Application Security Engineer
Core
Application Security Engineer supporting assessment, vulnerability management, DevSecOps enablement, and secure reference implementation for USCIS systems.
Role type
Senior IC Application Security Engineer
Builds
Secure reference implementations, utility applications, and DevSecOps automation workflows
Domain
Federal Government / Cybersecurity / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Application security testing, vulnerability management, secure coding guidance, SAST/DAST/SCA/container scanning, CI/CD integration, proof-of-concept development, security framework knowledge (Zero Trust, NIST, CISA, CIS, OWASP)
Preferred skills
SonarQube/Nexus IQ/Checkmarx/Twistlock analysis, CVE/CVSS analysis, Java/Spring Boot/Node.js/Python/Ruby/.NET development, Kubernetes security, Splunk/New Relic monitoring, Harness CI/CD platform experience
Technologies
SonarQube, Nexus IQ, Checkmarx, Twistlock, Java, Spring Boot, Node.js, Python, Ruby, .NET, Kubernetes, Splunk, New Relic, Harness
Responsibilities
Perform application security testing and vulnerability assessments; Support automated security scanning of applications, APIs, services, containers, and CI/CD pipelines; Document, track, and validate vulnerabilities; Provide technical guidance to development teams on secure coding and remediation; Support DevSecOps tool integration and automation; Develop proof-of-concept secure reference implementations and utility applications; Monitor compliance with application security standards and frameworks
Seniority
Senior, hands-on IC