> Markdown version of [/jobs/ext/2037502-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2037502-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Booz Allen Hamilton Inc. - **Location:** Bethesda, MD, United States - **Experience:** Expert - **Salary:** $86,900.0 - $198,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Agile Methodology, Artificial Intelligence, Applications Architecture, User Authentication, Cloud Computing Security, Cloud Engineering, Cyber Security, Information Systems, Integrated Development Environments, Open Web Application Security, Scrum Methodology, Software Architecture, Systems Development Life Cycle, Secure Coding, Software Engineering, Software Vulnerability Management, Enterprise Software Applications, Software Security, Mitre Att&ck, Kubernetes, Process Control Systems, Devsecops, Serverless Computing, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** August 12, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88010692/1 ## About the Role * 5+ years of experience in cybersecurity, application security, product security, or software engineering * Experience implementing or assessing Secure SDLC and application security programs, leading client engagements, managing multiple priorities, and performing architecture reviews, threat modeling, or security assessments * Experience with software supply chain security concepts, including SBOMs, dependency management, code signing, artifact integrity, and secure build pipelines * Experience implementing or evaluating application security tools such as SAST, DAST, SCA, IaC scanning, container security, API security, secrets detection, and software composition analysis * Experience with Agile, Scrum, and DevSecOps operating models in large-scale software development environments * Knowledge of secure software development principles, modern application architectures, and modern software architectures, including cloud-native, microservices, APIs, containers, Kubernetes, and serverless environments * Knowledge of authentication, authorization, cryptography, API security, and cloud security * Knowledge of vulnerability management processes, risk prioritization methodologies, and remediation workflows * Ability to translate complex technical risks into executive-level briefings, business cases, and actionable roadmaps, and communicate effectively with both technical and executive stakeholders * Bachelor's degree in CS, Cybersecurity, Information Systems, or Engineering Nice If You Have: * Experience designing or maturing enterprise application security and product security programs * Experience with secure development requirements for regulated industries, including healthcare, financial services, industrial control systems, automotive, aerospace, or critical infrastructure * Experience applying industry frameworks such as OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, and MITRE ATT&CK or ATLAS * Experience developing technical proposals, responding to RFPs, creating Statements of Work (SOWs), and supporting business development initiatives * Experience leading executive workshops, stakeholder interviews, and technical design sessions * Ability to mentor junior consultants, provide technical leadership, and contribute to practice development and thought leadership * Ability to travel up to 50% of the time, depending on client needs * Possession of strong written and verbal communication skills * Possession of strong facilitation skills * Master's degree in Cybersecurity, CS, Software Engineering, Information Assurance, or a related technical field ## Description Integrate security practices throughout the software development lifecycle to enhance and maintain the security posture of software. Apply advanced consulting skills and extensive technical expertise, including full industry knowledge. Develop innovative solutions to complex problems. Work without considerable direction, and mentor and supervise team members. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)