> Markdown version of [/jobs/ext/1737421-cybersecurity-engineer-journeyman](https://www.wearedevelopers.com/jobs/ext/1737421-cybersecurity-engineer-journeyman). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer Journeyman - **Company:** ASM - **Location:** Arlington, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Spring Security, Application Programming Interfaces (APIs), Proxy Servers, Software System Penetration Testing, Burp Suite, Configuration Management, Static Program Analysis, Software Documentation, Code Review, Cyber Security, Databases, DevOps, Distributed Systems, Gradle, Hibernate (Java), Identity and Access Management, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Spring Framework, Key Management, Lightweight Directory Access Protocols (LDAP), Node.Js, Open Web Application Security, Program Analysis, Role-Based Access Control, Fortify (Software), Zero Trust Network Access, Security Assertion Markup Language (SAML), Secure Coding, Security Information and Event Management, Single Sign-On, Software Engineering, Systems Integration, TCP/IP, Vagrant, Web Services, Scripting, Java Application Server, Enterprise Software Applications, Software Security, Firewalls (Computer Science), Backend, Git, Information Technology, Restful APIs, Software Version Control, Devsecops, Jenkins, Vulnerability Analysis - **Published:** July 31, 2026 - **Apply:** https://www.dice.com/job-detail/268289a1-feea-41f3-a6fc-a89e3ce28607 ## About the Role * Bachelor's Degree in Computer Science, Engineering, or other technical discipline, or equivalent relevant experience. * 5-10 years of experience as an Application Security Developer, Application Security Analyst, or equivalent role with direct responsibility for securing web and distributed applications. * Demonstrated hands-on experience implementing and reviewing application security controls and practices across the full software development lifecycle, including architecture review, secure design, code review, and integrated security testing. * Strong experience working with Unix/Linux operating systems and modern source code management tools such as Git in a collaborative development environment. * Solid knowledge of network, system, and application-layer security concepts, including common attack methods and mitigation techniques across TCP/IP, HTTP/HTTPS, and related protocols. * Ability to communicate complex security issues, risks, and remediation recommendations clearly to developers, architects, and non-technical stakeholders. * Eligibility to obtain and maintain any required background investigations and to work in a federal or similar high-compliance environment, with appropriate citizenship as specified by the client., * Expertise with Java application server technologies such as Spring Framework, Spring Security, Web Services, REST, and Hibernate. * In-depth experience with single sign-on and identity management technologies, including SAML, LDAP, and related federation and access control solutions. * Hands-on experience with static code analysis tools (e.g., HP Fortify), intercepting proxies (e.g., Burp Suite), and security engineering in JavaScript, NodeJS, or other scripting languages. * Familiarity with DevOps/automation tooling such as Vagrant, Chef, Rake, Gradle, Jenkins, and cache databases, along with experience in Agile/Scrum development environments; experience with Axiomatics or similar ABAC platforms is a plus., The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions. ## Description The Cybersecurity Engineer Journeyman designs, implements, and manages application and infrastructure security solutions across an enterprise IT environment, with a focus on aligning with DoD and NIST requirements and integrating security throughout the DevSecOps lifecycle. They work closely with development, infrastructure, and security operations teams to embed secure architecture, controls, and testing into CI/CD pipelines while maintaining compliance and documentation standards. This role combines hands-on engineering, threat modeling, and incident response expertise with governance and training responsibilities to strengthen the organization's overall security posture., * Design and implement secure application and infrastructure architectures that comply with DoD and NIST security requirements, including Zero Trust principles, while integrating security into DevSecOps practices. * Develop, configure, and manage security controls and tooling such as firewalls, intrusion detection/prevention systems, SIEM platforms, and identity and access management solutions to protect enterprise applications and services. * Embed secure coding practices into the software development lifecycle, including static and dynamic analysis, manual and automated code reviews, and penetration testing activities integrated into CI/CD pipelines. * Lead application threat modeling, risk and vulnerability assessments, and remediation activities across web and distributed applications, ensuring coverage of OWASP Top 10 and other relevant attack vectors. * Implement and maintain strong authentication and authorization mechanisms (including RBAC), encryption and hashing, key management, and data protection measures for APIs, web services, and backend components. * Monitor and analyze security events and logs, coordinate incident response procedures, and collaborate with development, network, and corporate security teams to investigate and resolve security incidents and weaknesses. * Define, maintain, and enforce application security best practices, policies, and standards; perform security audits and maintain compliance documentation for internal and external stakeholders. * Evaluate, select, and recommend application security tools and technologies (e.g., static analysis tools, intercepting proxies, configuration management and automation tools) to improve coverage, efficiency, and developer experience. * Train developers and other team members on secure code development techniques, common vulnerabilities, secure use of frameworks and libraries, and enterprise security protocols., Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees. ## Related Videos - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Modular Secrets to Lightning-Fast Android Builds](https://www.wearedevelopers.com/videos/1428-modular-secrets-to-lightning-fast-android-builds) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Give your build some love, it will give it back!](https://www.wearedevelopers.com/videos/514-give-your-build-some-love-it-will-give-it-back) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)