Senior Application Security Engineer
Job Description
Agile Defense is hiring a Senior Application Security Engineer to support enterprise-wide digital transformation through secure, reliable, and scalable integrated systems. In this remote role, you will help drive application security testing capabilities across the organization, with hands-on focus on Burp Enterprise and security scanning workflows.
Role focus
- Engineer and optimize integrated systems that enable enterprise-wide digital transformation initiatives.
- Develop solutions that improve system reliability, scalability, and security.
- Lead evaluation of new technologies and system architectures, translating findings into strategic recommendations.
- Perform DAST scanning with Burp Enterprise as a primary area of focus.
Core testing and security engineering requirements
- Ability to obtain and maintain a Public Trust Clearance, requiring U.S. citizenship.
- 1+ year experience supporting Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE plug-in environments using Veracode.
- 2+ years experience with Java, Python, .NET, or C#.
- 3+ years experience designing and implementing enterprise-wide security controls to protect applications, systems, network, or infrastructure services.
- Experience securing enterprise web applications using OWASP Top 10, CVSS, CWE, WASC, and SANS-25.
- Knowledge of federal compliance standards, including NIST 800-53, FIPS, or FedRAMP.
- 2+ years working in Linux environments, including basic troubleshooting for website connectivity issues.
- Familiarity with Linux and some type of coding and/or scripting.
- Experience with Burp Professional with a focus on SAST scanning.
- Experience using Veracode to perform SAST scanning.
- Experience with Eclipse, JDeveloper including pipeline development, or Visual Studio.
Technologies
- Veracode (SAST, DAST)
- Burp Enterprise, Burp Professional
- Java, Python, .NET, C#
- Eclipse, JDeveloper, Visual Studio
- OWASP Top 10, CVSS, CWE, WASC, SANS-25
- NIST 800-53, FIPS, FedRAMP
- Linux
- Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST)
Preferred skills
- Experience with Interactive Application Security Testing (IAST) capabilities and tools.
- Experience with HackerOne.
- Experience with Selenium.
- Experience writing bash scripts.
- Experience with OWASP ZAP or Burp Proxy.
Compensation and location
- Location: Remote (remote)
- Salary: USD 140,000 - 145,000 per year
Experience and education
- Minimum experience: 4 years
- Education: Bachelor’s degree in Systems Engineering, Computer Science, or related field
Benefits
- Health Insurance
- Life Insurance
- Paid Time Off
- Holiday Pay
- Short-term and long-term Disability
- Retirement
- Learning and Development opportunities
Similar Jobs
A