> Markdown version of [/jobs/ext/2691666-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2691666-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Caci Inc - **Location:** United States - **Experience:** Experienced - **Salary:** $75,200.0 - $158,100.0 - **Contract:** Contract - **Skills:** Java (Programming Language), Software System Penetration Testing, Software Quality, Code Review, Cyber Security, Information Systems, Python (Programming Language), Open Web Application Security, Comptia Pentest+ CE, Fortify (Software), Secure Coding, Software Engineering, SonarQube, Software Vulnerability Management, Scripting, Software Security, Information Technology, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 3, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9136869/application-security-engineer ## About the Role * Active Secret or TS clearance * 3-5 years of experience in application security, secure development, or penetration testing * Hands-on experience with SAST platforms (Fortify preferred) * Working knowledge of OWASP Top 10 and common application vulnerability classes * Demonstrated experience conducting or supporting penetration tests * DoD 8140.03M DCWF Basic Tier - CEH * DoD 8140 Interim Education Options Required to travel to Scott Airforce base on a quarterly basis Desired: * DoD 8140.03M DCWF Intermediate Tier - one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+ * Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems, IT, or Software Engineering * Experience with SonarQube or similar secure code analysis platforms * Familiarity with DevSecOps pipelines and CI/CD security integration * Scripting or development experience in Python, Java, or similar languages ## Description * Execute both static (SAST) and dynamic (DAST) application security testing using enterprise tooling * Lead and support penetration testing engagements, guiding developers through actionable remediation * Work within a fully staffed cybersecurity program-including architecture, GRC, and operations experts * Grow your expertise across the AppSec spectrum: code review, runtime testing, and compliance validation, * Perform SAST using Fortify across assigned applications * Conduct continuous code quality and security analysis using SonarQube * Execute DAST to identify runtime vulnerabilities * Coordinate and execute penetration testing engagements * Conduct secure code reviews and document findings with actionable guidance * Track and verify vulnerability remediation through closure * Validate application security controls against program and DoD requirements * Author application security assessment and penetration test reports * Support the Cybersecurity Architect with secure SDLC process design ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Automated Code Quality Checks with Custom SonarQube Rules](https://www.wearedevelopers.com/videos/428-automated-code-quality-checks-with-custom-sonarqube-rules) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Automated MS SQL Server database deployments with dacpacs and Azure DevOps](https://www.wearedevelopers.com/videos/334-automated-ms-sql-server-database-deployments-with-dacpacs-and-azure-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)