Senior Application Security Engineer

4 weeks ago


Washington, United States Global Solutions Consulting (GSC) Full time
Job DescriptionJob Description

Position Title: Senior Application Security Engineer

Location: Washington, DC (Hybrid)

Job Requirements:

  • Strong written and verbal communication skills

· Must have GitLab CI/CD pipeline experience

· Assist in the development and implementation of the DevSecOps strategy to include the definition and goals of the over-arching framework and methodologies

· Assist customers with implementing a secure CI/CD pipeline utilizing DevSecOps principles and practices to increase automation and reduce human involvement in the process

· Reviewing source code for potential security vulnerabilities

· Strong analytical skills to assess risks and vulnerabilities in complex systems

· Writing security test cases to check for vulnerabilities or broken/missing security controls.

· Implement automated security controls as part of CI/CD pipelines

· Support development teams with secure code (DAST, SAST, Dependency, Secret Detection, Container scans, etc.) reviews and other assessments to identify security weaknesses and vulnerabilities

· Establish and maintain secure coding standards and best practices to provide guidance and training to development teams on security best practices

· Recommend cyber defense and vulnerability assessment tools

· Review and research monthly continuous monitoring controls documentation tasks that is required by OIS

· Continuous Process Improvement, actively contribute to the development of standardized operating procedures (SOPs) for API security testing

· Collaborate closely with cross-functional teams, including system administrators and Information System Security Officers (ISSOs)

 

Security Clearance Requirement:

· Active Public Trust and eligible to obtain a Secret clearance

 

Certifications/Licenses:

  • At least Ten (10) years of experience working in cybersecurity or information technology with a bachelor’s degree. Minimum of 5 years’ experience in vulnerability management, application and software security team, Malware analysis, digital forensics, data/network analysis, penetration testing, information assurance, leading incident handling
  • Solid experience in application security and software development in one or more programming languages such as C#, Java, Python, etc
  • Experience with security tools such as SAST, DAST, IAST, SCA and other security tools

· Familiarity with industry-standard security frameworks such as OWASP, NIST, BSIMM etc

· Experience with CICD pipeline, security tools integration and secure SDLC

  • Knowledge of current and emerging threats and techniques for exploiting security vulnerabilities
  • CISSP, OSCP, any DevSecOps or other related Information Security certification
  • Experience with cloud-based infrastructure (AWS, Azure, or GCP)
Company DescriptionGSC is a leading cyber security and information technology company based in Washington, DC. We are looking to hire a Senior Security Application Engineer to support a full range of cyber security services on a long-term contract in Washington DC. The position is full-time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background and security clearance.Company DescriptionGSC is a leading cyber security and information technology company based in Washington, DC. We are looking to hire a Senior Security Application Engineer to support a full range of cyber security services on a long-term contract in Washington DC. The position is full-time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background and security clearance.

  • Washington, United States SourcePro Search, LLC Full time

    Our top rated global client is looking for an experienced Senior Application Security Engineer for their Washington, DC office. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This position collaborates with business units, project management, and...


  • Washington, United States Iron Vine Security Full time

    Job Requirements: · Strong written and verbal communication skills. · Experience designing, implementing, and maintaining IT security systems to protect digital assets from malicious cyber-attacks. · Experience developing and implementing an annual Incident Response Training and Testing Program · Experience implementing, configuring, and...


  • Washington, United States Micro Data Systems Full time

    Senior Security EngineerRemote - Washington DC Metro Area preferredYour ImpactWork full-time at the customer siteCommunicate with the customer(s), sales teams, peers, engineering and support teams as appropriateUnderstand the customer environment, requirements, and security roadmap to implement the appropriate security solutionConfigure, implement, and...


  • Washington, United States Bank of America Full time

    Senior Security EngineerLocation: Denver, Colorado; Washington, District of Columbia; Chicago, IllinoisJob Description:The Senior Security Engineer is responsible for leading multiple security engineering efforts that deliver enterprise security capabilities. This will include serving as a subject matter expert of security technology and acting as the...


  • Washington, United States Cherokee Federal Full time

    Senior Cloud Security EngineerAs required by our governmental client, this position requires being a US Citizen.Requires a Top-Secret Clearance.A Senior Cloud Security Engineer with over 5 years of experience in information security focuses on risk and compliance. They conduct ISO 27001 and SOC 2 audits, handle audit responses, and ensure regulatory...


  • Washington, United States ManTech Full time

    Become an integral part of a diverse team while working at an Industry Leading Organization, where our employees come first. At ManTech International Corporation, you’ll help protect our national security while working on innovative projects that offer opportunities for advancement. Currently, ManTech is seeking a motivated, career and customer-oriented...


  • Washington, United States Amazon Full time

    Senior Security Engineer, AWS Proactive SecurityJob ID: 2721293 | Amazon Development Center U.S., Inc.The Amazon Web Services (AWS) Proactive Security team continuously works to ensure our services and resources are implemented and maintained to meet the highest standards of security. Our mission is to prevent security incidents from happening and when they...


  • Washington, United States Booz Allen Hamilton Full time

    Security Engineer, Senior The Opportunity:   Are you looking for an opportunity to share your experience in Security engineering to safeguard our nation? As a systems security engineer, you can identify the technologies needed to assess vulnerabilities and recommend the best solution and security strategy. We need your experience to develop and implement...


  • Washington, United States Amazon Full time

    Senior Security Engineer , AWS Offensive SecurityJob ID: 2831178 | Amazon Development Center U.S., Inc.Do you enjoy finding unique security issues? Do you enjoy protecting customers at scale? Do you like challenging assumptions? On the AWS Offensive Security team, you will help ensure our devices, applications, services, and systems are designed and...


  • Washington, Washington, D.C., United States SAIC Full time

    This is a senior-level position for the security engineering team within the Cybersecurity Integrity Center (CIC) office, providing engineering leadership over multiple firewall and security systems and devices.The well-qualified candidate will possess comprehensive expertise knowledge regarding security devices and be capable of planning and leading the...


  • Washington, United States VISTRADA Full time

    Job Posting: Security System Engineer (Junior/Intermediate/Senior Level) Vistrada is currently seeking highly skilled and motivated Security System Engineers to join our esteemed team. As a Security System Engineer, you will play a crucial role in identifying and mitigating vulnerabilities, ensuring the secure integration and operation of systems, and...


  • Washington, Washington, D.C., United States GuidePoint Security Full time

    Job SummaryGuidePoint Security is seeking a highly skilled Splunk Security Engineer to join our team. As a Splunk Security Engineer, you will be responsible for driving complex security-focused deployments of Splunk or ArcSight while working side by side with customers to solve their unique problems across a variety of use cases.Key Responsibilities- Drive...

  • Senior Engineer

    2 days ago


    Washington, United States DAn Solutions, Inc Full time

    High-Level Description: The Senior Engineer will be responsible for designing, deploying, and maintaining secure, high-performance cross-domain solutions. This role involves collaboration with multiple stakeholders and ensuring adherence to security standards.Detailed Description: The Senior Engineer will take a lead role in designing and implementing...


  • Washington, Washington, D.C., United States Humana Full time

    Job SummaryConviva Care Centers is seeking a highly skilled Senior Security Architect to join our team. As a key member of our security team, you will play a critical role in implementing security architecture, application security, identity and access management, and compliance with applicable security regulations and frameworks.ResponsibilitiesIdentify...


  • Washington, United States ZipRecruiter Full time

    Position SummaryVersar, Inc., is seeking a Senior Security Engineer (Compliance) to support the Department of Homeland Security’s Enterprise Engineering Division (EED) within the Office of the Chief Information Officer (OCIO). This candidate will be a member of a high functioning team supporting cybersecurity countermeasures to strengthen DHS enterprise...


  • Washington, Washington, D.C., United States TEKsystems Full time

    Job Title: Senior Cloud Security Engineer - Advanced Threat DetectionJob Summary:We are seeking an experienced Senior Cloud Security Engineer to join our Cyber Security Operations team. The ideal candidate must have deep knowledge of security controls, tools, features, and operations for AWS / Azure.Key Responsibilities:Implement and enhance detective...


  • Washington, United States The Staffing Resource Group Inc Full time

    Job DescriptionSenior Information System Security Engineer (ISSE)Location: Washington, DC Industry: Dept. of Defense Salary: $117k-$172k Employment Type: Permanent Placement Clearance: Active TS/SCI clearance and US Citizenship Required Schedule: Monday to Friday, 8am to 5pm Summary: We are seeking a talented and motivated Senior ISSE to join our client s...


  • Washington, United States T-Rex Solutions Full time

    Job DescriptionJob DescriptionT-Rex Solutions is looking to select a Senior Cloud Security Engineer to play a critical role in the management, enhancement, and security of our Department of Treasury TCloud environments. Your deep knowledge in system administration, security administration, and scripting, combined with your proficiency in cloud platforms and...


  • Washington, United States Versar, Inc. Full time

    Job DescriptionJob DescriptionPosition SummaryVersar, Inc., is seeking a Senior Security Engineer (Compliance) to support the Department of Homeland Security’s Enterprise Engineering Division (EED) within the Office of the Chief Information Officer (OCIO). This candidate will be a member of a high functioning team supporting cybersecurity countermeasures...


  • Washington, United States Versar Full time

    Position Summary Versar, Inc., is seeking a Senior Security Engineer (Compliance) to support the Department of Homeland Security’s Enterprise Engineering Division (EED) within the Office of the Chief Information Officer (OCIO). This candidate will be a member of a high functioning team supporting cybersecurity countermeasures to strengthen DHS enterprise...