Sr. IT Application Security Engineer (USC or Green Card a must)

CAREER DEVELOPERS INC
Reston, VA, United States
13 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$150,000.0 - $180,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Software System Penetration Testing User Authentication Cyber Security Computer Engineering Continuous Integration DevOps IT Management OAuth OpenID Open Web Application Security Performance Tuning
+6 more
Systems Development Life Cycle Web Application Security Enterprise Software Applications Software Security Information Technology Vulnerability Analysis

Job description

Our client is seeking a Senior Security Engineer with a strong hands-on Application Security background. This role will focus on designing, implementing, operating, and improving security controls across enterprise applications and supporting platforms., The Senior Security Engineer will work closely with Development, DevOps, Operations, and Information Security teams to embed security throughout the SDLC and CI/CD process, strengthen web and API security, and identify and mitigate application vulnerabilities., * Develop and maintain application security policies, procedures, and controls

  • Partner with DevOps to build and maintain secure CI/CD pipelines
  • Design and operate WAF and API security controls
  • Tune security rules, reduce false positives, and automate policy updates
  • Conduct web application security scans, vulnerability assessments, and penetration testing
  • Identify application vulnerabilities, perform risk assessments, and recommend remediation
  • Support container security, including runtime hardening, image scanning, and vulnerability assessments
  • Develop security monitoring across the application stack
  • Investigate application security incidents
  • Work with IT leadership to communicate security risks and priorities

Requirements

  • Senior level, hands-on experience with conducting web application security scans, vulnerability assessments and penetration testing on applications., * 6 to 8 years of Application Security experience within enterprise environments
  • Strong hands on web application security experience
  • Strong knowledge of OWASP Top 10 vulnerabilities
  • Experience with WAF and API security, including policy design and rule tuning
  • Experience with application vulnerability scanning, security assessments, and/or penetration testing
  • Experience with container security, image scanning, and runtime hardening
  • Experience securing SDLC and CI/CD environments
  • Knowledge of OAuth, OpenID, authentication, and authorization services
  • Experience operating cloud and/or on premises security platforms
  • Ability to troubleshoot security and network related issues
  • Strong communication skills with the ability to work across Development, DevOps, Operations, and Security teams

Education Bachelor’s Degree in Information Security, Computer Science, Computer Engineering, Electrical Engineering, or equivalent professional experience.

Candidates must be eligible to work in the United States.

About the company

Career Developers Inc., a distinguished staffing and consulting firm, is proud to celebrate 30 years of service excellence. As a GSA Contract holder, we offer comprehensive staffing solutions for both commercial and government sectors nationwide. By selectively partnering with clients who share our values, we ensure productive collaborations that set us apart in the industry. Our dedication to candidates involves managing expectations with precision through business intelligence, thorough interview preparation, transparent communication, and exceptional feedback throughout the process.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all