Sr. IT Application Security Engineer (USC or Green Card a must)

JobDiva, Inc.

Reston (VA)

Hybrid

USD 150,000 - 180,000

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Career Developers Inc. is seeking a Senior IT Application Security Engineer (SME) to lead security for enterprise apps and DevOps pipelines. The role is Hybrid/Reston, VA with three days on-site weekly (Tue/Wed) and reports to Information Security leadership.

The candidate will design and implement security controls, perform container image scanning, and collaborate with Development and DevOps teams to reduce risk across cloud and on‑prem environments.

Qualifications

  • 6–8 years of Application Security experience.
  • Hands-on BIG-IP WAF administration and tuning.
  • Hands-on container image security scanning and remediation.
  • Experience with container security platforms (Prisma Cloud/Wiz/Snyk).
  • Strong OWASP Top 10 knowledge and secure coding practices.

Responsibilities

  • Administer and enhance BIG-IP WAF capabilities and security policies.
  • Design, implement, and operate security controls across enterprise apps.
  • Perform container image security scanning and analyze vulnerabilities.
  • Embed security into SDLC and CI/CD pipelines with DevOps teams.
  • Develop and maintain security policies, standards, and controls.
  • Provide proactive security monitoring and telemetry for the stack.

Skills

Security knowledge
Communication skills
SDLC/DevSecOps

Education

Bachelor’s degree in Information Security/CS/related

Tools

BIG-IP WAF
Container security tooling
Prisma Cloud / Wiz / Snyk
OAuth / OpenID

Job description

Career Developers Inc., a distinguished staffing and consulting firm, is proud to celebrate 30 years of service excellence. As a GSA Contract holder, we offer comprehensive staffing solutions for both commercial and government sectors nationwide. By selectively partnering with clients who share our values, we ensure productive collaborations that set us apart in the industry. Our dedication to candidates involves managing expectations with precision through business intelligence, thorough interview preparation, transparent communication, and exceptional feedback throughout the process.

We are committed to advancing your career and look forward to supporting your professional growth.

Senior IT Application Security Engineer (SME)

Department: Information Technology

Reports to: Director, Information Security

Location: Hybrid/Reston, VA - 3 days on-site in the office per week (Tues/Wed)

Salary: 150-180K + 7% Bonus

Must have the following
  • 6–8 years of Application Security experience designing, implementing, and operating security controls within enterprise application environments.

  • Hands-on BIG-IP WAF administration experience, including building WAF policies, configuring protections, tuning rules/policies, troubleshooting issues, reducing false positives, and maintaining WAF controls in a production environment.

  • Hands‑on container image security/scanning experience, including reviewing scan results, evaluating vulnerabilities, determining risk and remediation priorities, and working directly with development teams to resolve findings.

  • Experience with a container security/scanning platform. The specific tool is not critical; experience with platforms such as Prisma Cloud, Wiz, Snyk, or comparable technologies is relevant.

  • Strong web application security knowledge, including OWASP Top 10 vulnerabilities and practical application of security controls.

  • Experience conducting web application security scans, vulnerability assessments, and/or penetration testing.

  • Experience partnering directly with Development and DevOps teams to integrate security into the SDLC and CI/CD pipelines.

  • Experience with authentication and authorization technologies such as OAuth and OpenID.

  • Strong troubleshooting and communication skills, with the ability to explain security risks and remediation requirements to both technical teams and senior IT stakeholders.

Responsibilities
  • Administer and enhance enterprise BIG-IP WAF capabilities, including building security policies, tuning rules, investigating false positives, troubleshooting application traffic issues, and maintaining effective web application protections.

  • Design, implement, and operate application security controls across enterprise applications and supporting platforms.

  • Perform container image security scanning and analyze vulnerabilities identified within application and container images.

  • Assess the severity and business risk of container vulnerabilities and partner directly with development teams to prioritize and remediate findings.

  • Work closely with Development and DevOps teams to embed security controls into the SDLC and CI/CD pipelines.

  • Design and operate web application and API security protections, including policy configuration, rule tuning, automation, and ongoing improvement.

  • Identify application security vulnerabilities, conduct risk assessments, and recommend practical mitigation and remediation strategies.

  • Develop and maintain application security policies, standards, procedures, and controls.

  • Develop security monitoring and telemetry for the application stack to improve proactive detection.

  • Conduct technical investigations related to application security incidents and vulnerabilities.

  • Support container security activities including image scanning, vulnerability risk assessments, and runtime security/hardening.

  • Operate and support security technologies across cloud and/or on-premises environments.

  • Troubleshoot security, application, and network-related issues and clearly communicate technical findings and recommended actions.

  • Partner with senior IT stakeholders to interpret application security risks, priorities, and remediation needs.

Requirements
  • Bachelor’s degree in Information Security, Computer Science, Computer/Electrical Engineering, or a related discipline, and/or equivalent relevant professional experience.

  • 6–8 years of hands‑on Application Security experience.

  • Demonstrated production experience administering BIG‑IP WAF, particularly building and tuning WAF policies.

  • Demonstrated hands‑on experience with container image scanning and vulnerability management.

  • Experience personally reviewing container vulnerabilities and collaborating with developers on remediation—not simply operating or monitoring a scanning tool.

  • Experience with Prisma Cloud, Wiz, Snyk, or another comparable container/application security platform. Specific platform experience is not required if the candidate has strong transferable hands‑on experience.

  • Strong understanding of OWASP Top 10 and common web application vulnerabilities.

  • Experience with web application security scanning, vulnerability assessments, and/or penetration testing.

  • Experience securing APIs and working with authentication/authorization technologies such as OAuth and OpenID.

  • Experience integrating security practices and controls into CI/CD and secure software development processes.

  • Experience operating cloud-based and/or on-premises security platforms.

  • Ability to investigate and troubleshoot security and network-related issues using established security methodologies and best practices.

  • Strong communicator who can work effectively with developers, DevOps engineers, operations teams, and senior IT stakeholders.

  • Collaborative and approachable, with the ability to influence remediation and security improvements while maintaining strong cross‑functional relationships.

  • Proof of eligibility to work in the United States.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Application Security Architect & Engineer
Application Security Architect & Engineer

Mbi Llc • Richmond (VA)

On-site
USD 120,000 - 150,000
Application Security Engineer
Application Security Engineer

Eliassen Group • Washington

On-site
USD 90,000 - 120,000
Application Security Engineer
Application Security Engineer

Talentify • Philadelphia

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Security Engineer
Security Engineer

Wuxi Apptec, Inc. • Fort Snelling Unorganized Territory (MN)

Hybrid
USD 110,000 - 150,000
Senior Infrastructure Security Engineer
Senior Infrastructure Security Engineer

United States Digital Space LLC • United States

On-site
USD 87,000 - 161,000
Health insurance
401K & stock purchase
Tuition reimbursement
+2
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000