Lead Application Security Engineer

phia, LLC
Fairfax, VA, United States
3 months ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services Amazon Elastic Compute Cloud Bash Shell Burp Suite Command-Line Interface Continuous Integration Linux DevOps Github Jython
+14 more
Python (Programming Language) Linux Servers OAuth Open Source Technology OpenShift Ansible Software Security Veracode Cloudformation Kubernetes Devsecops Docker Static Application Security Testing Dynamic Application Security Testing

Job description

Most AppSec jobs hand you a queue. This one hands you a program. phia is hiring a Lead Application Security Engineer to drive the dynamic application security testing (DAST) program for a federal civilian client operating one of the more complex enterprise environments in government - a large attack surface with real, persistent cyber adversary activity, where application security is treated as mission, not paperwork.

You’ll join a four-person skunk-works AppSec team - two highly technical federal engineers and two contractors - that owns its entire stack end to end: self-managed Linux servers in AWS, Burp Suite Enterprise running nightly authenticated scans across multiple environments, Burp Suite Professional for hands-on validation, custom extensions the team writes itself, GitHub Actions pipelines, and an active migration to OpenShift with Ansible. No ticket mills. No layers of approval between you and the work. The federal technical lead is a Linux/*nix engineer’s engineer who wants a peer who can drive the conversation - and back it up on the keyboard.

What You’ll Own

  • The Burp Suite Enterprise program, full stack. Architect,operate, and continuously improve scheduled authenticated DAST scanning - recorded login sequences, session handling, scan tuning, and failure diagnosis through logs and traces, not dashboards.
  • Custom Burp extension development. Write and maintain extensions (Python/Jythonor Java/Montoya API) that solve authentication, validation, and workflow problems off-the-shelf tooling can’t.
  • Authenticated scanning against hard targets. MFA, one-time passwords, OAuth 2.0 (you know why client credentials beat authorization code for unattended scanning), SSO federation, and PIV/smart-card certificate environments.
  • Manual validation in Burp Suite Professional.Verify remediations, kill false positives with evidence, and defend findings to a technical audience that will push back.
  • Technical leadership across teams. Lead and drive discussions with DevOps, platform, and identity stakeholders outside the security team - you set direction, build consensus, and bring solutions, not status updates.
  • The infrastructure underneath it all. Administer the team’s Linux servers in AWS (EC2, Cloud Formation), support the migration to OpenShift, and convert legacy Python/shell tooling into Ansible roles and playbooks.
  • CI/CD security integration.GitHub Actions workflows (yes, you should know workflow_dispatch from workflow_call), Dependabot, and reusable security gates across repositories.

Requirements

  • 8+ years in engineering/security, with deep, recent, hands-on Burp Suite Enterprise and Burp Suite Professional operations - you have configured authenticated scans, not just reviewed their output
  • Demonstrated experience writing or significantly modifying custom Burp extensions (Python/Jython, Java, or Montoya API)
  • Strong Linux/Unix command-line fluency - comfortable diagnosing services, disk, memory, and network from a shell, daily

  • Python and Bash scripting; Ansible exposure; experience with Docker/Kubernetes (OpenShift a plus) and AWS
  • Experience integrating security tooling into GitHub Actions or comparable CI/CD pipelines
  • Proven technical leadership: you have driven programs or technical decisions across teams and can hold your own - energetically - in a room of senior engineers
  • An active, visible interest in AppSec and DevSecOps research: you test new techniques, follow the field, and bring ideas to the team unprompted
  • U.S. citizenship and the ability to complete federal Public Trust vetting (no security clearance required)

What Sets Candidates Apart

  • Published Burp extensions (BAppStore or GitHub), conference talks, blog posts, or open-source security tooling
  • Experience scripting around OTP/TOTP, PIV, or certificate-based authentication for automated scanning
  • Veracode SAST, Contrast IAST, or bug bounty validation experience (HackerOne or similar)
  • Prior federal or regulated-environment AppSec work (NIST 800-53 / FISMA familiarity)

Benefits & conditions

medical insurance, dental insurance, life insurance, vision insurance, paid time off, paid holidays, 401(k), Logistics

  • Fully remote, full-time, supporting a federal civilian client (client team is on-site; contractors are remote)
  • 8.5-hour workday anchored by an 8:30 AM ET daily standup - flexible around that rhythm
  • U.S. citizens only; Public Trust vetting required

About phia

phia LLC (“phia”) is a Northern Virginia based, small business established in 2011 with focus in Cyber Intelligence, Cyber Security/Defense, Intrusion Analysis & Incident Response, Cyber Architecture & Capability Analysis, Cyber Policy & Strategy, Information Assurance/Security, Compliance, Certification & Accreditation, Communications Security, Traditional Security, and Facilities Security. phia also provides cyber operations support functions such as: Program and Process Management, Engineering, Development, and Systems Administration that allows for Cyber Operations to efficiently integrate our customer’s missions and objectives. phia supports various agencies and offices within the Department of Defense (DoD), Federal government, and private/commercial entities.

phia offers excellent benefits to enhance work-life balance, including the following:

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Life Insurance
  • Short Term & Long-Term Disability
  • 401k Retirement Savings Plan with Company Match
  • Paid Holidays
  • Paid Time Off (PTO)
  • Tuition and Professional Development Assistance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all