Sr. IT Application Security Engineer
Job Description
The Sr. IT Application Security Engineer will serve as a senior technical SME focused on enterprise application protection, with ownership across BIG-IP WAF administration, application security control design, and container image security scanning. The role partners closely with Development and DevOps teams to incorporate security into SDLC and CI/CD workflows, while also conducting risk assessments, investigations, and remediation support.
Key Responsibilities
- Administer and continuously improve enterprise BIG-IP WAF capabilities, including building security policies, tuning detection rules, investigating false positives, troubleshooting application traffic issues, and maintaining effective web application protections.
- Design, implement, and operate application security controls across enterprise applications and supporting platforms.
- Perform container image security scanning, analyze vulnerabilities found in application and container images, and support risk-based outcomes.
- Assess vulnerability severity and business risk, then partner with development teams to prioritize and remediate findings.
- Collaborate with Development and DevOps to embed security controls into the SDLC and CI/CD pipelines.
- Design and operate web application and API security protections, including policy configuration, rule tuning, automation, and ongoing improvement.
- Identify application security vulnerabilities, perform risk assessments, and recommend practical mitigation and remediation strategies.
- Develop and maintain application security policies, standards, procedures, and controls.
- Build security monitoring and telemetry for the application stack to enhance proactive detection.
- Conduct technical investigations related to application security incidents and vulnerabilities.
- Support container security activities including image scanning, vulnerability risk assessments, and runtime security and hardening.
- Operate and support security technologies across cloud and/or on-premises environments.
- Troubleshoot security, application, and network-related issues, and communicate findings and recommended actions clearly.
- Partner with senior IT stakeholders to interpret application security risks, define priorities, and address remediation needs.
Required Qualifications
- 6–8 years of Application Security experience designing, implementing, and operating security controls in enterprise application environments.
- Hands-on BIG-IP WAF administration, including building WAF policies, configuring protections, tuning rules and policies, troubleshooting production issues, reducing false positives, and maintaining WAF controls.
- Hands-on container image security scanning experience, including reviewing results, evaluating vulnerabilities, determining risk and remediation priorities, and working directly with development teams to resolve findings.
- Experience with a container security/scanning platform; relevant platforms include Prisma Cloud, Wiz, Snyk, or comparable tools.
- Strong web application security expertise, including practical understanding and application of OWASP Top 10 vulnerabilities.
- Experience conducting web application security scans, vulnerability assessments, and/or penetration testing.
- Experience partnering directly with Development and DevOps teams to integrate security into SDLC and CI/CD pipelines.
- Experience with authentication and authorization technologies such as OAuth and OpenID.
- Strong troubleshooting and communication skills, including the ability to explain security risks and remediation requirements to both technical teams and senior IT stakeholders.
- Bachelor’s degree in Information Security, Computer Science, Computer/Electrical Engineering, or a related discipline, and/or equivalent relevant professional experience.
Technologies
- BIG-IP WAF
- Container image security/scanning
- Container security/scanning platforms (Prisma Cloud, Wiz, Snyk, or comparable)
- OWASP Top 10
- OAuth and OpenID
- SDLC and CI/CD
- Web application security scanning
- Penetration testing
Location
Reston, VA (Hybrid) with 3 days on-site in the office each week (Tues/Wed).
Compensation
$150,000 - $180,000 per year plus 7% bonus.