Senior Security Code Reviewer

Ashburn Consulting

Camp Springs (MD)

On-site

USD 175,000 - 205,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ashburn Consulting is looking for a Senior Security Code Reviewer based in Camp Springs, Maryland. In this role, you will lead application security testing, conduct secure code reviews, and guide DevSecOps integration.

The ideal candidate has over 10 years of experience in application security, including hands-on work with cloud environments and extensive security engineering skills. Competitive compensation and benefits are offered for this key position in supporting federal cybersecurity initiatives.

Qualifications

  • 10+ years of experience in application security.
  • Experience in automating application security scanning processes.
  • U.S. citizenship required.

Responsibilities

  • Conduct security code reviews and risk assessments.
  • Integrate security testing into DevSecOps pipelines.
  • Provide technical writing and mentoring.

Skills

Application Security Testing platforms
Zero Trust integration
AWS security best practices
Vulnerability management
Strong technical writing

Tools

Checkmarx
Burp Suite
Terraform
Kubernetes

Job description

  • Compensation: USD 175000 - USD 205000 - yearly
Company Description

Ashburn Consulting, LLC, based in the Washington, DC metropolitan area, specializes in providing network and network security solutions in complex environments to a select set of government and business clients. The company, an established leader in its field, is composed of an elite team of engineers and business consultants, each of whom is recognized, and highly regarded, within the network and security communities.

Job Description

Ashburn is seeking a Senior Security Code Reviewer to support a federal cybersecurity architecture opportunity. This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security evaluation for a proposal opportunity.

Primary Responsibilities
  • Conduct security code reviews and risk assessments for applications and enterprise systems.
  • Use application security testing tools to identify vulnerabilities and provide remediation guidance.
  • Integrate security testing into DevSecOps and CI/CD pipelines.
  • Review application architecture, source code, dependencies, infrastructure-as-code, and deployment practices.
  • Support secure coding standards, developer security training, and technical remediation guidance.
  • Evaluate and improve cloud, network, and enterprise system security.
  • Provide technical writing, reporting, and mentoring to engineering and development teams.
  • Support federal cybersecurity compliance objectives and secure development lifecycle requirements.
Qualifications
Required Qualifications
  • Candidates must be U.S. citizens.
  • Candidates must be willing and able to work as Ashburn W-2 employees. 1099 and corp-to-corp arrangements are not permitted for these roles.
  • DHS EOD / suitability is required.
  • 10+ years of experience automating application security scanning processes, Zero Trust integration, and data sanitization for Government or similarly complex enterprise systems.
  • Experience deploying and using Application Security Testing platforms such as Checkmarx.
  • Experience automating or supporting Zero Trust Network Access (ZTNA) and Secure Web Gateway (SWG) solutions.
  • Advanced security engineering experience across on-premises and cloud environments.
  • Experience implementing AWS security best practices, including VPC Flow Logs, Security Lake, and audit monitoring.
  • Experience building EKS clusters using Terraform and Kubernetes.
  • Experience creating custom hardened AMI builds.
  • Experience integrating network security tools such as Palo Alto, AlgoSec, Gigamon, and Corelight.
  • Experience reviewing, evaluating, and improving security of complex systems and networks.
  • Experience with vulnerability management, SIEM integrations, certificate management, single sign-on implementations, and federal regulatory compliance.
  • Demonstrated ability to lead security code reviews and conduct risk assessments.
  • Experience developing OS hardening strategies, evaluating firewall policies, and implementing enterprise infrastructure monitoring solutions.
  • Strong technical writing, training, and mentoring skills.
  • Ability to mentor development teams in secure coding practices and align technical solutions to Government cybersecurity objectives.
Preferred / Strongly Desired Qualifications
  • Experience with Burp Suite, Checkmarx One, PortSwigger, SonarQube, Fortify, SAST, DAST, SCA, API security testing, or IaC scanning.
  • Experience integrating application security testing into CI/CD pipelines.
  • Experience applying OWASP, NIST, DHS, DevSecOps, and secure software lifecycle practices.
  • Secure software certification preferred, such as CSSLP, GIAC secure software credential, EC-Council secure programmer certification, or comparable experience.
  • Prior DHS, DOD / DOW or federal application security experience.
Physical Requirements

Work is equally performed in the field as well as in a normal office environment. Lifting (up to 50lbs) may be required. Ladder climbing may be required. Driving is required. All duties performed with or without reasonable accommodations.

Equal Opportunity Employer Statement

Equal Opportunity Employer/Veterans/Disabled. An Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status. Ashburn Consulting is an Equal Opportunity and affirmative action employer. In compliance with the American with Disabilities Act Amendments Act (ADAAA), if you have a disability and would like to request and accommodation in order to apply for a position with Ashburn Consulting, please e-mail [emailprotected].

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Code ReviewerFull-timeEmployees work in a hybrid mode
Senior Security Code ReviewerFull-timeEmployees work in a hybrid mode

Ashburn Consulting LLC • Leesburg (VA)

On-site
USD 120,000 - 150,000
Senior Security Tools EngineerFull-timeEmployees work in a hybrid mode
Senior Security Tools EngineerFull-timeEmployees work in a hybrid mode

Ashburn Consulting LLC • Leesburg (VA)

On-site
USD 100,000 - 130,000
Senior Security Tools Engineer
Senior Security Tools Engineer

Ashburn Consulting • Camp Springs (MD)

On-site
USD 185,000 - 205,000
Splunk EngineerFull-timeEmployees work in a hybrid mode
Splunk EngineerFull-timeEmployees work in a hybrid mode

Ashburn Consulting LLC • Leesburg (VA)

On-site
USD 120,000 - 150,000
Senior AppSec Code Reviewer & Secure DevOps Lead
Senior AppSec Code Reviewer & Secure DevOps Lead

Ashburn Consulting • Camp Springs (MD)

On-site
USD 175,000 - 205,000
Lead Security Engineer
Lead Security Engineer

Dev Technology • Suitland (MD)

On-site
USD 120,000 - 190,000
Generous time-off policy
Flexible work schedules
401K matching
+1
Network Engineer Level IIIFull-timeEmployees work in a hybrid mode
Network Engineer Level IIIFull-timeEmployees work in a hybrid mode

Ashburn Consulting LLC • Leesburg (VA)

On-site
USD 90,000 - 130,000
Lead Security Engineer
Lead Security Engineer

ArdentMC • Rockville (MD)

Hybrid
USD 120,000 - 150,000
Competitive pay
Comprehensive health coverage
Flexible PTO
+2
Lead Security Engineer
Lead Security Engineer

Ardent MC • Rockville (MD)

Hybrid
USD 120,000 - 150,000
Competitive pay
Comprehensive health coverage
Flexible PTO
+3
Senior Engineer, Cloud and System Security
Senior Engineer, Cloud and System Security

SES Satellites • McLean (VA)

On-site
USD 140,000 - 180,000