Senior Application Security Engineer

4 weeks ago


Washington, United States TalentRemedy Full time

The Sr. Application Security Engineer is a technology and process focused security professional with extensive experience in Development Operations, Software Engineering, Application Security and/or Information Security disciplines. This individual will be at the forefront of our security efforts, partnering closely with product and application developers to establish and elevate best practices for secure software development. They will advise, implement, and train teams on the processes, tools, and automation needed to fortify the SDLC and safeguard our products and applications.


The Sr. Application Security Engineer is a full-time, remote, exempt position and reports to the CISO.


Specific Responsibilities:


  • Play a lead role in developing expert knowledge of Product Security, requirements, tools, and working methods across our organization.
  • Ideate, communicate, and guide the implementation of complex vulnerability mitigation strategies to development teams.
  • Conduct manual and automated security assessments and code reviews to identify vulnerabilities within applications.
  • Collaborate with Product, Technology, and broader security teams to provide recommendations for solutions focused on decreasing business risks.
  • Perform threat modeling to identify potential security issues before they can be exploited. This involves understanding the attack surface of applications and predicting potential attack vectors.
  • Deliver reports on completed tests and document technical issues identified during the assessments.
  • Evaluate, select, and deploy security tooling to automate the detection of security vulnerabilities. This may include integrating security tools into continuous integration/continuous deployment (CI/CD) pipelines.
  • Lead or participate in the response to security incidents, including conducting post-mortem analysis to prevent future occurrences.
  • Ensure applications comply with relevant security standards and regulations. This may involve collaborating with auditors and performing regular security assessments.


Supervisory Responsibilities:


None.


Skills:


  • Understanding of containerization technologies.
  • Demonstrated expertise in product/application security architecture.
  • Experience with threat modeling, risk analysis and control design.
  • In depth knowledge of network security, authentication, and authorization.
  • Experience with Security integration into CI/CD and experience in driving CI/CD adaptation for security controls.
  • Advanced understanding of vulnerability exploitation chaining, and vulnerability remediation.
  • Strong familiarity with software development lifecycle (SDLC) processes and source control technologies.


Experience:


  • 7+ Years of overall IT Experience with a major emphasis on application security.
  • Development experience in any modern programming language (including but not limited to Python, C++, Rust, Go).
  • Strong knowledge of Cloud Providers (Azure).


Education:


  • Bachelor’s degree in computer science or related field or possess the equivalent combination of industry related professional experience and education.
  • GWEB, CASE, CISSP, CSSLP certifications preferred.



  • Washington, United States SourcePro Search Full time

    SourcePro Search is conducting a search for an experienced Senior Application Security Engineer in Washington, DC. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This position collaborates with business units, project management, and engineering teams...


  • Washington, United States SourcePro Search Full time

    SourcePro Search is conducting a search for an experienced Senior Application Security Engineer in Washington, DC. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This position collaborates with business units, project management, and engineering teams...


  • Washington, United States Global Solutions Consulting (GSC) Full time

    Job DescriptionJob DescriptionPosition Title: Senior Application Security EngineerLocation: Washington, DC (Hybrid)Job Requirements:Strong written and verbal communication skills· Must have GitLab CI/CD pipeline experience· Assist in the development and implementation of the DevSecOps strategy to include the definition and goals of the over-arching...


  • Washington, United States Iron Vine Security Full time

    Job Requirements: · Strong written and verbal communication skills. · Experience designing, implementing, and maintaining IT security systems to protect digital assets from malicious cyber-attacks. · Experience developing and implementing an annual Incident Response Training and Testing Program · Experience implementing, configuring, and...


  • Washington, United States 3M Consultancy Full time

    Job DescriptionJob DescriptionThis is a remote position. Job Title: Senior Security Engineer. Location: Washington, DC (Remote) Duration: Full-Time. Role Specific Duties: Provide network IDS monitoring, cyber threat intelligence, security log analysis and forensics, and web application security scanning and analysis. Protect users by performing internal...


  • Washington, United States MDS (Micro-Data Systems) Full time

    Senior Security EngineerRemote, but prefer candidates to be located in the Washington, DC Metro AreaJob DescriptionYou will provide guidance and technical support to clients deploying security integrations. You'll act as the technical partner, providing strategic guidance around complex systems to secure a digital environment. Interacting directly with the...


  • Washington, United States MDS (Micro-Data Systems) Full time

    Senior Security EngineerRemote, but prefer candidates to be located in the Washington, DC Metro AreaJob DescriptionYou will provide guidance and technical support to clients deploying security integrations. You'll act as the technical partner, providing strategic guidance around complex systems to secure a digital environment. Interacting directly with the...


  • Washington, United States MDS (Micro-Data Systems) Full time

    Senior Security EngineerRemote, but prefer candidates to be located in the Washington, DC Metro AreaJob DescriptionYou will provide guidance and technical support to clients deploying security integrations. You'll act as the technical partner, providing strategic guidance around complex systems to secure a digital environment. Interacting directly with the...


  • Washington, United States Latitude, Inc. Full time

    Job DescriptionJob DescriptionNew Job Opportunity - Senior Network Security Engineer:New and exciting job opportunity with a client based out of Washington, DC. Looking to hire an experienced Sr. Network Security Engineer with at least 8 years of prior related professional experience (High level Network Security Engineer / Cybersecurity support experience)....


  • Washington, United States VISTRADA Full time

    Job DescriptionJob DescriptionJob Posting: Security System Engineer (Junior/Intermediate/Senior Level)Vistrada is currently seeking highly skilled and motivated Security System Engineers to join our esteemed team. As a Security System Engineer, you will play a crucial role in identifying and mitigating vulnerabilities, ensuring the secure integration and...


  • Washington, United States Gridiron IT Solutions LLC Full time

    Job DescriptionJob DescriptionGridIron IT is hiring a Senior Security Engineer to work on a remote basis.This role offers the exciting opportunity to manage vulnerabilities, conduct security scans using leading tools, and oversee the security infrastructure. You'll gain a strong understanding of FedRAMP and compliance frameworks to maintain high-security...


  • Washington, United States Vantage Point Consulting Inc. Full time

    The Senior Applications Engineer, Cloud Solutions acts as IT owner of various applications and productivity tools tied to the M365 platform and other cloud vendors. These include MS Teams, Copilot and IntApp Workspaces. This is a highly skilled technical position responsible for strategy, day-to-day oversight and support of assigned systems. This is an...

  • Senior Cloud Engineer

    2 weeks ago


    Washington, United States Cordia Resources by Cherry Bekaert Full time

    Our client has a Senior Cloud Engineer opening. This position may work 100% virtual/remote in a firm approved U.S. state. The Senior Cloud Engineer is responsible for partnering and working with IT engineering teams in the review and implementation of the firm's infrastructure and transition to hybrid cloud technology that includes compute, storage...

  • DHS HSEN

    4 weeks ago


    Washington, United States Versar, Inc. Full time

    Job DescriptionJob DescriptionPosition SummaryBayFirst Solutions, a subsidiary of Versar, Inc., is seeking a Senior Security Engineer (DevSecOps) to support the Department of Homeland Security’s Enterprise Engineering Division (EED) within the Office of the Chief Information Officer (OCIO). This candidate will be a member of a high functioning team...

  • DHS HSEN

    4 weeks ago


    Washington, United States Versar, Inc. Full time

    Job DescriptionJob DescriptionPosition SummaryBayFirst Solutions, a subsidiary of Versar, Inc., is seeking a Senior Security Tools Engineer to support the DHS’ Homeland Security Enterprise Network (HSEN) within the Office of the Chief Information Officer (OCIO), IT Operations, Enterprise Engineering Division (EED). This Security Tools Engineer will be a...


  • Washington, United States Versar, Inc. Full time

    Job DescriptionJob DescriptionPosition SummaryVersar, Inc., is seeking a Senior Security Engineer (Compliance) to support the Department of Homeland Security’s Enterprise Engineering Division (EED) within the Office of the Chief Information Officer (OCIO). This candidate will be a member of a high functioning team supporting cybersecurity countermeasures...


  • Seattle, Washington, United States Block Full time

    Job Description The Cloud Security Risk and Insights team is responsible for discovering, tracking and enabling the business to remediate the biggest security risks we face across Block’s cloud ecosystems. We drive the creation of security policy and best practices. We measure and aggregate deviations from these policies. We develop capabilities to...


  • Washington, United States Dynamis, Inc. Full time

    Job DescriptionJob DescriptionDynamis is seeking a Sr. Applications Software Programmer/Senior Engineer to support a data analytics contract in support of a US government client's mission. In this role the ideal candidate will develop information systems by studying operations; designing, developing, and installing software solutions; support and develop...


  • Washington, United States System One Holdings, LLC Full time

    Title: Sr Principal Security Engineer for HSM ALTA is supporting a direct hire opportunity.This position is 100% Onsite for initial 3-6 months and then remote 1-2 days/week and onsite 3-4 days/week after that.Location is in the National Harbor area, south of Washington DC. ALTA IT Services is a wholly owned subsidiary of System One, a leading provider of...


  • Washington, United States UPSLOPE ADVISORS, INC Full time

    Job DescriptionJob DescriptionSalary: UpSlope Advisors is seeking an exceptional candidate to serve as an Application Engineer SME.  The customer requires support to provide enterprise-level service desk and incidental information technology services. Services include: Help Desk Support, IT Operations Management and Support, Mobile Support, IT Asset...