
Application Security Engineer
Posted Aug 12

Posted Aug 12
This is a fully remote position, open to applicants in United States.
• Conduct application security assessments and vulnerability evaluations for web applications, APIs, services, containers, dependencies, and delivery environments.
• Assist with automated security scanning and set up and maintain security scanning tools throughout development, build, testing, release, and runtime processes.
• Document, prioritize, track, and verify vulnerabilities until they are remediated and resolved.
• Keep records of vulnerability status, remediation evidence, and closure documentation.
• Offer secure coding practices and remediation advice to development teams.
• Facilitate the integration of security tools and controls within CI/CD pipelines.
• Implement automated security gates, policy enforcement, and reporting workflows.
• Integrate DevSecOps tools via APIs.
• Create proof-of-concept secure reference implementations and sample applications.
• Preserve reusable secure design patterns and examples.
• Develop security utility applications, scripts, dashboards, integrations, and automation workflows.
• Monitor application security standards and controls in accordance with Zero Trust, NIST, CISA, and CIS frameworks.
• Gather security assessment data, scanning results, vulnerability evidence, remediation status, and operational metrics.
• Support enterprise-level DevSecOps, vulnerability reduction, secure software development, and application security modernization efforts across USCIS programs.
• Collaborate with development, security, platform, operations, and other technical teams.
• Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Engineering, or a related discipline.
• At least 4 years of professional IT experience along with 4 years of experience supporting application security, cybersecurity, DevSecOps, or closely related fields.
• In-depth technical knowledge of application security technologies, specialized applications, and operational environments.
• Proven experience in conducting technical and functional analysis, system integration, implementation, documentation, and providing technical guidance for complex application security or DevSecOps projects.
• Familiarity with application security testing and vulnerability assessments.
• Experience in secure coding practices and offering remediation guidance to development teams.
• Proficient in SAST, DAST, SCA, container scanning, and dependency security.
• Experience in integrating security controls and tools into CI/CD pipelines and DevSecOps workflows.
• Background in developing proof-of-concept applications, secure reference implementations, utility applications, scripts, dashboards, or API-based integrations.
• Knowledge of vulnerability management workflows, including triage, documentation, remediation tracking, validation, and closure.
• Awareness of Zero Trust, NIST, CISA, CIS, OWASP, and secure software development lifecycle practices.
• Proven ability to collaborate with development, security, platform, operations, and other technical teams.
• Willingness to undergo the government-issued background investigation process.
• Competitive pay.
• Comprehensive health coverage.
• Flexible PTO.
• Federal holidays off.
• Tuition reimbursement.
• Professional development support.
• Wellness stipends.
• Flexible work arrangements.
Avnet
Teradyne
Intetics
New Charter Technologies
Get handpicked remote jobs straight to your inbox weekly.