Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
CD

Sr. IT Application Security Engineer (USC or Green Card a must)

Career Developers
🇺🇸 United States
Hybrid
Senior
1 week ago
  • WAF
  • Prisma
  • Wiz
  • Snyk
  • OWASP
  • Penetration Testing
  • Devops
  • CI/CD
  • OAuth
  • OpenID
  • Vulnerability Management
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV
Refer a friend: Referral fee program

Career Developers Inc., a distinguished staffing and consulting firm, is proud to celebrate 30 years of service excellence. As a GSA Contract holder, we offer comprehensive staffing solutions for both commercial and government sectors nationwide. By selectively partnering with clients who share our values, we ensure productive collaborations that set us apart in the industry. Our dedication to candidates involves managing expectations with precision through business intelligence, thorough interview preparation, transparent communication, and exceptional feedback throughout the process.

We are committed to advancing your career and look forward to supporting your professional growth.

-----------------------------------------------------------------------------------------------------------------------------------------------


Senior IT Application Security Engineer  (SME)
DEPARTMENT: Information Technology
REPORTS TO: Director, Information Security
LOCATION: Hybrid/Reston, VA – 3 days on-site in the office per week (Tues/Wed)
SALARY:  150-180K + 7% Bonus

Must have the following

  • 6–8 years of Application Security experience designing, implementing, and operating security controls within enterprise application environments.

  • Hands-on BIG-IP WAF administration experience, including building WAF policies, configuring protections, tuning rules/policies, troubleshooting issues, reducing false positives, and maintaining WAF controls in a production environment.

  • Hands-on container image security/scanning experience, including reviewing scan results, evaluating vulnerabilities, determining risk and remediation priorities, and working directly with development teams to resolve findings.

  • Experience with a container security/scanning platform.The specific tool is not critical; experience with platforms such as Prisma Cloud, Wiz, Snyk, or comparable technologies is relevant.

  • Strong web application security knowledge, includingOWASP Top 10 vulnerabilities and practical application of security controls.

  • Experience conducting web application security scans, vulnerability assessments, and/or penetration testing.

  • Experience partnering directly withDevelopment and DevOps teams to integrate security into the SDLC and CI/CD pipelines.

  • Experience with authentication and authorization technologies such asOAuth and OpenID.

  • Strong troubleshooting and communication skills, with the ability to explain security risks and remediation requirements to both technical teams and senior IT stakeholders.

Responsibilities

  • Administer and enhance enterpriseBIG-IP WAF capabilities, including building security policies, tuning rules, investigating false positives, troubleshooting application traffic issues, and maintaining effective web application protections.

  • Design, implement, and operate application security controls across enterprise applications and supporting platforms.

  • Performcontainer image security scanning and analyze vulnerabilities identified within application and container images.

  • Assess the severity and business risk of container vulnerabilities and partner directly with development teams to prioritize and remediate findings.

  • Work closely with Development and DevOps teams to embed security controls into theSDLC and CI/CD pipelines.

  • Design and operate web application and API security protections, including policy configuration, rule tuning, automation, and ongoing improvement.

  • Identify application security vulnerabilities, conduct risk assessments, and recommend practical mitigation and remediation strategies.

  • Develop and maintain application security policies, standards, procedures, and controls.

  • Develop security monitoring and telemetry for the application stack to improve proactive detection.

  • Conduct technical investigations related to application security incidents and vulnerabilities.

  • Support container security activities including image scanning, vulnerability risk assessments, and runtime security/hardening.

  • Operate and support security technologies across cloud and/or on-premises environments.

  • Troubleshoot security, application, and network-related issues and clearly communicate technical findings and recommended actions.

  • Partner with senior IT stakeholders to interpret application security risks, priorities, and remediation needs.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Computer/Electrical Engineering, or a related discipline, and/or equivalent relevant professional experience.

  • 6–8 years of hands-on Application Security experience.

  • Demonstrated production experience administeringBIG-IP WAF, particularly building and tuning WAF policies.

  • Demonstrated hands-on experience withcontainer image scanning and vulnerability management.

  • Experience personally reviewing container vulnerabilities and collaborating with developers on remediation—not simply operating or monitoring a scanning tool.

  • Experience with Prisma Cloud, Wiz, Snyk, or another comparable container/application security platform.Specific platform experience is not required if the candidate has strong transferable hands-on experience.

  • Strong understanding of OWASP Top 10 and common web application vulnerabilities.

  • Experience with web application security scanning, vulnerability assessments, and/or penetration testing.

  • Experience securing APIs and working with authentication/authorization technologies such as OAuth and OpenID.

  • Experience integrating security practices and controls into CI/CD and secure software development processes.

  • Experience operating cloud-based and/or on-premises security platforms.

  • Ability to investigate and troubleshoot security and network-related issues using established security methodologies and best practices.

  • Strong communicator who can work effectively with developers, DevOps engineers, operations teams, and senior IT stakeholders.

  • Collaborative and approachable, with the ability to influence remediation and security improvements while maintaining strong cross-functional relationships.

  • Proof of eligibility to work in the United States.

    INDH

    WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer WAF application Security engineer 

Sr. IT Application Security Engineer (USC or Green Card a must) · Career Developers

Auto apply with Likeremote