Cybersecurity Engineer - Applications

Bright Vision Technologies
Herndon, VA, United States
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$100,000.0 - $150,000.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Application Portfolio Management Cloud Computing Security Code Review Cyber Security Continuous Integration Open Source Technology Open Web Application Security Runbook Session Management Software Engineering Software Vulnerability Management
+10 more
Cloud Platform System Large Language Models Software Security GWAPT Kubernetes Information Technology Tenable Nessus Static Application Security Testing Programming Languages Dynamic Application Security Testing

Job description

We are looking for an Cybersecurity Engineer - Applications to embed security throughout the software development lifecycle, partnering with engineering teams to design secure systems, identify vulnerabilities, and reduce risk across our application portfolio. The role blends hands-on offensive and defensive skills with strong communication and collaboration, helping development teams build secure software efficiently rather than slowing them down. The ideal candidate brings deep technical security expertise, strong software engineering fundamentals, and a track record of shipping security improvements that meaningfully reduce risk in production. Key Responsibilities

  • Conduct threat modeling and security architecture reviews for new and existing applications and services.
  • Perform manual code reviews, secure design consultations, and pair with engineering teams on hardening critical components.
  • Operate and tune SAST, DAST, IAST, SCA, and secret-scanning tools across CI/CD pipelines.
  • Drive vulnerability management workflows including triage, prioritization, owner assignment, and SLA tracking.
  • Build paved-road libraries and frameworks that make secure patterns the default for engineering teams.
  • Lead red-team and purple-team exercises against internal applications and drive remediation of identified weaknesses.
  • Implement and operate runtime protections including WAF, RASP, bot protection, and abuse-detection mechanisms.
  • Design and enforce secure authentication, authorization, session management, and cryptographic patterns.
  • Partner with infrastructure and platform teams to harden container, Kubernetes, and cloud environments.
  • Develop and deliver application security training, lunch-and-learns, and onboarding content for engineering staff.
  • Respond to security incidents involving application vulnerabilities or active exploitation.
  • Track and apply emerging threats and CVEs that may affect the application portfolio.
  • Maintain comprehensive, current technical documentation - including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures - so that the system remains supportable, auditable, and easy to onboard new engineers onto over time.
  • Stay current with application security research and emerging defensive tooling.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
  • Five or more years of application security or security engineering experience.
  • Strong understanding of OWASP Top 10, common vulnerability classes, and modern exploit patterns.
  • Hands-on experience performing code review across at least two major languages.
  • Deep familiarity with SAST, DAST, SCA, and CI/CD-integrated security tooling.
  • Strong understanding of authentication, authorization, and cryptographic primitives.
  • Experience with cloud security and modern infrastructure controls.
  • Strong communication skills with technical and non-technical audiences.
  • Proficiency in at least one programming language for tooling and automation.
  • Experience working closely with engineering teams in an Agile environment.

Preferred Qualifications

  • Industry certifications such as OSCP, OSCE, GWAPT, or CISSP.
  • Experience with offensive security tooling and red-team operations.
  • Bug bounty experience, public CVEs, or open-source security contributions.
  • Familiarity with AI/LLM application security considerations.
  • Exposure to regulated industries with strict compliance requirements.

About the company

Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States. This is a fantastic opportunity to join an established and well-respected organization offering tremendous career growth potential., Vantor

  • McLean, VA
  • $161,000-236,500 per year Vantor is forging the new frontier of spatial intelligence, helping decision makers and operators navigate what’s happening now and shape what’s coming next. Vantor is a place for …

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · WWC Europe 2026

4:04 min

Overview of Kubernetes operators and custom resource definitions

Philipp Krenn · WWC 2022

Videos

See all

Related articles

See all