Application Security Engineer

Nabout Leidos
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Regular working hours

Tech stack

Agile Methodology Artificial Intelligence Computing Platforms Configuration Management Computer Programming Continuous Integration Elasticsearch Machine Learning Systems Development Life Cycle Software Tools Ansible Cloudera
+14 more
Secure Coding Software Engineering Data Logging Webinspect Scripting Software Security Gitlab Kubernetes Infrastructure Automation Frameworks Information Technology Rancher Microfocus Static Application Security Testing Dynamic Application Security Testing

Job description

  • Ensure continuous monitoring of all CSD managed applications and implement an alerting system for critical incidents\n
  • Participate in market research to identify new security solutions as required to avoid obsolescence and to improve the overall security posture\n
  • Develop, deploy, maintain, and/or assist in the implementation and integration of Machine Learning (ML) and Artificial Intelligence (AI) into CBP’s security tool suite.\n
  • Integrate security best practices into the software development life cycle (SDLC) and ensure security is embedded from design to deployment.\n
  • Utilize SAST tools to analyze source code for vulnerabilities.\n
  • Work closely with development teams and ISSOs to remediate identified security issues.\n
  • Conduct security assessments using Microfocus WebInspect and other DAST tools.\n
  • Collaborate with development teams to address and remediate dynamic security findings.\n
  • Implement and manage container security tools, with a focus on Anchore, to ensure secure container deployments.\n
  • Provide recommendations for secure container orchestration.\n
  • Work on ensuring systems and applications comply with Security Technical Implementation Guide\n
  • Establish and maintain the definitive current basis for control and status accounting of application systems and their configuration items.\n
  • Select configuration items at appropriate levels for application products to facilitate documentation, control\n
  • Tune logging capabilities for efficiency, identify shortfalls, and recommend improvements and new technologies for application logging.\n
  • Support the CSD Service Desk in managing and executing the Vulnerability Identification and Remediation process for applications.\n

Requirements

  • BS degree in Information Technology, Software Engineering, or related field and 8 - 12 years of prior relevant experience\n
  • 3+ years of prior experience in application security with a focus on SAST, SCA, DAST\n
  • Knowledge of secure coding practices and integration into SDLC\n
  • Familiarity with common security frameworks and standards\n
  • Strong programming/scripting skills\n
  • Excellent communication and collaboration skills\n
  • Working in an Agile project management environment\n
  • Must have a Top Secret Clearance with SCI\n
  • Must be able to report into the Ashburn VA office up to 5 days per week.\n, * Master’s with 1-2 years of prior experience in application security with a focus on SAST, SCA, DAST\n
  • Experience with data engineering tools such as Kubernetes/Rancher, Cloudera\n
  • Experience with Configuration Management and IaC tools such as Salt or Ansible\n
  • Experience with scripting languages, CI/CD tools, Elasticsearch, or Gitlab\n
  • Experience working in an air-gapped environments\n
  • Experience working in large computing environments (> 1,000 end-points) \n

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.military.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · WWC 2024

3:47 min

Comparing declarative GitOps tooling alternatives and interface priorities

Davide Imola Davide Imola · LIVE

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:19 min

Executing complex workflows using Ansible Automation Platform

Goetz Rieger Goetz Rieger · WWC 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all