Career Developers Inc., a distinguished staffing and consulting firm, is proud to celebrate 30 years of service excellence. As a GSA Contract holder, we offer comprehensive staffing solutions for both commercial and government sectors nationwide. By selectively partnering with clients who share our values, we ensure productive collaborations that set us apart in the industry. Our dedication to candidates involves managing expectations with precision through business intelligence, thorough interview preparation, transparent communication, and exceptional feedback throughout the process.
We are committed to advancing your career and look forward to supporting your professional growth.
-----------------------------------------------------------------------------------------------------------------------------------------------
Senior IT Application Security Engineer (SME)DEPARTMENT: Information Technology
REPORTS TO: Director, Information Security
LOCATION: Hybrid/Reston, VA – 3 days on-site in the office per week (Tues/Wed)
SALARY: 150-180K + 7% Bonus
Must have the following skills to be considered for this position:
- Senior level, hands-on experience with conducting web application security scans, vulnerability assessments and penetration testing on applications.
Position Overview:
Our client is seeking a Senior Security Engineer with a strong hands-on Application Security background. This role will focus on designing, implementing, operating, and improving security controls across enterprise applications and supporting platforms.
The Senior Security Engineer will work closely with Development, DevOps, Operations, and Information Security teams to embed security throughout the SDLC and CI/CD process, strengthen web and API security, and identify and mitigate application vulnerabilities.
Responsibilities:
• Develop and maintain application security policies, procedures, and controls
• Partner with DevOps to build and maintain secure CI/CD pipelines
• Design and operate WAF and API security controls
• Tune security rules, reduce false positives, and automate policy updates
• Conduct web application security scans, vulnerability assessments, and penetration testing
• Identify application vulnerabilities, perform risk assessments, and recommend remediation
• Support container security, including runtime hardening, image scanning, and vulnerability assessments
• Develop security monitoring across the application stack
• Investigate application security incidents
• Work with IT leadership to communicate security risks and priorities
Required Experience
• 6 to 8 years of Application Security experience within enterprise environments
• Strong hands on web application security experience
• Strong knowledge of OWASP Top 10 vulnerabilities
• Experience with WAF and API security, including policy design and rule tuning
• Experience with application vulnerability scanning, security assessments, and/or penetration testing
• Experience with container security, image scanning, and runtime hardening
• Experience securing SDLC and CI/CD environments
• Knowledge of OAuth, OpenID, authentication, and authorization services
• Experience operating cloud and/or on premises security platforms
• Ability to troubleshoot security and network related issues
• Strong communication skills with the ability to work across Development, DevOps, Operations, and Security teams
Education
Bachelor's Degree in Information Security, Computer Science, Computer Engineering, Electrical Engineering, or equivalent professional experience.
Candidates must be eligible to work in the United States.