Назад
Company hidden
8 дней назад

Application Security Engineer (Cybersecurity)

86 900 - 198 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Cybersecurity): Integrating security practices throughout the software development lifecycle and strengthening application security programs with an accent on secure build pipelines, software supply chain security, and cloud-native architectures. Focus on threat modeling, security tool evaluation, vulnerability prioritization, and translating complex technical risks into executive-level roadmaps.

Location: Remote within the United States, with possible work at Booz Allen or customer facilities. Primary locations are Annapolis Junction, Maryland, and Bethesda, Maryland; travel may reach 50% depending on client needs.

Salary: $86,900–$198,000 annualized USD.

Company

hirify.global provides consulting and technology services focused on complex government and commercial challenges.

What you will do

  • Integrate security practices throughout the software development lifecycle and improve software security posture.
  • Implement and assess Secure SDLC and application security programs.
  • Perform architecture reviews, threat modeling, and security assessments.
  • Address software supply chain security, including SBOMs, dependency management, code signing, artifact integrity, and secure build pipelines.
  • Evaluate application security tools covering SAST, DAST, SCA, IaC scanning, container security, API security, and secrets detection.
  • Translate technical risks into executive briefings, business cases, and actionable roadmaps while mentoring team members.

Requirements

  • 5+ years of experience in cybersecurity, application security, product security, or software engineering.
  • Experience with Agile, Scrum, and DevSecOps in large-scale software development environments.
  • Knowledge of cloud-native architectures, microservices, APIs, containers, Kubernetes, and serverless environments.
  • Knowledge of authentication, authorization, cryptography, API security, cloud security, and vulnerability management.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.
  • Ability to work remotely within the United States and occasionally at Booz Allen or customer facilities.

Nice to have

  • Experience maturing enterprise application security or product security programs.
  • Experience with regulated industries and frameworks such as OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, and MITRE ATT&CK or ATLAS.
  • Experience with technical proposals, RFPs, Statements of Work, executive workshops, and technical design sessions.
  • Mentoring, technical leadership, facilitation, and thought leadership experience.
  • Master’s degree in Cybersecurity, Computer Science, Software Engineering, Information Assurance, or a related technical field.

Culture & Benefits

  • Health, life, disability, financial, and retirement benefits.
  • Paid leave, professional development, tuition assistance, work-life programs, and dependent care.
  • Recognition awards for exceptional performance and demonstration of company values.
  • Virtual employees are generally expected to keep cameras on during meetings.
  • Identity verification using biometrics and artificial intelligence is required during the hiring process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →