
Application Security Engineer
Booz Allen Hamilton4 days ago
Base Salary
$62k - $141k/yr
Responsibilities
- Collaborate with clients, application owners, and development teams to maintain security for highly visible and business-critical applications.
- Identify, prioritize, and remediate application security vulnerabilities throughout the software development lifecycle.
- Lead security discussions and advise application teams on secure development practices, security requirements, and application security best practices.
- Perform SAST, DAST, threat modeling, and application-level security assessments using tools such as Veracode and Burp Suite DAST.
- Design and implement enterprise-wide security controls and help development teams apply remediation strategies.
- Monitor emerging application security threats and vulnerabilities and apply OWASP frameworks, standards, and best practices.
Requirements
- Require 6+ years of experience in information technology, cybersecurity, or application security.
- Require 3+ years of experience with Java, Python, .NET, or C#.
- Require 3+ years of experience using Burp Suite DAST to perform DAST.
- Require 3+ years of experience designing and implementing enterprise-wide security controls for applications, systems, networks, or infrastructure services.
- Require 3+ years of experience with Linux or UNIX environments, including system navigation and troubleshooting basic website connectivity issues.
- Require 2+ years of experience with Veracode and development environments such as Eclipse and JDeveloper, including pipeline development and integration.
- Require experience securing enterprise web applications and frameworks, including OWASP Top 10, CVSS, CWE, WASC, and SANS-25.
- Require knowledge of federal security and compliance standards including NIST 800-53, FIPS, or FedRAMP.
- Require a high school diploma or GED.
- Must be able to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements.
- Experience with Interactive Application Security Testing (IAST) capabilities and tools is preferred.
- Applicants selected will be subject to a government investigation and may need to meet U.S. government client eligibility requirements.
Benefits
- Benefits include health, life, disability, financial, and retirement programs; paid leave; professional development; tuition assistance; work-life programs; dependent care; and recognition awards.
- Regular full-time and part-time employees working at least 20 hours per week are eligible for Booz Allen benefits, while employees below that threshold are eligible only for select offerings.
- Virtual employees may occasionally be required to work in person at a Booz Allen or customer facility, and hybrid or onsite work follows leadership and customer-facility expectations.
- Employees working virtually are generally expected to keep cameras on during meetings.
About Booz Allen Hamilton
Booz Allen Hamilton builds and integrates software, analytics, AI, cloud, and cybersecurity solutions while providing engineering and consulting services, primarily for U.S. defense, intelligence, and civil government clients, with select commercial partnerships. Its business is largely government contracting and professional services delivering mission systems and cyber defense. Founded in 1914 and headquartered in McLean, Virginia, Booz Allen is a public company traded on the NYSE (ticker: BAH).