Sr. IT Application Security Engineer
Job Description
Support enterprise application security in a hybrid role based in Reston, VA, focusing on WAF administration, container image security scanning, and SDLC/CI-CD security controls.
Responsibilities
- Administer and enhance enterprise BIG-IP WAF capabilities, including building security policies, tuning rules, investigating false positives, troubleshooting application traffic issues, and maintaining web application protections
- Design, implement, and operate application security controls across enterprise applications and supporting platforms
- Perform container image security scanning and analyze vulnerabilities found in application and container images
- Assess severity and business risk for container vulnerabilities and collaborate directly with development teams to prioritize and remediate findings
- Partner with Development and DevOps teams to embed security controls into the SDLC and CI/CD pipelines
- Design and operate web application and API security protections, including policy configuration, rule tuning, automation, and continuous improvement
- Identify application security vulnerabilities, complete risk assessments, and recommend practical mitigation and remediation strategies
- Develop and maintain application security policies, standards, procedures, and controls
- Build and maintain security monitoring and telemetry for the application stack to improve proactive detection
- Conduct technical investigations tied to application security incidents and vulnerabilities
- Support container security activities, including image scanning, vulnerability risk assessments, and runtime security/hardening
- Operate and support security technologies across cloud and/or on-premises environments
- Troubleshoot security, application, and network-related issues and communicate findings and recommended actions clearly
- Partner with senior IT stakeholders to interpret application security risks, priorities, and remediation needs
Requirements
- 6–8 years of Application Security experience designing, implementing, and operating security controls in enterprise application environments
- Hands-on BIG-IP WAF administration, including building WAF policies, configuring protections, tuning rules/policies, troubleshooting in production, reducing false positives, and maintaining WAF controls
- Hands-on container image security/scanning, including reviewing scan results, evaluating vulnerabilities, determining risk and remediation priorities, and working directly with development teams
- Experience with a container security/scanning platform (tool not critical). Relevant examples include Prisma Cloud, Wiz, Snyk, or comparable technologies
- Strong web application security knowledge, including OWASP Top 10 vulnerabilities and practical application of security controls
- Experience conducting web application security scans, vulnerability assessments, and/or penetration testing
- Experience partnering directly with Development and DevOps teams to integrate security into the SDLC and CI/CD pipelines
- Experience with authentication and authorization technologies such as OAuth and OpenID
- Strong troubleshooting and communication skills, able to explain security risks and remediation requirements to both technical teams and senior IT stakeholders
- Bachelor’s degree in Information Security, Computer Science, Computer/Electrical Engineering, or a related discipline, and/or equivalent relevant professional experience
- Demonstrated production experience administering BIG-IP WAF, including building and tuning WAF policies
- Demonstrated hands-on experience with container image scanning and vulnerability management
- Experience personally reviewing container vulnerabilities and collaborating with developers on remediation
- Experience integrating security practices and controls into CI/CD and secure software development processes
- Experience operating cloud-based and/or on-premises security platforms
- Ability to investigate and troubleshoot security and network-related issues using established security methodologies and best practices
- Strong communicator who can work effectively with developers, DevOps engineers, operations teams, and senior IT stakeholders
- Collaborative and approachable, able to influence remediation and security improvements while maintaining cross-functional relationships
- Proof of eligibility to work in the United States
Technologies
- BIG-IP WAF
- OWASP Top 10
- OAuth
- OpenID
- Prisma Cloud
- Wiz
- Snyk
- CI/CD
- SDLC
Benefits
- 150-180K base salary + 7% Bonus
Location
- Hybrid in Reston, VA 20190
- 3 days on-site per week (Tues/Wed)