Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Security Engineer

$140k - $160k

Edgewater Federal Solutions

Overview

Edgewater is currently seeking an Application Security Engineer who will be a hands-on subject matter expert in Microsoft Azure cloud technologies, application security, security architectures, security tools, and methodologies. The Application Security Engineer will support our federal customer in Washington DC. This is a hands-on technical role that will provide the right candidate with an exciting opportunity to develop the federal customer's application security program, working with developers and the organization to meet the strategic security goals of the agency.


This is a remote position but requires the candidate to work at the federal site in Washington DC at least two days a month so candidates local to the Washington, DC area strongly preferred.

Due to the contract and nature of the work, US Citizenship is required to obtain a Department of Energy security clearance.

Responsibilities

  • Drive the strategic maturation of the agency's Application Security (AppSec) program by defining security standards, scaling automation, and embedding secure development practices across all product lifecycles.
  • Perform SAST assessments using Veracode and GitHub Advanced Security, identifying code-level vulnerabilities and providing remediation guidance.
  • Conduct and analyze DAST scans, including configuration, execution, and triage of results.
  • Evaluate and prioritize vulnerabilities using industry frameworks such as CVSS, CWE, OWASP Top 10, WASC, and SANS Top 25.
  • Collaborate with development, DevOps, and security teams to integrate security controls into CI/CD pipelines and the broader SDLC.
  • Provide expert advice on secure coding principles and assist developers in resolving security findings.
  • Troubleshoot application and connectivity issues in Linux-based environments.
  • Contributes to the design and implementation of enterprise-wide application security controls.
  • Ensure alignment with federal security and compliance standards, including NIST 800-53, FIPS, and FedRAMP.
  • Maintain awareness of emerging threats, vulnerabilities, and best practices in application security.
Qualifications
  • Experience supporting SAST/DAST environments using Veracode.
  • Experience with SCA tools and vulnerability remediation
  • Experience leveraging CI/CD deployment methodologies and infrastructure as code (IaC)
  • Experience writing playbooks and scripts for automation tools including Terraform, Ansible for IaC
  • Demonstrate proficiency with a scripting or coding language, preferably Python.
  • Proficiency in automation and scripting, such as PowerShell, Python, Bash, and Terraform.
  • Ability to discuss Information Security concepts such as defense in depth and zero trust.
  • Demonstrate ability to communicate ideas both verbally and in writing to management, business and IT stakeholders, and technical resources in language that is appropriate for each group.
  • Ability to work collaboratively with developers across multiple departments
  • Ability to work effectively in a fast-paced, project-oriented environment
  • Ability to analyze and prioritize vulnerabilities based on risk
  • Strong technical acumen, communication, and influence skills
  • Working knowledge of system hardening (CIS, STIGs regulatory compliance)
  • Experience working with and supporting Unix/Linux and Windows systems.
  • Experience with SCA tools and vulnerability remediation in containers
  • Container orchestration and container security experience
  • 3+ years in application security supporting SAST, DAST, and SCA environments
  • 3+ years of experience designing and implementing application security controls
  • 3+ years of experience working in Linux-based environments, including troubleshooting application and connectivity issues.
  • Knowledge of federal security and compliance standards (NIST 800-53, FIPS, FedRAMP).
Preferred Qualifications:
  • Experience in securing Azure cloud infrastructure (i.e., inspection, logging, WAF, VM)
  • Experience with Azure DevOps
  • Practical implementation and architectural experience in encryption techniques, including data at rest and in transit
  • Prior experience as a software developer is highly preferred
Requirements:
  • Bachelor's degree in computer science or related fields
  • Minimum of 8 years of experience in Information Security or related fields
  • CISSP or equivalent (CompTIA Security+, CEH, or DoD equivalent)
Preferred Certifications:
  • ISC2 Certified Information Systems Security Professional (CISSP)
  • ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
  • GIAC Web Application Penetration Tester (GWAPT)
  • Microsoft Azure Security Engineer (AZ-500)
  • HashiCorp Terraform Associate (Infrastructure as Code)

Salary: $140,000 - $160,000

About Us:

Edgewater Federal Solutions is a privately held government contracting firm located in Frederick, MD. The company was founded in 2002 with the vision of being highly recognized and admired for supporting customer missions through employee empowerment, exceptional services and timely delivery. Edgewater Federal Solutions is ISO 9001, 20000-1, 270001 certified, appraised at CMMI Level 3 Maturity for Development and Services, and has been named in the Top Workplaces in the Greater Washington Area Small Companies for 2018 through 2025.

It has been and continues to be the policy of Edgewater Federal Solutions to provide equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, marital status, veteran status, and/or other statuses protected by applicable law.status protected by applicable law.
Vacancy posted 14 hours ago
Similar jobs that could be interesting for youBased on the Application Security Engineer in Washington DC vacancy
  • $40 per hour

     ...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback...  ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some... 
    Suggested
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Washington DC
    2 days ago
  • Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation...  ...innovative security tools and a team of dedicated security engineers to protect our products throughout their lifecycle. Job... 
    Suggested

    Bloomberg Industry Group

    Arlington, VA
    3 days ago
  •  ...AI Systems Security Specialist Client added a crucial skill that they are seeking expertise in here is securing AI systems...  ...AWS cloud security architecture and services Cloud application security engineering Docker and Kubernetes security Infrastructure as Code... 
    Suggested

    RIT Solutions

    Washington DC
    4 days ago
  •  ...Community Service and Employee Engagement events are atop our calendar events! MBL Technologies is seeking an experienced Application Security Engineer to support the security and integrity of enterprise applications within a federal environment. This role will focus on... 
    Suggested
    Full time
    Remote work

    MBL Technologies

    Washington DC
    3 days ago
  • $62k - $141k

     ...Application Security Engineer The Opportunity: Work together with the client and application community to maintain a resilient security posture for highly visible applications. Remediate application security flaws in conjunction with the application security team... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Washington DC
    2 days ago
  •  ...VA Contract What You'll Do: Collaborate with a team of engineers to implement *** specific security policies in the CI/CD security tools including but not limited to SAST, DAST and SCA applications. Work with Development, DevOps and Security teams to... 
    Contract work
    Work experience placement

    US Tech Solutions

    Arlington, VA
    2 days ago
  •  ...Application Security Engineer Comtech is a woman-owned small business founded in 1998 and headquartered in Reston, VA. We offer IT solutions across the disciplines of program/project management, applications development, infrastructure, Cyber security, and enterprise... 

    Comtech LLC

    Washington DC
    4 days ago
  • SourcePro Search is conducting a search for an experienced Senior Application Security Engineer in Washington, DC. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This... 

    SourcePro Search

    Washington DC
    2 days ago
  • $110k

    Job Description We seek a highly motivated and experienced Application Security Engineer to join our growing security team. This role is highly technical and candidates must possess a solid understanding of the security and privacy of our company's applications and data... 
    Full time

    Ryder System, Inc.

    Washington DC
    2 days ago
  •  ...the lifecycle of supply chain risk, bringing speed and clarity to enterprise response. Job Overview: The Application Security Engineer will secure Interos.ai's AWS cloud environments, containerized workloads, application stack, CI/CD pipelines, and... 

    RIT Solutions, Inc.

    Washington DC
    4 days ago
  • Ernst & Young Oman is hiring an Application Security Engineer in Arlington, Virginia. The role involves managing application development platforms and optimizing security tools while ensuring operational efficiency through automation. Ideal candidates should have a relevant... 
    Flexible hours

    Ernst & Young Oman

    Arlington, VA
    5 days ago
  • Ernst & Young Oman seeks an Application Security Engineer to enhance security tools and manage development platforms. You will collaborate with teams to integrate security processes and automate deployments while ensuring optimal security measures throughout the software... 

    Ernst & Young Oman

    Washington DC
    5 days ago
  • A leading security solutions firm is seeking a Senior Application Security Engineer in Washington, DC. The ideal candidate will integrate secure design in application development and collaborate on security solutions. They should have extensive experience in cybersecurity... 

    SourcePro Search

    Washington DC
    2 days ago
  • $166k - $200k

     ...in months, not years. ABOUT THE TEAM The Technical Security (TechSec) team within Anduril's Corporate Security Program is...  ...landscape. ABOUT THE JOB The Senior Technical Security Application Engineer, Secured Spaces , is the technical authority for the design... 
    Full time
    Contract work
    Work experience placement
    Immediate start

    Anduril Industries

    Washington DC
    3 days ago
  • $100k - $155k

    Overview As an Application Security Engineer , you will provide technical expertise and solutions to remediate persistent and challenging portfolio-wide vulnerabilities. We’re looking for someone who has passion for IT, resourceful problem‑solving abilities, and a desire... 

    Steampunk

    Mc Lean, VA
    3 days ago
  • $100k - $155k

    Steampunk is seeking an Application Security Engineer in McLean, Virginia. This role involves providing expertise to remediate vulnerabilities and uphold security practices across enterprise applications. Ideal candidates need to have experience in application security... 

    Steampunk

    Mc Lean, VA
    2 days ago
  • $77.5k - $140.9k

     ...diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. As an Application Security Engineer, you will be responsible for implementing and managing application development platforms and optimizing security tools to... 
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Washington DC
    5 days ago
  • $120k - $140k

     ...Application Security Engineer Location: Fully Remote (East Coast) Clearance: Public Trust, Secret Clearance preferred Employment Type: Full-time Salary: $120,000-$140,000 Role Overview : The Application Security Engineer will support the secure development... 
    Full time
    Remote work

    TOMORROW HIRE

    Washington DC
    17 days ago
  • SourcePro Search is seeking a Mid-Level Application Engineer - Cyber Security Analytics Engineer in Washington, DC. The ideal candidate will develop and manage software tools to support Enterprise Management, focusing on software specifications, program design, and documentation... 

    SourcePro Search

    Washington DC
    5 days ago
  • We are conducting a search for a Mid‑Level Application Engineer - Cyber Security Analytics Engineer. We are seeking an ideal candidate who can develop and manage software tools to support Enterprise Management. This role involves formulating and defining specifications... 

    SourcePro Search

    Washington DC
    5 days ago
  • $105k - $130k

     ...government and nonprofit organizations and individuals. Applications Engineer The Applications Engineer is a highly skilled technical position...  ...project work with minimal supervision, ensuring stable, secure, and scalable application solutions aligned with business... 
    Temporary work
    Work at office
    Remote work

    Katten Muchin Rosenman LLP

    Washington DC
    2 days ago
  • $140k - $165k

     ...Senior Product Security Engineer Uplight is creating a new category of energy. We make software that manages energy resources in homes...  ...bring to Uplight: Advanced experience in securing applications and application settings Advanced experience in app and... 
    Local area
    Flexible hours
    Shift work

    upLIGHT

    Washington DC
    4 days ago
  • $130k - $150k

     ...the ultimate goal of enabling human life on Mars. PRODUCT SECURITY ENGINEER (STARSHIELD) Starshield leverages SpaceX’s Starlink...  ...immediately necessary upon hire, we encourage you to initiate the application process promptly upon accepting this offer. Your ability to... 
    Permanent employment
    Temporary work
    Immediate start
    Flexible hours
    Weekend work

    SpaceX

    Washington DC
    1 day ago
  •  ...Product Security Engineer Gecko Robotics is helping the world's most important organizations ensure the availability, reliability, and...  ...We are building the Product Security team to build and scale application security at Gecko. As a Product Security Engineer you will play... 
    Work at office
    Local area
    Work from home
    Flexible hours

    Gecko Robotics Inc

    Washington DC
    4 days ago
  • $118.72k - $190.04k

     ...Fortune 500 companies. The Red Hat Product Security Compliance team is seeking a knowledgeable and proactive Product Security Engineer to achieve our security and compliance...  ...not limited to job location, experience, applicable skills and training, external market... 
    Permanent employment
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work
    Work from home
    Worldwide
    Flexible hours

    Red Hat

    Washington DC
    5 days ago
  •  ...Title: Senior Application Developer/Engineer/Programmer Location: Washington, DC Job Description The Senior Information Systems Specialist provides advanced support for enterprise information systems, including analysis, integration, and administration... 

    Apex Informatics

    Washington DC
    3 days ago
  • $108.6k - $181k

     ...Job Description Summary About the Role: We're seeking a highly skilled and experienced Senior Application Engineer with a strong background in technical solution design, system integration, and precise cost estimation for large-scale EPC (Engineering, Procurement... 
    Contract work
    Remote work
    Relocation package

    GE Vernova

    Washington DC
    2 days ago
  •  ...Senior OCI Application Engineer (Level III) Tharseo IT is seeking a senior OCI Application Engineer (Level III) to support a federal program...  ...connectivity issues that may involve network security group (NSG) rules and related controls. Supervise software... 
    For subcontractor
    Remote work

    InstantServe LLC

    Washington DC
    3 days ago
  •  ...Overview VetsEZ is seeking a HealthShare Application Engineer (Remote Opportunity) to join our remote team. The engineer should have experience and knowledge to design, code, test, debug, and document software in a variety of programming languages. The candidate must... 
    Remote work

    Antler Ltd

    Washington DC
    1 day ago
  •  ...Job Description: Senior Application Developer / Engineer / Programmer Position Title: Senior Application Developer / Engineer / Programmer...  ...candidates will play a critical role in designing, developing, securing, and maintaining enterprise-grade applications in AWS... 

    Diverse Agile Solutions LLC

    Washington DC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!