Application Security Engineer

Veilant

Tysons (VA)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible PTO
401k match benefit up to 10%
Medical, dental, and vision insurance
Employer contribution to HSA
Professional coaching services
Free daily snacks & drinks

Job summary

Veilant is seeking an Application Security Engineer to improve software security through auditing, vulnerability analysis, and remediation strategies. You will work closely with the InfoSec team, engineering teams, and have a hands-on role in enhancing our security posture.

Successful candidates will possess strong software development experience, especially in Java, and be adept at identifying vulnerabilities in Java Spring Boot applications. The position offers flexible PTO, a generous 401k match, and opportunities for career growth.

Qualifications

  • Ability to obtain a Security Clearance.
  • 2+ years of software development experience.
  • Experience with containerized environments.

Responsibilities

  • Audit software releases for security flaws.
  • Analyze source code for vulnerabilities.
  • Build proof-of-concept examples.

Skills

Software development experience in Java
Application security expertise
Hands-on experience with Java Spring Boot
Web security testing
Strong written communication skills

Tools

Burp Suite
GitLab CI
Kubernetes
Azure DevOps

Job description

Job Description

Veilant is looking for an Application Security Engineer to join our InfoSec team and help validate, secure, and continuously improve software developed by internal and partner engineering teams.

This role is ideal for someone who combines a software engineering foundation with an attacker mindset. You will review major and minor software releases before deployment, identify and validate vulnerabilities, create proof‑of‑concept demonstrations where appropriate, and provide practical remediation guidance that developers can act on.

You will not simply file security tickets and move on. You will work closely with engineering teams to understand application architecture, business logic, user workflows, data sensitivity, and production environments so that your findings are accurate, contextualized, and useful.

You will work collaboratively across Veilant’s software, DevSecOps, and infrastructure teams.

In this role, you will:

  • Audit software releases across major and minor cycles to intercept and remediate security flaws before deployment.
  • Analyze source code to identify, isolate, validate, and contextualize vulnerabilities in complex application codebases.
  • Build safe proof‑of‑concept examples to demonstrate exploitation paths and verify the real‑world impact of discovered risks.
  • Contextualize findings based on application business logic, user workflows, data sensitivity, and production use cases.
  • Author clear remediation guidance and partner with development teams to implement effective patches, controls, or architectural mitigations.
  • Intercept and analyze application‑layer network traffic using tools such as Burp Suite or similar intercepting proxies to inspect encrypted payloads, API calls, and authentication flows.
  • Assess and help secure core architectures across REST APIs, SQL databases, PostgreSQL, JWT/OAuth, identity providers, and token‑based authentication mechanisms.
  • Perform threat modeling for web applications based on use cases, data flows, user roles, trust boundaries, and production environments.
  • Improve DevSecOps pipelines by integrating, tuning, and operationalizing SAST, DAST, SCA, IaC scanning, secrets detection, and container security tooling.
  • Support container runtime security efforts using monitoring and runtime protection tools such as Falco, NeuVector, or similar technologies.
  • Create standardized security reporting that translates technical findings into clear risk narratives for both engineering teams and executive stakeholders.
What You Will Accomplish in Your First Six Months

Within your first six months, success in this role will look like:

Building a repeatable AppSec review process for major and minor software releases, helping engineering teams identify and resolve security issues before deployment.

Integrating and improving SAST, DAST, and SCA checks in CI/CD pipelines so that security testing becomes a reliable part of the development lifecycle rather than a late‑stage blocker.

Establishing threat modeling practices for web applications using common frameworks and applying them to Veilant’s Angular front‑end, Java Spring Boot back‑end, REST APIs, SQL databases, and authentication flows.

Partnering with engineering and software teams to improve secure coding practices through practical feedback, remediation guidance, and collaborative reviews.

Implementing best practices in container runtime security, including visibility, monitoring, and runtime protections for containerized workloads.

Writing standardized security reports that clearly communicate risk, impact, and remediation steps for both executive‑level stakeholders and engineering teams.

Qualifications

What We Are Looking For

Strong candidates will bring:

  • Ability to obtain a Security Clearance
  • 2+ years of software development experience in Java.
  • Hands‑on experience reviewing or securing applications built with Java Spring Boot, Angular, REST APIs, SQL databases, and PostgreSQL.
  • Working knowledge of authentication and authorization technologies, including JWT, OAuth, identity providers, Entra, Keycloak, and token‑based access models.
  • Experience intercepting, decrypting, manipulating, and analyzing web or application network traffic.
  • Demonstrated ability to find, validate, and explain vulnerabilities in a real codebase.
  • Familiarity with CI/CD tools such as GitLab CI, Azure DevOps, or GitHub Actions.
  • Experience with containerized environments and orchestration tools such as Kubernetes.
  • Exposure to infrastructure‑as‑code and container scanning tools such as Trivy, Kubesec, or similar technologies.
  • Understanding of cloud hosting environments such as Azure or AWS.
  • Familiarity with secrets management tools such as GitLab Secrets Manager, AWS KMS, Azure Key Vault, or Ansible Vault.
  • Experience with automated application security testing, including SAST, DAST, and SCA.
  • Familiarity with runtime security and monitoring tools for containers, such as Falco, NeuVector, or similar platforms.
  • Hands‑on web security testing experience using Burp Suite or comparable tooling.
  • Strong written communication skills, including the ability to write reports for both technical and non‑technical audiences.
  • OSWE, OSCP, and/or GXPN certifications are highly desirable.

The Kind of Person Who Will Thrive Here

You will do well in this role if you are curious, collaborative, and comfortable working across both code and security. You know how to speak with developers in practical terms, explain risk without creating unnecessary friction, and help teams ship secure software without slowing the mission down.

You are someone who can move from reviewing source code, to analyzing an API request, to modeling a threat scenario, to writing a report that an executive can understand. You enjoy solving problems at the root cause, not just documenting symptoms.

Additional Information

Why You’ll Love Working Here:

  • Innovative Environment: Work in a setting where your ideas and expertise are valued.
  • Collaborative Culture: Be part of a team that supports each other and works toward shared goals.
  • Career Growth: Opportunities for professional development and career advancement.

Here are some Perks!

  • Flexible PTO + holidays
  • Generous 401k match benefit up to 10%, with an automatic 3% safe harbor contribution and additional matching based on employee contributions.
  • Medical (HSA & PPO Plans Available), dental, vision, disability, and life insurance
  • Employer Contribution to Health Savings Account (HSA)
  • Professional coaching services
  • Get the technology you want to do your job
  • We have free daily snacks & drinks
Physical Requirements
  • Must be able to remain in a stationary position 50% of the time. The person in this position needs to occasionally move about inside the office
  • Constantly work with computers and other information technology equipment
  • The ability to communicate information and ideas in a classroom style format, may stand at a podium for long periods of time

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, veteran status, or any other characteristic protected by law. We are proud to be an equal opportunity workplace.

If you require a reasonable accommodation to apply for a position with Veilant through its online applicant system, please contact Veilant's Talent Management Department at (703) 544-2424 or contact us throughe-mail at contact_us@ veilant.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Ridgeline International, LLC • Tysons (VA)

On-site
USD 190,000 - 232,000
Flexible PTO
401k match up to 10%
Medical insurance
+7
Cyber Defense Analyst
Cyber Defense Analyst

Veilant • Tysons (VA)

On-site
USD 80,000 - 110,000
Flexible PTO + holidays
Generous 401k match benefit
Medical, dental, and vision insurance
+2
Information Systems Security Manager ISSM
Information Systems Security Manager ISSM

Veilant • Tysons (VA)

On-site
USD 190,000 - 232,000
Flexible PTO + holidays
401k match up to 10% + 3% safe harbor
Medical (HSA & PPO) + dental + vision
+5
System Administrator/FSR – Onsite Customer Support
System Administrator/FSR – Onsite Customer Support

Ridgeline International, LLC • Tysons (VA)

On-site
USD 89,000 - 140,000
Flexible PTO + holidays
401k match up to 10%
Health/dental/vision/disability/life
+5
System Administrator/FSR – Onsite Customer Support
System Administrator/FSR – Onsite Customer Support

Veilant Company • Tysons (VA)

On-site
USD 89,000 - 140,000
Flexible PTO + holidays
Generous 401k match up to 10%
Medical, dental, vision, disability, &
+5
Senior Linux Systems Engineer
Senior Linux Systems Engineer

Veilant • Tysons (VA)

On-site
USD 100,000 - 130,000
Flexible PTO
401k match
Medical, dental, and vision insurance
+2
Senior Human Resources Generalist
Senior Human Resources Generalist

Veilant • Tysons (VA)

Hybrid
USD 95,000 - 125,000
Flexible PTO + holidays
Generous 401k match up to 10%
Health insurance (HSA & PPO) including
+3
Sr. Commercial Product Manager
Sr. Commercial Product Manager

Ridgeline International, LLC • Tysons (VA)

Hybrid
USD 195,000 - 250,000
Flexible PTO + holidays
401k match up to 10%
Health insurance (HSA & PPO)
+5
NOC Systems Administrator, Linux
NOC Systems Administrator, Linux

Ridgeline International, LLC • Tysons (VA)

On-site
USD 73,000 - 104,000
Flexible PTO + holidays
401k with match and safe harbor
employer health benefits
+4
Senior Human Resources Generalist
Senior Human Resources Generalist

Ridgeline International, LLC • Tysons (VA)

Hybrid
USD 95,000 - 125,000
Flexible PTO
401k match
Health insurance
+3