Federal Vulnerability Mgmt & App Security Engineer (US Citizen)
$125kPSI Services
Description Title: Vulnerability Mgmt. and Application Security Engineer Location: Remote-US Salary: $125K annually About PSI We are PSI Services. We power world leading tests. Delivered with trusted science and the very best test taker experience. PSI supports test-takers on their journey to pursuing dreams and gaining certifications that are important to them. They believe that their dreams are worth working for; that their dreams are worth the effort. And we believe that too. This is our core purpose, to empower people to achieve their dreams. We do this by being the best provider of workforce solutions, which foster both technology and science to deliver the best solutions for our test takers. We are searching for top talent to join our PSI team and help grow our products and services. We have a creative, supportive and inclusive culture where we empower people in their careers to be their authentic self and make the most of their great talent. At PSI, we are committed to helping people meet their potential and we believe that promoting diversity, equity and inclusion is critical to our success. That's why you'll find these ideals are intrinsic to our company culture and applied throughout the employee lifecycle. Learn more about what we do at: The Threat, Vulnerability & Application Security Analyst is a dual-focus security practitioner responsible for identifying, assessing, and reducing risk across infrastructure, cloud, and application environments. This role combines enterprise threat and vulnerability management with hands-on application security oversight across the software development lifecycle (SDLC). The analyst correlates threat intelligence, asset inventory, vulnerability data, and application risk to inform security priorities, guide remediation, and continuously improve the organization's security posture. A core responsibility is partnering closely with engineering, platform, and product teams to embed security earlier in development, reduce exploitable risk, and ensure compliance with internal security standards and external regulatory requirements. This role emphasizes automation, scalability, and pragmatism-driving measurable risk reduction through tooling, process improvements, and actionable security guidance. Success requires persistence, strong technical depth across AppSec and vulnerability domains, and the ability to translate risk into clear, prioritized actions for technical and non-technical stakeholders. Role Responsibilities Drive continuous improvements in vulnerability management processes and tools by?leveraging?industry-leading technologies, automation, and data-driven insights.? Stay current on industry trends, emerging threats and best practices in vulnerability management and?adapt?the program accordingly.? Evaluate and recommend vulnerability management tools and technologies, ensuring the?optimal?balance of effectiveness and efficiency.? Develop and deliver regular metrics, reports, KPIs and presentations to executive leadership and key stakeholders, communicating the status and effectiveness of the vulnerability management program.? Assist?in building a diverse vulnerability management program that covers secure software development lifecycle, patch governance, and application security.? Perform technical threat/risk and vulnerability assessments and manage vulnerabilities throughout their lifecycle.? Provide support and?maintain?tools?required?for the vulnerability management program.? Provide consultative support to operational teams on how to fix identified vulnerabilities. Own and evolve the Application Security program, integrating findings into the broader vulnerability management lifecycle. Perform and oversee application security assessments, including static (SAST), dynamic (DAST), software composition analysis (SCA), and manual secure code reviews where appropriate. Partner with development and DevOps teams to embed security into the SDLC, including CI/CD pipeline integrations and secure design reviews. Define and maintain application risk prioritization that considers exploitability, business impact, data sensitivity, and threat context. Review application architectures and threat models to proactively identify design-level security weaknesses. Establish and maintain secure coding standards aligned to OWASP Top 10 and industry best practices. Triage, validate, and manage application vulnerabilities through remediation and verification. Enable developer success through consultative AppSec support, clear remediation guidance, and security-by-design recommendations. Knowledge, Skills and Experience Requirements Core Security & Risk Strong understanding of information security risk measurement (qualitative and quantitative) to support effective prioritization. Working knowledge of industry security frameworks and standards (e.g., NIST CSF/800-53, ISO 27001, OWASP). Ability to correlate threat intelligence with vulnerability and application risk. Application Security (New / Expanded) Solid understanding of secure application development , including common programming languages, frameworks, and architectural patterns. Hands-on experience with Application Security testing methodologies , including: Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) Software Composition Analysis (SCA) Familiarity with OWASP Top 10 , API Security Top 10, and common application attack patterns. Experience integrating security scanning tools into CI/CD pipelines . Ability to perform threat modeling and design-level security assessments. Strong understanding of authentication, authorization, session management, and data protection controls within applications. Vulnerability & Threat Management Expertise in vulnerability management programs, including lifecycle management and remediation governance. Experience with vulnerability scanning and reporting tools (e.g., Qualys, Tenable, CrowdStrike, or equivalent). Familiarity with cyber threat intelligence services and the application of threat data to prioritization decisions. Broad technical knowledge of networks, operating systems, cloud platforms, and web applications Education and Experience 3+ years of combined experience in cybersecurity, application security, or vulnerability management. Prior experience working closely with software engineering or DevOps teams is strongly preferred. Ability to pass an IRS Clearance and Background Check REQUIRED Benefits & Culture Retirement Benefits: 401(k), pension, or country-specific retirement plans with employer contributions Generous Time Off: Enhanced paid time off/annual leave policies Health & Wellbeing Coverage: Medical insurance tailored to your region, plus: US: Dental, vision, life, and short-term disability insurance UK: Medical cashback plan including dental, vision, and income protection Flexible Spending Accounts (US) Employee Assistance Program (EAP): Confidential support whenever you need it Work-Life Balance: We understand life happens outside of work, and we fully support flexibility Wellness Culture: Regular global wellness initiatives to help you stay healthy and inspired Future Planning: Tools and support to help you grow personally and professionally Giving Back: Enjoy a Volunteer Day each year and opportunities to support our communities and industry Alongside a competitive salary, we offer a comprehensive benefits package designed to support your well-being, your future, and your sense of purpose. ? At PSI, we're more than just a workplace - we're a global team driven by shared values and real impact. If you're ready to be part of a company that's committed to your growth and well-being, we'd love to hear from you. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights ( notice from the Department of Labor. PSI Services
$110k - $115k
...with a team to discover vulnerabilities in increasingly... ...Embedded Systems Reverse Engineer/Vulnerability... ...develop unique embedded security solutions for government... ...internally Must be a US Citizen with the ability and... ...protected under applicable Federal, state, or local law....ResidentWork experience placementWork at officeLocal areaRemote workFlexible hours- ...a highly experienced Security Engineer to provide Security Control... ...Monitoring (CM), and vulnerability management activities... ...Security clearance. US Citizenship. A... ...the areas of Defense, Citizen Services, and... ...military, numerous U.S. Federal civilian agencies, the...ResidentFull timeContract workPart timeLocal areaFlexible hours
- Security Engineer III The security of a global financial institution depends on the strength of... ...and the millions of people who depend on us — protected. This is your opportunity... ...Cybersecurity & Technology Controls, Runtime Vulnerability Assessment team, you serve as a...Suggested
$144.2k - $288.4k
...quality in everything we do. Join us and be part of something... ...the Principal Application Security Engineer - Threat Research, you will... ...data. Lead security testing, vulnerability analysis, and documentation.... ...in accordance with all federal, state and local laws. CVS...SuggestedHourly payFull timeTemporary workLocal areaImmediate startRemote work$110k - $140k
...science, electrical engineering, and mathematics to develop... ...unique embedded security solutions for government... ...system threats and vulnerabilities, and develop security... ...ATT&CKMust be a US Citizen with the ability to obtain... ...under applicable Federal, state, or local law....ResidentWork experience placementWork at officeLocal areaRemote workFlexible hours$100k - $150k
...Job Title: Cloud Security Engineer - Oracle Location:... ...Sponsorship: U.S. Citizens, Green Card Holders,... ...OCI Identity Domains, federation with corporate IdPs,... ...user analysis. Lead vulnerability management programs,... ...bvteck.com or contact us at (***) ***-****. Learn...ResidentFull timeH1bLocal areaImmediate startRemote workVisa sponsorship$129.1k
...SUMMARY CANDIDATE MUST BE US Citizen (due to contractual/... ...Principal Information Security Architect - Data... ...environments, distributed query engines, and enterprise data... ..., identity & access mgmt., threat mgmt., etc.)... ...to applicable federal and state laws, rules,...ResidentFor contractorsWork at officeLocal areaRemote work- Battelle is looking for a Reverse Engineering/Vulnerability Research Intern for Spring Semester 2027 in Columbus, OH. This crucial role... ...demonstrate strong programming skills along with the ability to obtain a US government security clearance. #J-18808-Ljbffr BattelleInternship
$100k - $150k
...+ years Sponsorship: U.S. Citizens, Green Card Holders, EAD Holders... ...testing, and mentor junior engineers. Required Qualifications... ...to ****@*****.*** or contact us at (***) ***-****. Learn more... ...status as defined by applicable federal, state, or local laws. This commitment...ResidentFull timeH1bLocal areaImmediate startRemote workVisa sponsorship- Vulnerability Management Analyst (OS/Infrastructure) Columbus, OH Information Technology Company... ..., assessing, and remediating security risks across enterprise networks, operating... ...Clearance Requirements: Must be a U.S. citizen Must possess a current Top-Secret clearance...Resident
- ...and CRM counselling, Product Engineering, Business Intelligence, Data Management... ...and e-commerce. USM, a US ensured Minority Business... ...Description OPT EAD, GC EAD, GC, TN and Citizens Only Position: Service Now... ...) 4) Strong IT Service Mgmt Experience (Helpful) Additional...ResidentWorldwide
$70 - $79 per hour
...Job Title: Senior Security Engineer – Web Application & Network Protection (Contract to Hire... ...W-2 Only Work Authorization: U.S. Citizens Only | Green Card holders also eligible... ...Threat hunting Security assessments Vulnerability remediation Root cause analysis...ResidentContract workLocal areaRemote workVisa sponsorshipMonday to Friday- Lead Information Security Engineer Anywhere Type: Contract Category: Security... ...improve an LLM-based code vulnerability detection and reporting... ...supervision. Eligible to work in the US without sponsorship now or... ...other category protected by federal, state, or local laws. Don'...Hourly payContract workLocal areaRemote workShift workNight shiftRotating shift
$77 - $88 per hour
...Security Solution Architect Location: Columbus,... ...Authorization: U.S. Citizens Only | Green Card holders... ..., threat and vulnerability management, governance... ...and local, state, and federal agencies during incident... ...in Computer Science, Engineering, Information Technology...ResidentContract workWork experience placementLocal areaRemote workVisa sponsorshipMonday to Friday$105.79k - $141.05k
...ecosystem. We enable secure, high‑performance connectivity... ...connectivity, join us today. Location... ...Information Security Engineer owns the development,... ...ensuring compliance with federal requirements and... ...drive remediation of vulnerabilities, audit findings, and control...Full timeTemporary workRemote work$93.75k - $133.2k
The Federal Bureau of Investigation (FBI) seeks candidates to become special agents who will protect national security by analyzing data, identifying patterns, and leading investigations... ...SCI clearance. Applicants must be US citizens with a bachelor’s degree or J.D. #J...ResidentWork at office- ...seeking an aspiring Junior Vulnerability Researchers to work... ...Science, Computer Engineering, Electrical... ...protocols Must Be a US Citizen with the ability and... ...analysis Active DoD Secret security clearance Benefits:... ...protected under applicable Federal, state, or local law....ResidentWork at officeLocal areaRemote workFlexible hours
- ...remarkable Software Development Engineer to join us! We've built a team of not... ...cloud software (platform + apps + ecosystem) to accelerate... ...government data into the hands of citizens, developers, businesses and... ...empower local, state, and federal government entities to...ResidentLocal areaVisa sponsorship
- ...seeking an Early Career Vulnerability Researcher in the... ...Computer Science, Computer Engineering, Electrical... ...fuzzers Must be a sole US citizen with the ability maintain a US government security clearance Preferred... ...protected under applicable Federal, state, or local law....ResidentWork at officeLocal areaRemote workFlexible hours
$19.61 - $39.62 per hour
...science, technology, engineering and business operations... ..., healthier and more secure world. Job Summary... ...Reverse Engineering/Vulnerability Research Intern for the... ...Must be a sole US citizen with the ability to obtain... ...protected under applicable Federal, state, or local law....ResidentHourly payInternshipWork at officeLocal areaRemote workRelocationFlexible hours- ...Network Security Engineer Anywhere Type: Consulting Category: Development Industry:... ...ensure that you are working directly with us by confirming the following: · When... ...employees, or any other category protected by federal, state, or local laws. Don't miss out...Hourly payLocal areaRemote workWeekend workAfternoon shift
- ...possible. As a Lead Software Engineer at JPMorganChase within the... ...technology products in a secure, stable, and scalable way. You... ...modeling, secure code review, vulnerability remediation, and secure configuration... ...#CTC ~#CTC About Us JPMorganChase, one of the...
$99k - $225k
Application Security EngineerThe Opportunity: Everyone is trying to “harness the cloud”, but... ...teammates at your fingertips. Join us. The world can’t wait. You Have: 4+ years... ..., web-based UI, SSH, and CLIKnowledge of federal compliance standards, including NIST 800-...Full timeContract workPart timeWork at officeLocal areaRemote work- ...Columbus, OH office is seeking a Junior Embedded Systems Reverse Engineer/Vulnerability Researcher to join the Cyber research team. You will work... ...across disciplines to push the cutting edge of embedded security for government and industry clients. #J-18808-Ljbffr...Work at office
$63.8k - $169.3k
...process definition, process improvement and re-engineering. Minimum 2+ years' experience... ...disability or religious observance, please call us toll free at (***) ***-**** or send us... ...or any other basis as protected by federal, state, or local law.?Our rich diversity...ResidentWork experience placementLive inLocal area$40k
Maximus is a trusted federal partner supporting mission-critical programs across national security, defense, and public service delivery... ...scale. The Junior Security Engineer supports 24x7 enterprise... ...assisting with containment, vulnerability management, and compliance activities...Contract workRemote work$86.4k
...Identity & Access Management Security Engineer participates in the development... ...of our Single Sign-On (SSO)/Federation engineering team, focusing on... .... · Knowledge of Microsoft Apps and Suites, Windows server, SharePoint... ...If you would like to contact us regarding the accessibility...For contractorsWork at officeLocal areaRemote work$126k - $188k
...applications and services by identifying security risks early, partnering closely with product and engineering teams, and guiding practical... ...community including new vulnerabilities, methodologies, and products.... ...our own technologies to help us find and attract top talent...Work experience placementLocal areaRemote work- Senior C#.Net Developer Location: Columbus, OH (2 Days Onsite) Position Type: Contract US Citizen, Green Card, TN, GC EAD and H4 EAD only No Third-party agencies corp to corp. Job Description: Technically Strong on .NET programming languages (7-8 yrs) C#.Net, ASP.Net,...ResidentContract work
$104k - $156k
...Job Overview The Advanced IAM Engineer is a technically deep, hands... ...the Manager of Enterprise Security and cross-functional teams,... ...access paths. Implement SSO, federation, and authentication... ...Security Operations, Threat Modeling, Vulnerability Management RelativityRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Federal Vulnerability Mgmt & App Security Engineer (US Citizen). Be the first to apply!
- software applications developer Columbus, OH
- hydraulic application engineer Columbus, OH
- application system engineer Columbus, OH
- junior application support engineer Columbus, OH
- application engineer Columbus, OH
- app developer Columbus, OH
- application performance engineer Columbus, OH
- network applications engineer Columbus, OH
- project application engineer Columbus, OH
- senior application developer Columbus, OH



