Application Security Engineer (Full Scope Poly)

Concept Plus
Reston, VA, United States
25 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

JavaScript (Programming Language) Agile Methodology Artificial Intelligence Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Continuous Integration Information Engineering Data Transformation Database Connection Infrastructure as a Service (IaaS)
+30 more
Identity and Access Management Python (Programming Language) Key Management Oracle Databases Open Web Application Security Platform as a Service (PAAS) Secure Coding Security Software Shell Script Software Engineering PL-SQL SQL Databases Systems Integration Software Vulnerability Management Data Logging Data Processing Cloud Platform System Spring Cloud Software Security Build Management Kubernetes Information Technology Restful APIs Oracle Cloud Infrastructure Devsecops Docker Static Application Security Testing Vulnerability Analysis Programming Languages Dynamic Application Security Testing

Job description

Concept Plus is seeking a highly experienced and motivated Application Security Engineer for an exciting new contract. This role will be part of a team of Data, Cloud, and Security engineers delivering a cloud-native, centralized platform that provides end-to-end budget traceability. The Application Security Engineer will integrate security throughout the software development lifecycle, partnering with developers and cloud engineers to design, build, assess, and sustain secure mission applications.

Requirements

  • US Citizen
  • Must possess a TS/SCI security clearance with Polygraph.
  • Technical expertise and hands-on experience in application security, secure software development, software engineering, or DevSecOps, with the ability to apply these skills to Oracle Cloud and customer mission challenges.
  • Experience integrating security throughout the software development lifecycle, including secure design and architecture reviews, threat modeling, secure code review, security testing, vulnerability remediation, and release authorization support.
  • Experience developing or reviewing applications using Python, JavaScript frameworks, SQL, Shell scripting, PL/SQL, and other programming languages, with a strong understanding of common application vulnerabilities and secure coding practices.
  • Experience with application security testing tools and processes, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and container or infrastructure vulnerability scanning.
  • Experience building and securing cloud-native applications and services using Kubernetes, containers, Docker, REST APIs, and CI/CD pipelines.
  • Experience implementing DevSecOps practices, including automated security controls and testing within build and deployment pipelines.
  • Experience with cloud-native security services and controls; Oracle Cloud Infrastructure (OCI) experience is desired.
  • Knowledge of security frameworks and standards such as NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, and applicable federal security requirements.
  • Experience securing Oracle RDBMS environments, including database access controls, encryption, auditing, and secure handling of sensitive data.
  • Ability to assess, prioritize, document, and communicate application and cloud security risks, findings, and remediation recommendations to both technical and non-technical stakeholders.
  • Passion for technology, curiosity, and willingness to continuously learn new security tools, techniques, and approaches for solving complex technical challenges.
  • Experience working in an Agile framework.
  • 8+ years of relevant experience in application security, software engineering, DevSecOps, cybersecurity, or a related technical discipline.
  • Bachelor’s Degree in engineering, computer science or related technical discipline. Master’s degree preferred.

Preferred Qualifications

  • Oracle Cloud Infrastructure (OCI) IaaS and/or PaaS certifications are preferred.
  • Security certifications such as CISSP, CSSLP, Security+, GIAC, CEH, OSCP, or comparable credentials.
  • Experience implementing identity and access management, privileged access controls, secrets management, encryption, logging, monitoring, and incident response capabilities in cloud environments.
  • Experience with AI technologies for software development and securing AI-enabled applications or development workflows.
  • Data engineering experience, including securing data validations, business rules, data transformations, and sensitive-data handling.

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Life insurance
  • Paid holidays, We offer competitive pay, comprehensive health, dental, and vision insurance, paid life insurance, paid time off, 11 paid holidays, performance bonuses, tuition reimbursement, unlimited training, and the opportunity to thrive in a collaborative, flexible, and innovative environment.

About the company

Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm.

Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

Videos

See all

Related articles

See all