Application Security Engineer
Application Security
Data Security
DevOps
DevSecOps
Engineer
Facilities Management
Identity and Access Management
Information Security
InfoSec
Project Management
Risk Management
Secure Software Development Lifecycle
Security
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Software Security
Job Description
Application Security Engineer role focused on embedding security practices across the software development lifecycle and improving software security posture.
Responsibilities
- Integrate security practices throughout the software development lifecycle to enhance and maintain the security posture of software
- Use advanced consulting skills and extensive technical expertise, including full industry knowledge
- Design innovative solutions to complex problems
- Operate with limited direction while mentoring and supervising team members
Requirements
- 5+ years of experience in cybersecurity, application security, product security, or software engineering
- Experience implementing or assessing Secure SDLC and application security programs
- Experience leading client engagements and managing multiple priorities
- Experience performing architecture reviews, threat modeling, and/or security assessments
- Experience with software supply chain security concepts, including SBOMs, dependency management, code signing, artifact integrity, and secure build pipelines
- Experience implementing or evaluating application security tools, including SAST, DAST, SCA, IaC scanning, container security, API security, secrets detection, and software composition analysis
- Experience applying Agile, Scrum, and DevSecOps operating models in large-scale software development environments
- Knowledge of secure software development principles and modern application architectures, including cloud-native, microservices, APIs, containers, Kubernetes, and serverless environments
- Knowledge of authentication, authorization, cryptography, API security, and cloud security
- Knowledge of vulnerability management processes, risk prioritization methodologies, and remediation workflows
- Ability to translate complex technical risks into executive-level briefings, business cases, and actionable roadmaps
- Communicate effectively with technical and executive stakeholders
- Bachelor’s degree in CS, Cybersecurity, Information Systems, or Engineering
Technologies
- SBOMs, SAST, DAST, SCA, IaC scanning, container security, API security, secrets detection, software composition analysis
- Agile, Scrum, DevSecOps
- microservices, Kubernetes, cloud-native, serverless environments
- authentication, authorization, cryptography
- secure build pipelines
Nice If You Have
- Experience designing or maturing enterprise application security and product security programs
- Experience with secure development requirements for regulated industries, including healthcare, financial services, industrial control systems, automotive, aerospace, or critical infrastructure
- Experience applying industry frameworks such as OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, and MITRE ATT&CK or ATLAS
- Experience developing technical proposals, responding to RFPs, creating Statements of Work (SOWs), and supporting business development initiatives
- Experience leading executive workshops, stakeholder interviews, and technical design sessions
- Ability to mentor junior team members, provide technical leadership, and contribute to practice development and thought leadership
- Ability to travel up to 50% of the time, depending on client needs
- Excellent written and verbal communication skills
- Excellent facilitation skills
- Master’s degree in Cybersecurity, CS, Software Engineering, Information Assurance, or a related technical field
Work Model
- Onsite: Work will primarily be performed at a Booz Allen office or customer facility
- Employees working virtually are generally expected to have their cameras on during meetings
Identity Statement
- Expected to be on camera during interviews and assessments
- Booz Allen reserves the right to take your picture to verify identity and prevent fraud
Candidate AI Usage Policy
- Use of artificial intelligence (AI) or other tools to assist with responses during interviews (in-person or virtual) is prohibited unless permission is explicitly provided
Non-Discrimination
- All qualified applicants receive consideration for employment without regard to disability, protected veteran status, or any other status protected by applicable federal, state, local, or international law
Location: Annapolis Junction, MD (onsite)
Salary: USD 86,900 - 198,000 per yearly
Minimum Experience: 5 years
Education: Bachelor’s degree in CS, Cybersecurity, Information Systems, or Engineering
Similar Jobs
A