
Application Security Engineer
Booz Allen Hamilton2 days ago
Base Salary
$87k - $198k/yr
Responsibilities
- Integrate security practices throughout the software development lifecycle and maintain the security posture of software.
- Implement or assess Secure SDLC and application security programs, including architecture reviews, threat modeling, and security assessments.
- Evaluate software supply chain security practices, including SBOMs, dependency management, code signing, artifact integrity, and secure build pipelines.
- Assess application security capabilities such as SAST, DAST, SCA, IaC scanning, container security, API security, secrets detection, and software composition analysis.
- Lead client engagements, manage multiple priorities, and develop solutions to complex application security problems.
- Translate technical risks into executive-level briefings, business cases, and actionable roadmaps.
- Lead executive workshops, stakeholder interviews, and technical design sessions.
- Mentor junior team members, provide technical leadership, and contribute to practice development and thought leadership.
- Develop technical proposals, respond to RFPs, create Statements of Work, and support business development initiatives.
Requirements
- 5+ years of experience in cybersecurity, application security, product security, or software engineering.
- Experience implementing or assessing Secure SDLC and application security programs.
- Experience with client engagements, architecture reviews, threat modeling, security assessments, and managing multiple priorities.
- Experience with software supply chain security concepts, including SBOMs, dependency management, code signing, artifact integrity, and secure build pipelines.
- Experience implementing or evaluating SAST, DAST, SCA, IaC scanning, container security, API security, secrets detection, and software composition analysis tools.
- Knowledge of secure software development principles, cloud-native architectures, microservices, APIs, containers, Kubernetes, and serverless environments.
- Knowledge of authentication, authorization, cryptography, API security, cloud security, vulnerability management, risk prioritization, and remediation workflows.
- Ability to communicate complex technical risks to technical and executive stakeholders.
- Bachelor's degree in computer science, cybersecurity, information systems, or engineering.
- Preferred experience designing or maturing enterprise application security and product security programs.
- Preferred experience with secure development requirements for regulated industries such as healthcare, financial services, industrial control systems, automotive, aerospace, or critical infrastructure.
- Preferred experience with OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, and MITRE ATT&CK or ATLAS.
- Preferred experience with technical proposals, RFPs, Statements of Work, executive workshops, stakeholder interviews, and technical design sessions.
- Excellent written, verbal communication, and facilitation skills.
- Master's degree in cybersecurity, computer science, software engineering, information assurance, or a related technical field is preferred.
- Ability to travel up to 50% depending on client needs.
Benefits
- Health, life, disability, financial, and retirement benefits.
- Paid leave, professional development, tuition assistance, work-life programs, and dependent care.
- Recognition awards for exceptional performance and demonstration of company values.
- Benefits eligibility is available to full-time and part-time employees working at least 20 hours per week on a regular basis, with select offerings for others.
- Travel may be required up to 50% depending on client needs.
- The position is subject to Booz Allen's applicable remote, hybrid, or onsite work model and may require work at company or customer facilities.
Tech Stack
Categories
About Booz Allen Hamilton
Booz Allen Hamilton builds and integrates software, analytics, AI, cloud, and cybersecurity solutions while providing engineering and consulting services, primarily for U.S. defense, intelligence, and civil government clients, with select commercial partnerships. Its business is largely government contracting and professional services delivering mission systems and cyber defense. Founded in 1914 and headquartered in McLean, Virginia, Booz Allen is a public company traded on the NYSE (ticker: BAH).