> Markdown version of [/jobs/ext/1308462-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1308462-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Edgewater Federal Solutions - **Location:** Washington, DC, United States (Remote available) - **Experience:** Experienced - **Salary:** $140,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Windows, Microsoft Azure, Bash Shell, CompTIA Security+, Cyber Security, Continuous Integration, DevOps, Federal Information Processing Standards (FIPS), Github, Information Systems Security Architecture Professional, Python (Programming Language), Linux System Administration, Open Web Application Security, Windows PowerShell, Systems Development Life Cycle, Ansible, Zero Trust Network Access, Secure Coding, Software Vulnerability Management, Data Logging, Scripting, Software Security, Software Troubleshooting, Veracode, Kubernetes, Information Technology, Deployment Automation, Terraform, Static Application Security Testing, Programming Languages, Dynamic Application Security Testing - **Published:** July 17, 2026 - **Apply:** https://www.dice.com/job-detail/08aa81e1-8fd5-43b8-8e8d-dc7d1f83f711 ## About the Role o Experience supporting SAST/DAST environments using Veracode. o Experience with SCA tools and vulnerability remediation o Experience leveraging CI/CD deployment methodologies and infrastructure as code (IaC) o Experience writing playbooks and scripts for automation tools including Terraform, Ansible for IaC o Demonstrate proficiency with a scripting or coding language, preferably Python. o Proficiency in automation and scripting, such as PowerShell, Python, Bash, and Terraform. o Ability to discuss Information Security concepts such as defense in depth and zero trust. o Demonstrate ability to communicate ideas both verbally and in writing to management, business and IT stakeholders, and technical resources in language that is appropriate for each group. o Ability to work collaboratively with developers across multiple departments o Ability to work effectively in a fast-paced, project-oriented environment o Ability to analyze and prioritize vulnerabilities based on risk o Strong technical acumen, communication, and influence skills o Working knowledge of system hardening (CIS, STIGs regulatory compliance) o Experience working with and supporting Unix/Linux and Windows systems. o Experience with SCA tools and vulnerability remediation in containers o Container orchestration and container security experience o 3+ years in application security supporting SAST, DAST, and SCA environments o 3+ years of experience designing and implementing application security controls o 3+ years of experience working in Linux-based environments, including troubleshooting application and connectivity issues. o Knowledge of federal security and compliance standards (NIST 800-53, FIPS, FedRAMP). + Preferred Qualifications: o Experience in securing Azure cloud infrastructure (i.e., inspection, logging, WAF, VM) o Experience with Azure DevOps o Practical implementation and architectural experience in encryption techniques, including data at rest and in transit o Prior experience as a software developer is highly preferred Requirements o Bachelor's degree in computer science or related fields o Minimum of 8 years of experience in Information Security or related fields o CISSP or equivalent (CompTIA Security+, CEH, or DoD equivalent) Preferred Certifications, o ISC2 Certified Information Systems Security Professional (CISSP) ## Description Edgewater is currently seeking an Application Security Engineer who will be a hands-on subject matter expert in Microsoft Azure cloud technologies, application security, security architectures, security tools, and methodologies. The Application Security Engineer will support our federal customer in Washington DC. This is a hands-on technical role that will provide the right candidate with an exciting opportunity to develop the federal customer's application security program, working with developers and the organization to meet the strategic security goals of the agency., * + Drive the strategic maturation of the agency's Application Security (AppSec) program by defining security standards, scaling automation, and embedding secure development practices across all product lifecycles. + Perform SAST assessments using Veracode and GitHub Advanced Security, identifying code-level vulnerabilities and providing remediation guidance. + Conduct and analyze DAST scans, including configuration, execution, and triage of results. + Evaluate and prioritize vulnerabilities using industry frameworks such as CVSS, CWE, OWASP Top 10, WASC, and SANS Top 25. + Collaborate with development, DevOps, and security teams to integrate security controls into CI/CD pipelines and the broader SDLC. + Provide expert advice on secure coding principles and assist developers in resolving security findings. + Troubleshoot application and connectivity issues in Linux-based environments. + Contributes to the design and implementation of enterprise-wide application security controls. + Ensure alignment with federal security and compliance standards, including NIST 800-53, FIPS, and FedRAMP. + Maintain awareness of emerging threats, vulnerabilities, and best practices in application security. ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)