Application Security Engineer

Leidos LLC

Ashburn (VA)

On-site

USD 108,000 - 195,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Leidos’ DHS CBP Cyber Security Directorate seeks an experienced security engineer in Ashburn, VA to monitor, assess, and enhance application security across CBP networks. The role emphasizes integrating secure coding into SDLC, leading SAST/SCA/DAST efforts, and collaborating with development teams to remediate findings.

Responsibilities include implementing ML/AI into security tool suites, container security with Anchore, and ensuring compliance with STIGs and guidelines.

Qualifications

  • BS degree in Information Technology, Software Engineering, or related field and 8–12 years of prior relevant experience
  • 3+ years of prior experience in application security with a focus on SAST, SCA, DAST
  • Knowledge of secure coding practices and integration into SDLC
  • Familiarity with common security frameworks and standards
  • Strong programming/scripting skills
  • Excellent communication and collaboration skills
  • Working in an Agile project management environment
  • Must have a Top Secret Clearance with SCI
  • Must be able to report into the Ashburn VA office up to 5 days per week.

Responsibilities

  • Ensure continuous monitoring of all CSD managed applications and implement an alerting system for critical incidents
  • Participate in market research to identify new security solutions as required to avoid obsolescence and to improve the overall security posture
  • Develop, deploy, maintain, and/or assist in the implementation and integration of ML/AI into CBP’s security tool suite
  • Integrate security best practices into the SDLC and ensure security is embedded from design to deployment
  • Utilize SAST/DAST/DAST tools to analyze vulnerabilities
  • Work closely with development teams and ISSOs to remediate identified security issues
  • Conduct security assessments using Microfocus WebInspect and other DAST tools
  • Collaborate with development teams to address and remediate dynamic security findings
  • Implement and manage container security tools, with a focus on Anchore, to ensure secure container deployments
  • Provide recommendations for secure container orchestration
  • Work on ensuring systems and applications comply with Security Technical Implementation Guide
  • Establish and maintain the definitive current basis for control and status accounting of application systems and their configuration items
  • Select configuration items at appropriate levels for application products to facilitate documentation, control
  • Tune logging capabilities for efficiency, identify shortfalls, and recommend improvements and new technologies for application logging
  • Support the CSD Service Desk in managing and executing the Vulnerability Identification and Remediation process for applications.

Skills

Programming/Scripting
Agile PM experience
Communication skills
Collaboration

Education

BS in IT/Software Engineering
Master's degree (preferred)

Tools

SAST
SCA
DAST
Kubernetes
Rancher
Elasticsearch
Gitlab
Ansible

Job description

The Department of Homeland Security (DHS), Customs and Border Protection (CBP) Cyber Security Directorate (CSD) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations.

Primary Responsibilities
  • Application Security Operations and Maintenance, Application Security Configuration Management and Application Security Logging and Vulnerability Management : Ensure continuous monitoring of all CSD managed applications and implement an alerting system for critical incidents
  • Participate in market research to identify new security solutions as required to avoid obsolescence and to improve the overall security posture
  • Develop, deploy, maintain, and/or assist in the implementation and integration of Machine Learning (ML) and Artificial Intelligence (AI) into CBP’s security tool suite.
  • Integrate security best practices into the software development life cycle (SDLC) and ensure security is embedded from design to deployment.
  • Utilize SAST tools to analyze source code for vulnerabilities.
  • Work closely with development teams and ISSOs to remediate identified security issues.
  • Conduct security assessments using Microfocus WebInspect and other DAST tools.
  • Collaborate with development teams to address and remediate dynamic security findings.
  • Implement and manage container security tools, with a focus on Anchore, to ensure secure container deployments.
  • Provide recommendations for secure container orchestration.
  • Work on ensuring systems and applications comply with Security Technical Implementation Guide
  • Establish and maintain the definitive current basis for control and status accounting of application systems and their configuration items.
  • Select configuration items at appropriate levels for application products to facilitate documentation, control Tune logging capabilities for efficiency, identify shortfalls, and recommend improvements and new technologies for application logging.
  • Support the CSD Service Desk in managing and executing the Vulnerability Identification and Remediation process for applications.
Basic Qualifications
  • BS degree in Information Technology, Software Engineering, or related field and 8 – 12 years of prior relevant experience
  • 3+ years of prior experience in application security with a focus on SAST, SCA, DAST
  • Knowledge of secure coding practices and integration into SDLC
  • Familiarity with common security frameworks and standards
  • Strong programming/scripting skills
  • Excellent communication and collaboration skills
  • Working in an Agile project management environment
  • Must have a Top Secret Clearance with SCI
  • Must be able to report into the Ashburn VA office up to 5 days per week.
Preferred Qualifications
  • Master’s with 1-2 years of prior experience in application security with a focus on SAST, SCA, DAST
  • Experience with data engineering tools such as Kubernetes/Rancher, Cloudera
  • Experience with Configuration Management and IaC tools such as Salt or Ansible
  • Experience with scripting languages, CI/CD tools, Elasticsearch, or Gitlab
  • Experience working in an air-gapped environments
  • Experience working in large computing environments (> 1,000 end-points)

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting: July 13, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range: Pay Range $107,900.00 - $195,050.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Leidos Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended January 2, 2026. For more information, visit www.Leidos.com.

Pay and Benefits
  • Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement.

More details are available here.

Securing Your Data

Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to spam.leidos@leidos.com.

Commitment and Diversity

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law.

Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Leidos Inc • Ashburn (VA)

On-site
USD 107,900 - 195,050
Software Engineer
Software Engineer

Leidos LLC • Plyers Mill Estates (MD)

On-site
USD 87,000 - 157,000
Paid Time Off
11 holidays
401K with matching
+1
Software Engineer - Mid Level
Software Engineer - Mid Level

Leidos LLC • Clarksburg (WV)

On-site
USD 70,000 - 126,000
Health and Wellness programs
Competitive compensation
Income Protection
+1
Staff Cyber Security Engineer
Staff Cyber Security Engineer

Via Logic LLC • Bethesda (MD)

On-site
USD 108,000 - 195,000
Paid Time Off
11 paid Holidays
401K with 6% company match
+4
Staff Cyber Security Engineer
Staff Cyber Security Engineer

Koitecc Solutions • Bethesda (MD), Northern (KY)

Hybrid
USD 108,000 - 195,000
Paid Time Off
11 paid holidays
401K with company match
+5
Staff Cyber Security Engineer
Staff Cyber Security Engineer

Quest Oracle Community • Bethesda (MD), Northern (KY)

Hybrid
USD 108,000 - 195,000
Competitive benefits
11 paid holidays
401K with 6% match
+2
Full Stack Developer with AI
Full Stack Developer with AI

Leidos LLC • Ashburn (VA)

Hybrid
USD 131,000 - 237,000
DevSecOps Engineer – Intelligent Platforms & Agents
DevSecOps Engineer – Intelligent Platforms & Agents

Leidos LLC • United States

Remote
USD 108,000 - 195,000
Junior Security Engineer
Junior Security Engineer

Leidos Inc • Bethesda (MD)

On-site
USD 70,000 - 126,000
Sr Product Application Security Engineer
Sr Product Application Security Engineer

Leidos Inc • United States

On-site
USD 87,000 - 157,000