Application Security Engineer

Steampunk

McLean (VA)

On-site

USD 100,000 - 155,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Steampunk in McLean, VA is seeking a Web Application Security Engineer to deliver risk-based remediation across enterprise applications. You will collaborate with IT and development teams to harden environments, assess vulnerabilities, and design proactive controls that improve overall security posture.

The ideal candidate will hold a U.S. government security clearance or be eligible, bring experience with PKI/TLS, DevSecOps tools, and automation with Python, and be capable of translating

Qualifications

  • Ability to obtain a U.S. government Security Clearance.
  • Experience with building and securing enterprise applications.
  • Strong knowledge of security testing tools and automation.

Responsibilities

  • Provide subject matter expertise for risk assessments in an Agile environment.
  • Advocate secure practices within application development portfolios.
  • Secure OS, Database, App Server, Load Balancer, and Web Server layers.
  • Remediate findings and baselines; socialize remediation solutions.
  • Support SOC with scan analysis and partner with development teams.
  • Document findings in an enterprise knowledge base.

Skills

Security mindset
Python automation
Vulnerability remediation

Education

Master's degree + 3 years
Bachelor's degree + 5 years
No degree + 9 years

Tools

AWS GovClouds
Azure GovClouds
JIRA
ServiceNow
Invicti
WebInspect

Job description

Overview

As a Web Application Security Engineer, you will provide technical expertise and solutions to remediate persistent and challenging portfolio-wide vulnerabilities. We’re looking for someone who has passion for IT, resourceful problem-solving abilities, and a desire to learn our indicators of success in this role. The ideal candidate will have a breadth of experience over a variety of application and web based technologies. The candidate will not necessarily have deep experience in all domain areas but should have a good understanding of how the various layers of an enterprise application stack interact with one another. You will work directly with system admin teams to assist and remediate vulnerabilities and harden environments, while providing recommendations on ways to enhance vulnerability management. Additionally, you will work in a team environment to develop proactive solutions to improve overall enterprise security posture through process streamlining and automation.

Contributions
  • Provide subject matter expertise for various risk assessments, working in an Agile environment with an understanding of the full software development lifecycle.
  • Advocate for and ensure appropriate security practices are communicated and implemented within application development portfolios.
  • Ability and proven experience in securing multiple areas of an enterprise application stack, including the OS, Database, Application Server, Load Balancer, and Web Server layers. Understanding how PKI/TLS certificates work is a must.
  • Integrate with both the application development and security assurance divisions to ensure vulnerability findings are understood, remediated or baselined as appropriate.
  • Document & Socialize security findings and remediation solutions in an enterprise knowledge base.
  • Support the Information Assurance Branch and the SOC with scan analysis and partner with development teams to understand and remediate security findings.
Qualifications
  • Ability to obtain a U.S. government Security Clearance
  • Master's Degree and 3 years of relevant experience; OR
    • Bachelor's Degree and 5 years of relevant experience; OR
    • No degree and 9 years of relevant experience
  • Possesses at least one professional certification relevant to the technical service provided. Maintain a certification relevant to the product being deployed and/or maintained.

Preferred:

  • Former Developer or Systems Administrator experience
  • Working knowledge of technologies used for building and deploying enterprise applications, such as, Maven, Grade, GIT, Jenkins, Ansible, Java, C#/.NET, Apache Tomcat, Apache HTTP Server, IIS, F5, Oracle, MSSQLSEVER, PostGres
  • Working knowledge and experience in AWS and Azure GovClouds
  • Ability to analyze DISA STIG audit compliance scan results and provide recommendations for resolution
  • Analyze security environment, provide recommendations
  • Working knowledge of JIRA, Service Now or equivalent
  • Working knowledge of operating system and dynamic application security testing scan tools – Invicti, Web Inspect, DAST/IAST suites
  • Experience using Python to automate tasks

Certifications:

  • CEH, GFACT, GPEN, OSCP or other relevant industry certifications
  • Other Application based Technology specific certifiations
About steampunk

Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $100,000 to $155,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here.

Identity Statement

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Steampunk is aChange Agentin the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through ourHuman-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visithttp://www.steampunk.com.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.Steampunk participates in the E-Verify program.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Steampunk • Bloomington (IL)

On-site
USD 100,000 - 155,000
Cybersecurity/Technical Engineer
Cybersecurity/Technical Engineer

Steampunk • McLean (VA)

On-site
USD 85,000 - 170,000
Cloud Security Engineer
Cloud Security Engineer

Steampunk • Washington

On-site
USD 100,000 - 155,000
AWS/Azure/GCP certifications
Tuition for certifications
Health insurance
+1
Vulnerability Management Lead
Vulnerability Management Lead

Steampunk • Bloomington (IL)

On-site
USD 125,000 - 175,000
Cybersecurity/Technical Engineer
Cybersecurity/Technical Engineer

Steampunk, Inc. • McLean (VA)

On-site
USD 85,000 - 170,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Steampunk • Washington

On-site
USD 130,000 - 180,000
Vulnerability Management Lead
Vulnerability Management Lead

Steampunk, Inc. • McLean (VA)

On-site
USD 125,000 - 175,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Steampunk, Inc. • Washington

On-site
USD 130,000 - 180,000
Software / Integration Engineer
Software / Integration Engineer

Steampunk • McLean (VA)

On-site
USD 140,000 - 170,000
Red-Team / Adversarial Security Lead
Red-Team / Adversarial Security Lead

Steampunk • McLean (VA)

On-site
USD 85,000 - 170,000