Application Security Engineer

Leidos, Inc.
Ashburn, VA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Regular working hours

Tech stack

Agile Methodology Artificial Intelligence Configuration Management Computer Programming Continuous Integration Elasticsearch Machine Learning Systems Development Life Cycle Software Tools Ansible Cloudera Secure Coding
+14 more
Software Engineering Software Vulnerability Management Data Logging Webinspect Scripting Software Security Gitlab Kubernetes Infrastructure Automation Frameworks Information Technology Rancher Microfocus Static Application Security Testing Dynamic Application Security Testing

Job description

Application Security Operations and Maintenance, Application Security Configuration Management and Application Security Logging and Vulnerability Management :

  • Ensure continuous monitoring of all CSD managed applications and implement an alerting system for critical incidents
  • Participate in market research to identify new security solutions as required to avoid obsolescence and to improve the overall security posture
  • Develop, deploy, maintain, and/or assist in the implementation and integration of Machine Learning (ML) and Artificial Intelligence (AI) into CBP’s security tool suite.
  • Integrate security best practices into the software development life cycle (SDLC) and ensure security is embedded from design to deployment.
  • Utilize SAST tools to analyze source code for vulnerabilities.
  • Work closely with development teams and ISSOs to remediate identified security issues.
  • Conduct security assessments using Microfocus WebInspect and other DAST tools.
  • Collaborate with development teams to address and remediate dynamic security findings.
  • Implement and manage container security tools, with a focus on Anchore, to ensure secure container deployments.
  • Provide recommendations for secure container orchestration.
  • Work on ensuring systems and applications comply with Security Technical Implementation Guide
  • Establish and maintain the definitive current basis for control and status accounting of application systems and their configuration items.
  • Select configuration items at appropriate levels for application products to facilitate documentation, control
  • Tune logging capabilities for efficiency, identify shortfalls, and recommend improvements and new technologies for application logging.
  • Support the CSD Service Desk in managing and executing the Vulnerability Identification and Remediation process for applications.

Requirements

  • BS degree in Information Technology, Software Engineering, or related field and 8 - 12 years of prior relevant experience
  • 3+ years of prior experience in application security with a focus on SAST, SCA, DAST
  • Knowledge of secure coding practices and integration into SDLC
  • Familiarity with common security frameworks and standards
  • Strong programming/scripting skills
  • Excellent communication and collaboration skills
  • Working in an Agile project management environment
  • Must have a Top Secret Clearance with SCI
  • Must be able to report into the Ashburn VA office up to 5 days per week.

  • Master’s with 1-2 years of prior experience in application security with a focus on SAST, SCA, DAST
  • Experience with data engineering tools such as Kubernetes/Rancher, Cloudera
  • Experience with Configuration Management and IaC tools such as Salt or Ansible
  • Experience with scripting languages, CI/CD tools, Elasticsearch, or Gitlab
  • Experience working in an air-gapped environments
  • Experience working in large computing environments (> 1,000 end-points)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · WWC 2024

3:47 min

Comparing declarative GitOps tooling alternatives and interface priorities

Davide Imola Davide Imola · LIVE

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:19 min

Executing complex workflows using Ansible Automation Platform

Goetz Rieger Goetz Rieger · WWC 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all