Federal Vulnerability Mgmt & App Security Engineer (US Citizen)

PSI Services LLC

United States

On-site

USD 106,000 - 144,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

PSI Services LLC in the United States (Remote-US) is seeking a Vulnerability Management and Application Security Engineer to lead risk reduction across infrastructure, cloud, and applications.

You will own the vulnerability management program, integrate security into the SDLC with CI/CD, and work closely with engineering and product teams to prioritize remediation.

Qualifications

  • Experience identifying, assessing, and reducing risk across infrastructure, cloud, and applications.
  • Hands-on in SDLC security and embedding security earlier in development.
  • Knowledge of OWASP Top 10 and industry security standards.
  • Ability to translate risk into prioritized actions for technical and non-technical stakeholders.

Responsibilities

  • Drive improvements in vulnerability management tools and processes.
  • Develop metrics and reports for executive leadership.
  • Collaborate with engineering and DevOps to integrate security into CI/CD.
  • Perform and oversee application security assessments (SAST/DAST/SCA).

Skills

Security risk assessment
Threat intelligence correlation
Application Security testing
CI/CD security integration

Tools

SAST tools
DAST tools
SCA tools
CI/CD tooling

Job description

Title: Vulnerability Mgmt. and Application Security Engineer


Location:Remote-US


Salary:$125K annually


About PSI

We are PSI Services. We power world leading tests. Delivered with trusted science and the very best test taker experience. PSI supports test-takers on their journey to pursuing dreams and gaining certifications that are important to them. They believe that their dreams are worth working for; that their dreams are worth the effort. And we believe that too. This is our core purpose, to empower people to achieve their dreams. We do this by being the best provider of workforce solutions, which foster both technology and science to deliver the best solutions for our test takers.


We are searching for top talent to join our PSI team and help grow our products and services. We have a creative, supportive and inclusive culture where we empower people in their careers to be their authentic self and make the most of their great talent.


At PSI, we are committed to helping people meet their potential and we believe that promoting diversity, equity and inclusion is critical to our success. That's why you'll find these ideals are intrinsic to our company culture and applied throughout the employee lifecycle.


Learn more about what we do at: https://www.psiexams.com/


The Threat, Vulnerability & Application Security Analyst is a dual-focus security practitioner responsible foridentifying, assessing, and reducing risk across infrastructure, cloud, and application environments. This role combines enterprise threat and vulnerability management with hands-on application security oversight across the software development lifecycle (SDLC).


The analyst correlates threat intelligence, asset inventory, vulnerability data, and application risk to inform security priorities, guide remediation, and continuously improve the organization’s security posture. A core responsibility is partnering closely with engineering, platform, and product teams to embed security earlier in development, reduce exploitable risk, and ensure compliance with internal security standards and external regulatory requirements.


This role emphasizes automation, scalability, and pragmatism—driving measurable risk reduction through tooling, process improvements, and actionable security guidance. Success requires persistence, strong technical depth across AppSec and vulnerability domains, and the ability to translate risk into clear, prioritized actions for technical and non-technical stakeholders.


Role Responsibilities


  • Drive continuous improvements in vulnerability management processes and tools byleveragingindustry-leading technologies, automation, and data-driven insights.

  • Stay current on industry trends, emerging threats and best practices in vulnerability management andadaptthe program accordingly.

  • Evaluate and recommend vulnerability management tools and technologies, ensuring theoptimalbalance of effectiveness and efficiency.

  • Develop and deliver regular metrics, reports, KPIs and presentations to executive leadership and key stakeholders, communicating the status and effectiveness of the vulnerability management program.

  • Assistin building a diverse vulnerability management program that covers secure software development lifecycle, patch governance, and application security.

  • Perform technical threat/risk and vulnerability assessments and manage vulnerabilities throughout their lifecycle.

  • Provide support andmaintaintoolsrequiredfor the vulnerability management program.

  • Provide consultative support to operational teams on how to fix identified vulnerabilities.

  • Own and evolve the Application Security program, integrating findings into the broader vulnerability management lifecycle.

  • Perform and oversee application security assessments, including static (SAST), dynamic (DAST), software composition analysis (SCA), and manual secure code reviews whereappropriate.

  • Partner with development and DevOps teams to embed security into the SDLC, including CI/CD pipeline integrations and secure design reviews.

  • Define andmaintainapplication risk prioritization that considers exploitability, business impact, data sensitivity, and threat context.

  • Review application architectures and threat models to proactivelyidentifydesign-level security weaknesses.

  • Establish andmaintainsecure coding standards aligned to OWASP Top 10 and industry best practices.

  • Triage,validate, and manage application vulnerabilities through remediation and verification.

  • Enable developer success through consultative AppSec support, clear remediation guidance, and security-by-design recommendations.


Knowledge,Skillsand Experience Requirements

Core Security & Risk


  • Strong understanding of information security risk measurement (qualitative and quantitative) to support effective prioritization.

  • Working knowledge of industry security frameworks and standards (e.g., NIST CSF/800-53, ISO 27001, OWASP).

  • Ability to correlate threat intelligence with vulnerability and application risk.


Application Security (New / Expanded)


  • Solid understanding of secure application development , including common programming languages, frameworks, and architectural patterns.

  • Hands-on experience with Application Security testing methodologies , including:

  • Static Application Security Testing (SAST)

  • Dynamic Application Security Testing (DAST)

  • Software Composition Analysis (SCA)

  • Familiarity with OWASP Top 10 , API Security Top 10, and common application attack patterns.

  • Experience integrating security scanning tools into CI/CD pipelines .

  • Ability to perform threat modeling and design-level security assessments.

  • Strong understanding of authentication, authorization, session management, and data protection controls within applications.


Vulnerability & Threat Management

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities


This employer is required to notify all applicants of their rights pursuant to federal employment laws.


For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Federal Vulnerability Mgmt & App Security Engineer (US Citizen)
Federal Vulnerability Mgmt & App Security Engineer (US Citizen)

PSI Services • Salt Lake City (UT)

Remote
USD 106,000 - 144,000
Remote Vulnerability & App Security Engineer
Remote Vulnerability & App Security Engineer

PSI Services LLC • Northern (KY)

Hybrid
USD 113,000 - 138,000
401(k) plan
Pension plan
Health insurance
+4
Remote AppSec & Vulnerability Management Engineer
Remote AppSec & Vulnerability Management Engineer

PSI Services • Salt Lake City (UT)

Remote
USD 106,000 - 144,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

PCI Professional Services • United States

On-site
USD 110,000 - 160,000
Principal Application Security Analyst
Principal Application Security Analyst

Cybersecurity Jobs • Madison (WI)

Hybrid
USD 135,000 - 165,000
Health insurance
Dental insurance
Telehealth services
+3
Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)
Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)

ShorePoint, LLC • Washington

On-site
USD 110,000 - 160,000
144 hours PTO
11 holidays
Health insurance coverage 85%
+2
Application Security Analyst
Application Security Analyst

AccruePartners • Fort Mill (SC)

On-site
USD 70,000 - 90,000
Ongoing investment in professional development
Exposure to modern security platforms
Collaborative team environment
Vulnerability Engineer
Vulnerability Engineer

CBTS • United States

On-site
USD 80,000 - 85,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

United States Digital Space LLC • Seattle (WA), San Francisco (CA)

On-site
USD 110,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000