> Markdown version of [/jobs/ext/584429-lead-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/584429-lead-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Application Security Engineer - **Company:** phia, LLC - **Location:** Fairfax, VA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Amazon Elastic Compute Cloud, Bash Shell, Burp Suite, Command-Line Interface, Continuous Integration, Linux, DevOps, Github, Jython, Python (Programming Language), Linux Servers, OAuth, Open Source Technology, OpenShift, Ansible, Software Security, Veracode, Cloudformation, Kubernetes, Devsecops, Docker, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 12, 2026 - **Apply:** https://diversityjobs.com/career/17239702/Lead-Application-Security-Engineer-Virginia-Fairfax ## About the Role * 8+ years in engineering/security, with deep, recent, hands-on Burp Suite Enterprise and Burp Suite Professional operations - you have configured authenticated scans, not just reviewed their output * Demonstrated experience writing or significantly modifying custom Burp extensions (Python/Jython, Java, or Montoya API) * Strong Linux/Unix command-line fluency - comfortable diagnosing services, disk, memory, and network from a shell, daily * Python and Bash scripting; Ansible exposure; experience with Docker/Kubernetes (OpenShift a plus) and AWS * Experience integrating security tooling into GitHub Actions or comparable CI/CD pipelines * Proven technical leadership: you have driven programs or technical decisions across teams and can hold your own - energetically - in a room of senior engineers * An active, visible interest in AppSec and DevSecOps research: you test new techniques, follow the field, and bring ideas to the team unprompted * U.S. citizenship and the ability to complete federal Public Trust vetting (no security clearance required) What Sets Candidates Apart * Published Burp extensions (BAppStore or GitHub), conference talks, blog posts, or open-source security tooling * Experience scripting around OTP/TOTP, PIV, or certificate-based authentication for automated scanning * Veracode SAST, Contrast IAST, or bug bounty validation experience (HackerOne or similar) * Prior federal or regulated-environment AppSec work (NIST 800-53 / FISMA familiarity) ## Description Most AppSec jobs hand you a queue. This one hands you a program. phia is hiring a Lead Application Security Engineer to drive the dynamic application security testing (DAST) program for a federal civilian client operating one of the more complex enterprise environments in government - a large attack surface with real, persistent cyber adversary activity, where application security is treated as mission, not paperwork. You'll join a four-person skunk-works AppSec team - two highly technical federal engineers and two contractors - that owns its entire stack end to end: self-managed Linux servers in AWS, Burp Suite Enterprise running nightly authenticated scans across multiple environments, Burp Suite Professional for hands-on validation, custom extensions the team writes itself, GitHub Actions pipelines, and an active migration to OpenShift with Ansible. No ticket mills. No layers of approval between you and the work. The federal technical lead is a Linux/*nix engineer's engineer who wants a peer who can drive the conversation - and back it up on the keyboard. What You'll Own * The Burp Suite Enterprise program, full stack. Architect,operate, and continuously improve scheduled authenticated DAST scanning - recorded login sequences, session handling, scan tuning, and failure diagnosis through logs and traces, not dashboards. * Custom Burp extension development. Write and maintain extensions (Python/Jythonor Java/Montoya API) that solve authentication, validation, and workflow problems off-the-shelf tooling can't. * Authenticated scanning against hard targets. MFA, one-time passwords, OAuth 2.0 (you know why client credentials beat authorization code for unattended scanning), SSO federation, and PIV/smart-card certificate environments. * Manual validation in Burp Suite Professional.Verify remediations, kill false positives with evidence, and defend findings to a technical audience that will push back. * Technical leadership across teams. Lead and drive discussions with DevOps, platform, and identity stakeholders outside the security team - you set direction, build consensus, and bring solutions, not status updates. * The infrastructure underneath it all. Administer the team's Linux servers in AWS (EC2, Cloud Formation), support the migration to OpenShift, and convert legacy Python/shell tooling into Ansible roles and playbooks. * CI/CD security integration.GitHub Actions workflows (yes, you should know workflow_dispatch from workflow_call), Dependabot, and reusable security gates across repositories. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)