Senior AppSec Engineer - Burp Suite, Linux, & Custom Extensions
Phia
Senior AppSec Engineer - Burp Suite Enterprise, Linux, and Custom Extensions Bring your own Burp extensions. We'll bring the Linux boxes. About the Role phia is hiring a Senior Application Security Engineer to join a small, highly technical AppSec team supporting a federal civilian client. This is a fully remote role within the United States. You will work directly alongside the government technical lead and our existing senior AppSec engineer as the third member of a tight-knit two-to-three person team operating inside a broader 19-person cybersecurity program. This is a hands-on engineering seat, not a paper-pusher role. The client is a deeply technical Linux/Unix practitioner with strong DevSecOps and AppSec instincts who runs lean by design. We are looking for an engineer who can hold a peer-level technical conversation with him on day one, push back when warranted, and drive technical discussions with development and platform teams outside of security. If you live in a terminal, build your own tooling, and treat Burp Suite as an extensible platform rather than a point-and-click scanner, you will be at home here. Who You Are
- A *nix native. You administer your own Linux servers from the command line every day and you do not reach for a GUI when bash, systemd, or a quick Python script will do.
- An AppSec specialist whose center of gravity is dynamic application security testing. Burp Suite Enterprise for automated DAST and Burp Suite Professional for manual verification are your primary instruments.
- A builder. You write custom Burp extensions, session handling rules, and macros to solve problems that the out-of-the-box product cannot. You convert ad-hoc Python and shell scripts into proper Ansible roles and playbooks without being asked twice.
- Energetic and direct. You lead technical discussions with application development, platform, and identity teams and translate AppSec findings into concrete remediation work.
- Naturally curious about AppSec and DevSecOps research, and you keep current through OWASP, security advisories, and hands-on lab work with new tooling and techniques.
- Own day-to-day operations of the Burp Suite Enterprise DAST program: scan scheduling, agent and Linux infrastructure health, scan tuning, and result triage across multiple federal application environments.
- Configure and troubleshoot authenticated scans against modern web applications and APIs, including recorded login sequences (via the official Burp recorder Chrome extension), session-handling rules, and macro-based re-authentication.
- Diagnose and resolve Burp Enterprise scan failures end to end: consecutive audit-item failures, skipped insertion points, timeouts, session invalidation, and authentication state loss. You read scan logs and traces, not just dashboards.
- Extend Burp Suite Professional with custom extensions (Python/Java/Montoya API) to automate repetitive manual verification, custom authentication flows, and findings validation for the bug bounty program.
- Make Burp Enterprise work against authenticated APIs and applications that were designed for human authorization-code flows by adapting them to OAuth 2.0 client-credentials and other machine-to-machine patterns suitable for automated scanning.
- Design and implement authenticated scan workflows that survive multi-factor authentication, including SMS one-time passwords, TOTP tokens, hardware dongles, PIV and smart card client-certificate authentication, and SSO federation.
- Partner with the application and identity teams to provision dedicated lower-environment test accounts and authentication paths that allow continuous, hands-off DAST coverage.
- Clearly articulate and apply the distinctions between OAuth 2.0 authorization-code flow, client-credentials flow, SAML, and OpenID Connect when designing scan authentication strategies.
- Administer the AppSec team's own Linux infrastructure in AWS (currently EC2 with containerized Burp Enterprise components) and contribute to the migration to on-premise OpenShift.
- Convert legacy Python and shell tooling left behind by previous engineers into Ansible roles and playbooks; manage YAML, Dockerfiles, and Kubernetes manifests as code.
- Use CloudFormation for AWS infrastructure as code; comfortably operate at the Kubernetes and Linux CLI for routine tasks (disk usage with df, service status with systemctl, container lifecycle, log retrieval, and basic networking diagnostics).
- Integrate AppSec tooling into GitHub Actions workflows alongside Dependabot SCA, including the appropriate use of workflow_dispatch versus workflow_call patterns and reusable workflows.
- Work with development teams to embed scan gates and remediation feedback loops into existing CI/CD pipelines (GitHub Actions primary; Jenkins as encountered).
- Provide secondary support to the broader AppSec toolset: Veracode SAST, Contrast IAST for interactive scanning and runtime security testing, GitHub Advanced Security workflows, and the HackerOne bug bounty program (validating reported findings with Burp Suite Professional).
- Veracode SAST is part of the program but is not the primary focus of this position. This role is centered on Burp.
- 6+ years of hands-on application security engineering experience.
- Demonstrable, current expertise with Burp Suite Enterprise (DAST operations, scan authentication, troubleshooting) and Burp Suite Professional (manual testing, repeater, intruder, session handling).
- Strong Linux/Unix administration skills from the command line. Comfortable answering basic questions like "what command checks disk space" or "how do I check whether a service is running" without hesitation, and equally comfortable with more advanced diagnostics.
- Proficiency writing custom Burp extensions and security automation scripts in Python (and ideally Java for the Montoya API).
- Working experience with Kubernetes, Docker, and YAML-driven infrastructure.
- Experience with AWS CloudFormation (or equivalent IaC) and Ansible.
- Experience integrating security scanning into CI/CD pipelines using GitHub Actions, including reusable workflows and Dependabot.
- Demonstrated experience designing authenticated DAST scans against applications protected by SSO, MFA, OTP, or PIV/smart card authentication.
- Clear understanding of modern authentication and authorization protocols, including OAuth 2.0 flows (authorization-code, client-credentials, refresh tokens), SAML, and OpenID Connect.
- U.S. Citizenship and ability to obtain and maintain the required federal Public Trust clearance.
- OpenShift administration experience, particularly migration of workloads from EKS or self-managed Kubernetes.
- Experience operationalizing Contrast IAST or another interactive application security testing platform.
- Experience supporting or validating findings from a managed bug bounty program (HackerOne, Bugcrowd, etc.).
- Active participation in AppSec or DevSecOps research, OWASP chapters, CTFs, or public security publications.
- Relevant certifications such as OSCP, OSWE, GWAPT, Burp Suite Certified Practitioner, CKA/CKS, AWS Security Specialty, or CISSP.
- Fully remote within the United States.
- Standard work day is 8.5 hours with a 30-minute lunch, starting at 8:30 AM EDT with the federal client daily stand-up. Hours are flexible around the stand-up and any scheduled client meetings.
- The client is generally on-site; the phia team is remote with occasional, well-coordinated on-site visits planned in advance.
- Small team: you will be one of two to three engineers focused on the AppSec work stream, with direct, daily collaboration with the government technical lead.
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Senior AppSec Engineer - Burp Suite, Linux, & Custom Extensions in Fairfax, VA vacancy
- ...Senior System Administrator/System Engineer (Linux) At Bcore, our strength comes from how we deliver impact to the... ...Columbia, Maryland. One day per week at customer location in Fairfax County, VA... ...What is ideal? Extensive experience installing, configuring...SeniorLinuxMonday to FridayFlexible hours1 day per week
- ...Description Fortinet Federal Senior Systems Engineer, DoW Overview: The... ...level, self-starter with extensive pre-sales experience,... ...calls and answer/ educate the customer on topics ranging from features... .... Expertise with Linux and various Linux/Unix scripting...SeniorLinux
- ...Senior Storage Engineer Grow, innovate, and generate progress: Harness your expertise... ...COOP) strategies aligned with customer requirements. Install and administer Linux and Windows systems supporting... ...mentoring team members. Extensive experience administering...SeniorLinuxContract workLocal area
- ...We are seeking an experienced SailPoint Senior Engineer to design, implement, and maintain our... ...business requirements Configure and customize workflows, forms, policies, rules, and... ...database concepts Experience with UNIX/Linux and Windows environments Proficiency...SeniorLinuxFull time
- ...Senior Solutions Engineer Are you ready to enhance your skills and build your career in a rapidly... ...essential technological services to our customers in support of their missions to sustain... ...multiple operating systems (Windows, Linux, and MacOS). Deep understanding of...SeniorLinux
- ...Serves as senior engineer and Subject Matter Expert (SME) on technologies deployed in the Data... ...switches, and host connectivity in a Windows/Linux environment. Serves as SME on systems... ...server usage and storage. Administers suites of monitoring tools from vendors like...SeniorLinuxRemote work
$103.8k - $218.1k
...Senior RHEL STIG Engineer CACI is seeking a skilled and experienced Security... ...ideal candidate will have extensive experience in information systems... ...in Red Hat Enterprise Linux (RHEL) environments. The role... ...group dedicated to our customer's missions and driven by a...SeniorLinuxContract workWork experience placementFlexible hours- ...Senior VMware Engineer Introduction Elluminates Software - We Make Your Infrastructure... ...for Federal and commercial customers. Openvista® Suite • Hyperscaler® - AI for... ...Qualifications Red Hat Linux and RHEL Satellite Server Senior...SeniorLinuxFull timeContract workWork at officeLocal areaRelocationShift work
- ...naval forces worldwide. With our extensive portfolio of capabilities,... ...our 'five-eyes' Defense customers with an unbeatable warfighting... ...navies worldwide! Systems Engineer Job Description Ultra Maritime... ...including setup and use of Linux-based system integration, test...SeniorLinuxFor contractorsLocal areaWorldwide
- ...Overview Senior Geospatial Engineer Vienna, VA Are you ready to enhance your skills and build... ...enterprise IT support to Federal customers both CONUS and OCONUS. CARS employs Subject... ...or migration Knowledge of Linux and UNIX environments Familiarity...SeniorLinuxWork at officeRemote workWork from homeHome office
$142.79k - $175.95k
...Cyber Engineer Position Location: USA VA McLean Full Part/Time:... ...Cybersecurity, Endpoint Security, Linux, Splunk Enterprise Security... ...seasoned professional with extensive, hands-on experience navigating... ...in RMF activities and the Senior Cyber Engineer in security operations...SeniorLinuxFull timeContract workTemporary workPart timeRemote workFlexible hours$104k - $166k
...Systems Integration Engineer - Senior Job Locations US-VA-Herndon | US-MD-Bowie... ...such as Visio and Microsoft Office Suite Redhat Linux experience Strong understanding of... ...most daunting challenges facing our customers. Visit peraton.com to learn how we'...SeniorLinuxContract workFor contractorsWork at officeShift work- ...Companies (FOCs) is looking for a Senior Level Vulnerability Patch Management Engineer to support our government customer located in Arlington, VA . This... ...requirements to include but not limited to extensive engineering of Windows and Linux operating systems. Installing,...SeniorLinuxFull time
$113.2k - $237.8k
...Job Title: Senior Systems Engineer Job Category: Engineering Time Type: Full... ...authorities and integrate customer systems into enterprise.... ...) • In-depth knowledge of Linux distributions, including configuration... ...of Windows Active Directory suite to include (DNS, DFS, ADCS,...SeniorLinuxFull timeContract workWork experience placementLocal areaImmediate startFlexible hours$125.3k - $187.9k
.... Principal Cyber Systems Engineer to join our cross functional... ...deploy solutions in support of customer mission needs. Maintain,... ...network. Experience working in Linux environments and capable of... ...issues until resolution Extensive experience working in Linux...SeniorLinuxRelocation packageShift work$159.8k - $216.2k
...and toil through long-term engineering projects. MO is building the... ...looking for highly motivated Senior Linux Systems Engineers who can balance... ...risks before they become customer-impacting issues - Mentor... ...companies trust our robust suite of products and services to...SeniorLinuxFlexible hours- ...Overview Senior System Engineer Vienna, Virginia Are you ready to enhance your skills and... ...enterprise IT support to Federal customers both CONUS and OCONUS. CARS employs Subject... ...experience on Windows and/or Linux ~ Working knowledge of at least one...SeniorLinuxWork at officeWork from homeHome office
$120.8k - $265.8k
...Job Title: Senior Systems Administrator & Database Engineer Job Category: Information Technology Time Type: Full... ...support for both Windows and Linux environments, administers Microsoft... ...performing group dedicated to our customer's missions and driven by a higher...SeniorLinuxFull timeContract workWork experience placementFlexible hours$108k - $175k
...values and dedicated to our customers' mission. Our National... ...T has an opening for a Senior Network Tool Engineer: To support the... ...maintaining software in a Linux (RHEL) environment. Intermediate... ...Assistance Programs (EAP) ~ Extensive employee wellness programs...SeniorLinuxTemporary workWork at officeLocal areaRelocation$191k - $253k
...provider of specialized engineering and products for... ...Intelligence Community (IC) customers. We work within the IC... ...Anduril is seeking a senior engineer with... ...complex issues across Linux-based infrastructure... ...Kubernetes is preferred Extensive experience with SRE principles...SeniorLinuxFull timeWork experience placementImmediate start- ...performance, scalability, extensibility and maintainability... ...systems and seeks customer feedback. Required... ...Customer Account Data Engine 2 (CADE2), Integrated... ...following technologies: Linux (RHEL, etc.), DB2, Assembler... ...Development Lifecycle (SDLC) suite of tools...SeniorLinux
$132.96k - $226.04k
...into intelligence and provides engineering, integration and sustainment... ...In addition they should have extensive experience in the following:... ...Operating Systems: Experience with Linux and/or Windows operating... ...technology solutions and customer support services. Improving the...SeniorLinuxFull timeFor contractorsLocal areaFlexible hours- ...ECS is seeking a Senior Information System... ...between cybersecurity engineering, RMF compliance,... ...and the C-suite. Institute organization... ..., government customers, and regulatory bodies... ...acceptable). # Extensive knowledge and hands... ...Domain and Linux systems architectures...SeniorLinuxFor subcontractorWork at officeRemote work
$229.9k - $262.4k
...Senior Lead Software Engineer, DevOps (Cloud Operations Resilience Engineering) Do you love building... ...to solve real problems and meet real customer needs. We are seeking DevOps Engineers... ...Platform) At least 6 years of Unix or Linux system administration experience...SeniorLinuxFull timePart timeInternshipLocal area- ...Overview Senior CI/CD & Platform Automation Engineer (DevOps) Vienna, VA Are you ready to enhance your... ...integrated enterprise IT support to Federal customers both CONUS and OCONUS. CARS employs... ...to solve it Familiarity with Linux environments and containerized...SeniorLinuxInternshipWork at officeWork from homeHome office
$113.2k - $237.8k
...Job Title: Senior DevOps Engineer - Cloud Infrastructure & Automation Specialist... ...Automation tools such as Linux scripting, Python, and... ...and distributed networks ~ Extensive experience with open-source... ...performing group dedicated to our customer's missions and driven by a...SeniorLinuxFull timeContract workWork experience placementLocal areaFlexible hours- ...ActioNet is looking for a Senior Wireless Engineer to join our team in Vienna,... ...network procedures. ~Has extensive knowledge of routing protocols... ...~Skilled in MS Office Suite, Teams, and SharePoint ~Experience... ...Services. With a 98% customer retention rate, ActioNet is...SeniorFlexible hours
- ...This position is for a Senior Cybersecurity Engineer specializing in Data Scanning. The successful candidate will serve as a technical lead, providing... ..., Problem, and Change Management • Experience with Linux Administration • Experience with container platforms (AKS...SeniorLinuxFull timeWork experience placementCasual workMonday to FridayAfternoon shift
- ...Description: Role Overview The Senior Cybersecurity Engineer is responsible for implementing and... ...~ Hands-on experience with Linux systems and security tooling ~ Knowledge... ...to deliver unparalleled value to our customers and the world. Unleash Voices...SeniorLinuxVisa sponsorshipWork visa
- ...Senior Systems Engineer/DevOps Engineer Duration: 12 months (possible to hire) Location: Fairfax, VA (Hybrid model) Type: W2 only System... ...IT skillset, including experience with AWS Cloud services, Linux and Windows operating systems, server configurations—such as...SeniorLinuxWork experience placementWeekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior AppSec Engineer - Burp Suite, Linux, & Custom Extensions. Be the first to apply!
Related searches
- linux administrator Fairfax, VA
- linux systems administrator Fairfax, VA
- linux engineer Fairfax, VA
- senior linux systems engineer Fairfax, VA
- linux developer Fairfax, VA
- senior vmware engineer Fairfax, VA
- senior performance engineer Fairfax, VA
- senior software design engineer Fairfax, VA
- senior application security engineer Fairfax, VA
- senior tableau developer Fairfax, VA


