  • Experience with Interactive Application Security Testing (IAST) tools and methodologies
  • Proficiency with Selenium for automated testing
  • Skill in writing bash scripts for security automation
  • Hands-on experience with OWASP ZAP or Burp Proxy
  • Certifications in application security or related fields (e.g., CSSLP, OSCP, GWAPT)
Security Clearance
  • U.S. Citizenship required
  • Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Public Trust determination is required
If you thrive on complex problem-solving, enjoy providing innovative solutions, and want to have a meaningful impact on national security, let's explore the possibility of working for phia

#LI-LC1

Who You Are

A proactive problem solver that appreciates the challenges of working in a fast-paced, dynamic environment.

Intellectually curious with a genuine desire to learn and advance your career.

An effective communicator, both verbally and in writing.

Customer service-oriented and mission-focused.

Critical thinker with excellent problem-solving skills

If your experience and qualifications aren't a match for this position, you will remain in our database for consideration for future opportunities that may be a better fit.

Who We Are

phia, LLC is a Northern Virginia-based, small business established in 2011 with a focus on Cyber Intelligence, Cyber Security/Defense, Intrusion Analysis & Incident Response, Cyber Architecture & Capability Analysis, Cyber Policy & Strategy, and Information Assurance/Security. we proudly support various agencies and offices within the Department of Defense (DoD), Federal government, and private/commercial entities.

phia values work-life balance and offers the following benefits to full-time employees:

Comprehensive medical insurance to include dental and vision

Short Term & Long-Term Disability

401k Retirement Savings Plan with Company Match

Tuition and Professional Development Assistance Flex Spending Accounts (FSA)

phia does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity, or any other reason prohibited by law in the provision of employment opportunities and benefits.

Please be aware job applicants have rights under federal employment laws. You can find more information about The Family Medical Leave Act (FMLA), Know Your Rights (EEO), and Employee Polygraph Protection Act (EPPA) on The U.S. Department of Labor (DOL)'s website HERE. Frequently Asked Questions - United States Department of Labor

  • Pasco, Washington, United States Tech Talent Link, Inc Full time

    ***We are unable to work with 3rd-party or corp-to-corp candidates for this position*** Overview: Our client will be hiring a full-time Application Security Engineer with an interest in learning Azure. This organization is going through transformational change; timing is ideal to get on board HYBRID role - 3 days per week onsite in Vancouver, WA. ...


  • Pasco, Washington, United States Agile Defense Full time

    About Agile DefenseWe are a leading provider of adaptive innovation and security solutions to our nation's most important missions. Our team of experts is dedicated to providing seamless integration of advanced technologies and exceptional service to our clients.The RoleThis Senior Application Security Engineer position is a critical part of our application...


  • Pasco, Washington, United States Agile Defense Full time

    At Agile Defense we know that action defines the outcome and new challenges require new solutions. That's why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next. Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of...


  • Pasco, Washington, United States Snapchat Full time

    Snap Inc is a technology company. We believe the camera presents the greatest opportunity to improve the way people live and communicate. Snap contributes to human progress by empowering people to express themselves, live in the moment, learn about the world, and have fun together. The Company's three core products are Snapchat, a visual messaging app that...

  • Security Engineer

    4 weeks ago


    Pasco, Washington, United States Glocomms Full time

    Job Opportunity: DevSecOps Engineer Join a leading technology company specializing in real estate information and analytics. They are seeking a skilled DevSecOps Engineer to enhance the security and scalability of their web applications using cutting-edge tools and practices. Key ResponsibilitiesImplement and maintain security controls for cloud and...


  • Pasco, Washington, United States Agile Defense Full time

    Job DescriptionIn this role, you will work closely with our clients and engineers to maintain a resilient security posture for our highly visible applications. Your expertise in remediation, threat modeling, and testing will be invaluable in helping us to identify and mitigate potential vulnerabilities.Responsibilities and Requirements* Remediate application...


  • Pasco, Washington, United States Palantir Technologies Full time

    Safeguard Our NetworkWe're seeking an experienced Principal Infrastructure Security Engineer to join our team at Palantir Technologies. As a key member of our security team, you'll be responsible for designing, architecting, and implementing defensive security controls across our multi-cloud, multi-tenant SaaS infrastructure. This involves ensuring the...


  • Pasco, Washington, United States Top Secret Clearance Jobs Full time

    About the job Information Security Engineer - CIRT Top Secret Clearance Jobs is dedicated to helping those with the most exclusive security clearance find their next career opportunity and get interviews within 48 hours. A World-Changing CompanyPalantir builds the world's leading software for data-driven decisions and operations. By bringing the right data...

  • Security Engineer

    2 days ago


    Pasco, Washington, United States Element Solutions Full time

    Who is Element? We serve as a partner at the intersection of innovation and our clients' needs, efficiently crafting meaningful user experiences for government and commercial customers. By breaking down complex problems to their fundamental elements, we create modern digital solutions that drive efficiencies, maximize taxpayer dollars, and deliver essential...


  • Pasco, Washington, United States Palantir Technologies Full time

    A World-Changing Company Palantir builds the world's leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As an Information Security Engineer, you are...


  • Pasco, Washington, United States Vets Hired Full time

    About the job Information Security Engineer Responsibilities:Conduct thorough reviews of customer toolset configurations to ensure compliance with security standards and customer organizational policies. Conduct in depth enterprise configuration and logging reviews to ensure compliance with OMB M-21-31. Recommend solutions in alignment with customer...


  • Pasco, Washington, United States Envisioneering Inc Full time

    Job Title Information System Security Engineer (ISSE) Location Washington, DC 20375 US (Primary) Job Type Full-Time Education Certification How much will you travel if the job requires it? 0 - 25% Minimum Security Clearance Required TS Job Description Envisioneering, Inc. is seeking an Information Systems Security Engineer (ISSE). This position will be...


  • Pasco, Washington, United States Envisioneering Inc Full time

    Job Title Information System Security Engineer (ISSE) Location Washington, DC 20375 US (Primary) Job Type Full-Time Education Certification How much will you travel if the job requires it? 0 - 25% Minimum Security Clearance Required TS Job Description Envisioneering, Inc. is seeking an Information Systems Security Engineer (ISSE). This position will be...


  • Pasco, Washington, United States Glocomms Full time

    Job Title: Offensive Security Lead Responsibilities: Lead purple team activities in collaboration with threat management and defensive blue teams, including adversary emulation and validation of detective, defensive, and vulnerability controls. Plan and oversee external red team engagements with external partners. Oversee and mentor other offensive security...


  • Pasco, Washington, United States Top Secret Clearance Jobs Full time

    About the Role Top Secret Clearance Jobs is a dedicated platform for high-clearance job seekers and employers. Our mission is to provide a seamless connection between talent and opportunity, ensuring that candidates with the right skills and experience can thrive in their careers. A Leader in InnovationPalantir is a pioneer in the field of data analytics,...


  • Pasco, Washington, United States FIS Full time

    Job Description We are Atelio by FIS, and our mission is to empower developers across all verticals to easily imagine, create, and monetize financial products to profoundly transform the way the entire financial industry consumes services. Today, it's difficult for many businesses to build the financial products they imagine. Whether that's launching a new...


  • Pasco, Washington, United States Everfox Full time

    Job Description:The ideal candidate will have previous experience providing administrator or SME level support for endpoint security solutions, such as HBSS, Tanium, CrowdStrike, etc. We are seeking a skilled Cyber Security Engineer to join our professional services engineering team.Key Responsibilities:• Installing, maintaining, upgrading/patching, and...


  • Pasco, Washington, United States VECTRA Full time

    Vectra is the leader in AI-driven threat detection and response for hybrid and multi-cloud enterprises. The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Powered by patented Attack Signal Intelligence, it empowers security teams to rapidly prioritize, investigate and respond...


  • Pasco, Washington, United States Sayari Full time

    About Sayari: Sayari is the transparency company providing the public and private sectors with immediate visibility into complex commercial relationships by delivering the largest commercially available collection of corporate and trade data as a dynamic model of global ownership and trade activity. Sayari's solutions harness this model to enable risk...


  • Pasco, Washington, United States Palantir Technologies Full time

    A World-Changing Company Palantir builds the world's leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a Principal Infrastructure Security Engineer,...