
Application Security Engineer (Full Scope Poly)
Concept Plus, LLC28 days ago
Reston, VA, USASenior
Responsibilities
- Integrate security throughout the software development lifecycle for mission applications.
- Partner with developers and cloud engineers on secure application and cloud-native solution design.
- Conduct secure architecture reviews, threat modeling, secure code reviews, security testing, vulnerability remediation, and release authorization support.
- Develop or review applications using Python, JavaScript frameworks, SQL, Shell scripting, PL/SQL, and other programming languages.
- Implement SAST, DAST, SCA, secrets scanning, and container or infrastructure vulnerability scanning processes.
- Build and secure applications and services using Kubernetes, containers, Docker, REST APIs, and CI/CD pipelines.
- Implement DevSecOps practices, including automated security controls and testing in build and deployment pipelines.
- Secure Oracle RDBMS environments through access controls, encryption, auditing, and sensitive-data handling.
- Assess, prioritize, document, and communicate application and cloud security risks and remediation recommendations.
- Support cloud security capabilities including IAM, privileged access controls, secrets management, encryption, logging, monitoring, and incident response.
Requirements
- U.S. citizenship is required.
- A TS/SCI security clearance with polygraph is required.
- At least 8 years of relevant experience in application security, software engineering, DevSecOps, cybersecurity, or a related technical discipline is required.
- A bachelor’s degree in engineering, computer science, or a related technical discipline is required; a master’s degree is preferred.
- Hands-on application security, secure software development, software engineering, or DevSecOps experience is required.
- Experience securing cloud-native applications and services, with Oracle Cloud Infrastructure experience desired.
- Knowledge of NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, and applicable federal security requirements.
- Experience with security testing processes including SAST, DAST, SCA, secrets scanning, and container or infrastructure vulnerability scanning.
- Preferred certifications include Oracle Cloud Infrastructure IaaS or PaaS certifications and security credentials such as CISSP, CSSLP, Security+, GIAC, CEH, or OSCP.
- Experience with AI technologies for software development, securing AI-enabled applications, or securing development workflows is preferred.
- Data engineering experience involving data validation, business rules, data transformations, and sensitive-data handling is preferred.
- Experience working in an Agile framework is required.
Benefits
- Fully onsite in Reston, Virginia, five days per week.
- Competitive pay, comprehensive health, dental, and vision insurance.
- Paid life insurance, paid time off, and 11 paid holidays.
- Performance bonuses, tuition reimbursement, and unlimited training.
- Collaborative, flexible, and innovative work environment.