Based in Reston, Virginia with a hybrid work model across the DC, MD, and VA region, this Application Cyber Security Engineer role focuses on securing software and cloud environments for a healthcare payor. The position supports DevSecOps, AWS cloud security, and cloud migration initiatives, with monthly on-site presence in Reston to align with project needs.
Responsibilities
- Design and deploy application security controls to build trusted, secure systems
- Support DevSecOps practices including SAST, DAST, IAST, SCA, penetration testing, secure code reviews, and threat modeling
- Secure AWS environments across IAM, EC2, S3, Lambda, EKS, CloudTrail, Security Hub, and GuardDuty
- Manage Kubernetes and container security including Amazon EKS, pod security, RBAC, network policies, and runtime hardening
- Operate CNAPP, CSPM, KSPM, and CWPP platforms such as Wiz, CrowdStrike, or similar solutions
- Map application and cloud-native controls to frameworks including NIST CSF, NIST 800-53, ISO 27001, SOC2, CIS Benchmarks, and MITRE ATT&CK
- Implement infrastructure-as-code and policy-as-code using Terraform, Helm, CloudFormation, and Rego/OPA
- Collaborate with development teams to communicate security findings and drive practical remediation
- Advise management on cybersecurity policies, processes, and procedures
Requirements
- Strong hands-on experience in Application Security, Secure SDLC, DevSecOps, Cloud Security, and Vulnerability Management
- Deep knowledge of OWASP Top 10, API Security Top 10, and secure coding practices
- Hands-on experience with CNAPP, CSPM, KSPM, CWPP platforms (Wiz, CrowdStrike, or similar)
- Hands-on AWS cloud security experience across core services
- Deep knowledge of Kubernetes and container security including Amazon EKS
- Strong CI/CD and DevSecOps pipeline security experience
- Experience with IaC and policy-as-code tools — Terraform, Helm, CloudFormation, Rego/OPA
- Strong written and verbal communication skills for both technical and non-technical audiences
- One or more certifications required: CISSP, CISM, CEH, or CISA
Technologies
- AWS IAM, AWS EC2, AWS S3, AWS Lambda, AWS EKS, AWS CloudTrail, AWS Security Hub, AWS GuardDuty
- Kubernetes, Amazon EKS
- CNAPP, CSPM, KSPM, CWPP
- Wiz, CrowdStrike
- Terraform, Helm, CloudFormation, Rego, OPA
- NIST CSF, NIST 800-53, ISO 27001, SOC2, CIS Benchmarks, MITRE ATT&CK
- SAST, DAST, IAST, SCA, RBAC
Project Description
Our client, a leading healthcare payor in Reston, VA, seeks a software-focused Application Cyber Security Engineer to support DevSecOps, AWS Cloud Security, and cloud migration initiatives. This role is largely remote with monthly on-site visits to Reston, VA. Candidates must reside in the DC, MD, or VA area, as travel expenses will not be reimbursed. The interview process consists of two rounds, with a mandatory face-to-face final round in Reston, VA.
Nice-to-have Skills
- AWS Certified Security Specialty certification
- Experience in healthcare or similarly regulated industries
- Background in cloud migration security initiatives
Company Overview
Glint Tech Solutions is a women-owned global staffing and IT recruiting firm connecting top technical talent with leading enterprise clients across the United States.