> Markdown version of [/jobs/ext/3115477-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3115477-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Booz Allen Hamilton Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $62,000.0 - $141,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Burp Suite, C Sharp (Programming Language), Unix, Cyber Security, Linux, Eclipse (Software), Federal Information Processing Standards (FIPS), JDeveloper, Python (Programming Language), Open Web Application Security, Web Applications, Web Navigation, Software Security, Veracode, Information Technology, Data Pipelines, Dynamic Application Security Testing - **Published:** September 27, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88464659/1 ## About the Role * 6+ years of experience with information technology, and cybersecurity or application security * 3+ years of experience with Java, Python, .NET, or C# * 3+ years of experience using Burp Suite DAST to perform DAST * 3+ years of experience designing and implementation enterprise-wide security controls to secure applications, systems, networks, or infrastructure services * 3+ years of experience with Linux or UNIX environments, including system navigation and troubleshooting basic website connectivity issues * 2+ years of experience with Veracode and development environments such as Eclipse and JDeveloper, including pipeline development and integration * Experience securing enterprise web applications and frameworks, including OWASP Top 10, CVSS, CWE, WASC, and SANS-25 * Knowledge of federal security and compliance standards, including NIST 800-53, FIPS, or FedRAMP * Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements * HS diploma or GED Nice If You Have: * Experience with Interactive Application Security Testing (IAST) capabilities and tools ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [93 Java Interview Questions You Should Prepare For](https://www.wearedevelopers.com/magazine/14-93-java-interview-questions-you-should-prepare-for)