Application Security Engineer
Application Security
Application Security Engineering
Aws Solutions Architect
Cloud Platforms
Data Security
Dynamic Application Security Testing
Engineer
Facilities Management
Information Security
InfoSec
Management
Pki/tls
Product Security
Project Management
Risk Governance
Risk Management
Security
Security Assurance
Security Automation
Security Compliance
Security Operations
Security Remediation
Security Standards
Security Testing
Security Testing Tools
Software Security
Vulnerability Management
Web Security
Job Description
Steampunk is hiring an Application Security Engineer to help harden enterprise environments and reduce persistent web application risk across a portfolio. This onsite role in McLean, VA 22102 blends practical security remediation work with the opportunity to streamline vulnerability management through proactive solutions and automation. You will collaborate across system administration, development, security assurance, and the SOC to turn findings into measurable improvements.
Compensation: USD 100,000 - 155,000 per year
Experience: 3+ years
Education: Master’s Degree
Responsibilities
- Provide subject matter expertise for risk assessments while working in an Agile environment with an understanding of the full software development lifecycle.
- Ensure security practices are communicated and implemented within application development portfolios.
- Coordinate with application development and security assurance teams so vulnerability findings are understood and handled appropriately through remediation or baselining.
- Document and socialize security findings and remediation solutions in an enterprise knowledge base.
- Support the Information Assurance Branch and the SOC with scan analysis, and partner with development teams to remediate security findings.
Requirements
- Ability to obtain a U.S. government Security Clearance.
- Hold at least one professional certification relevant to the technical service provided, and maintain a certification relevant to the product being deployed and/or maintained.
Preferred Qualifications
- Former Developer or Systems Administrator experience.
- Working knowledge of enterprise application build and deployment technologies such as Maven, Gradle, GIT, Jenkins, Ansible, Java, C#/.NET, Apache Tomcat, Apache HTTP Server, IIS, F5, Oracle, MSSQL, PostgreSQL.
- Experience and working knowledge of AWS and Azure GovClouds.
- Ability to analyze DISA STIG audit compliance scan results and provide resolution recommendations.
- Ability to analyze the security environment and provide recommendations.
- Working knowledge of JIRA, Service Now, or equivalent tooling.
- Working knowledge of operating system and dynamic application security testing tools such as Invicti, Web Inspect, and DAST/IAST suites.
- Experience using Python to automate tasks.
Tools and Technologies
- PKI/TLS
- Maven, Gradle, GIT, Jenkins, Ansible, Java, C#/.NET
- Apache Tomcat, Apache HTTP Server, IIS, F5
- Oracle, MSSQL, PostGres
- AWS, Azure GovClouds
- DISA STIG
- JIRA, Service Now
- Invicti, Web Inspect, DAST/IAST suites
- Python
Certifications
- CEH, GFACT, GPEN, OSCP or other relevant industry certifications.
- Other application-based technology-specific certifications.