Application Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Application Security Engineer (Cybersecurity): Integrating security practices throughout the software development lifecycle and maturing application security programs with an accent on secure software supply chains, cloud-native architectures, and DevSecOps. Focus on threat modeling, architecture reviews, security tooling, vulnerability prioritization, and translating technical risks into executive-level roadmaps.
Location: Remote role based in the United States, with occasional work at a Booz Allen or customer facility; listed locations are Annapolis Junction and Bethesda, Maryland.
Salary: $86,900–$198,000 annualized USD.
Company
provides consulting and technology services for government and enterprise clients.
What you will do
- Integrate security practices across the software development lifecycle and maintain software security posture.
- Implement and assess Secure SDLC, application security, and product security programs.
- Perform architecture reviews, threat modeling, security assessments, and vulnerability risk prioritization.
- Evaluate and implement SAST, DAST, SCA, IaC scanning, container security, API security, and secrets detection tools.
- Develop solutions for cloud-native, microservices, API, container, Kubernetes, and serverless environments.
- Lead client engagements, communicate risks to technical and executive stakeholders, and mentor team members.
Requirements
- 5+ years of experience in cybersecurity, application security, product security, or software engineering.
- Experience with Secure SDLC programs, architecture reviews, threat modeling, security assessments, and client engagements.
- Knowledge of software supply chain security, including SBOMs, dependency management, code signing, artifact integrity, and secure build pipelines.
- Experience with Agile, Scrum, and DevSecOps in large-scale software development environments.
- Knowledge of authentication, authorization, cryptography, API security, cloud security, and vulnerability management.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or Engineering.
Nice to have
- Experience maturing enterprise application security or product security programs.
- Knowledge of OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, MITRE ATT&CK, or ATLAS.
- Experience in regulated industries such as healthcare, financial services, automotive, aerospace, or critical infrastructure.
- Experience with proposals, RFPs, Statements of Work, executive workshops, and technical design sessions.
- Willingness to travel up to 50% depending on client needs and a master’s degree in a related technical field.
Culture & Benefits
- Remote work with occasional in-person work at a Booz Allen or customer facility.
- Health, life, disability, financial, and retirement benefits.
- Paid leave, professional development, tuition assistance, work-life programs, and dependent care.
- Recognition awards and opportunities to mentor, provide technical leadership, and contribute to thought leadership.
- Camera use is generally expected during virtual meetings; AI assistance during interviews is prohibited unless explicitly permitted.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →