Application Security Engineer
Job Description
Contribute to application security for business-critical systems by partnering with clients and development teams across the software development lifecycle.
Responsibilities
- Partner with clients, application owners, and development teams to help maintain a resilient security posture for highly visible, business-critical applications
- Collaborate with application security teams to identify, prioritize, and remediate application security vulnerabilities throughout the SDLC
- Lead security discussions with application teams and provide guidance on secure development practices, security requirements, and application security best practices
- Conduct application security testing, including SAST, DAST, threat modeling, and application-level security assessments
- Use tools such as Veracode and Burp Suite DAST to support application security activities
- Apply current OWASP framework, standards, and best practices to identify risks and strengthen application security
- Track emerging application security threats and vulnerabilities, supporting development teams with effective security controls and remediation strategies
Requirements
- 6+ years of experience in information technology and cybersecurity or application security
- 3+ years of experience with Java, Python, .NET, or C#
- 3+ years of experience using Burp Suite DAST to perform DAST
- 3+ years designing and implementing enterprise-wide security controls to secure applications, systems, networks, or infrastructure services
- 3+ years experience with Linux or UNIX environments, including system navigation and troubleshooting basic website connectivity issues
- 2+ years experience with Veracode and development environments such as Eclipse and JDeveloper, including pipeline development and integration
- Experience securing enterprise web applications and frameworks, including OWASP Top 10, CVSS, CWE, WASC, and SANS-25
- Knowledge of federal security and compliance standards, including NIST 800-53, FIPS, or FedRAMP
- Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements
- HS diploma or GED
Nice if you have
- Experience with Interactive Application Security Testing (IAST) capabilities and tools
Technologies
- Java, Python, .NET, C#
- Burp Suite DAST, Veracode
- SAST, DAST
- OWASP, OWASP Top 10, CVSS, CWE, WASC, SANS-25
- Eclipse, JDeveloper
- NIST 800-53, FIPS, FedRAMP
Benefits
- Health, life, disability, financial, and retirement benefits
- Paid leave
- Professional development
- Tuition assistance
- Work-life programs
- Dependent care
- Recognition awards program acknowledging employees for exceptional performance and superior demonstration of company values
- Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs
Work model
- Onsite: Work will primarily be performed full-time at a customer facility, collaborating directly with colleagues and customers as required by the role
Vetting
- Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client
Identity statement
- During the hiring process, applicants will complete an identity verification process leveraging advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud
- Applicants are expected to be on camera during interviews and assessments
- Booz Allen may take a picture to verify identity and prevent fraud
Candidate AI usage policy
- AI is used as part of daily work, and responsible and ethical use is expected
- Use of artificial intelligence or other tools to assist with responses during interviews (in-person or virtual) is prohibited unless permission is explicitly provided
Compensation
- Projected compensation range: $62,000 to $141,000 (annualized USD)
- Range reflects typical salary for the position and is one component of Booz Allen’s total compensation package
- This posting will close within 90 days from the Posting Date
Location: Washington, DC (onsite)