Information Technology Security Specialist
Listed on 2026-09-12
-
IT/Tech
Cybersecurity
Position Title: IT Security Specialist (Application Security & Cloud Security)
Location: Remote (United States) — Supporting Rosslyn, VA
Clearance Requirements: Public Trust / Moderate Background Investigation (Must be eligible)
Secret clearance preferred
Position Status: Contract
Pay Rate: Competitive — Based on experience
Position DescriptionWe are seeking a highly skilled IT Security Specialist to support a Federal Government customer in securing enterprise applications, cloud environments, and critical information systems. This role focuses heavily on application security engineering
, secure SDLC
, and cloud security
, serving as a technical authority for cybersecurity design, implementation, and operations.
The ideal candidate brings hands‑on expertise in SAST/DAST
, manual code review
, CI/CD security integration
, and Microsoft Azure security services
, along with a strong understanding of FISMA and NIST frameworks
. This position offers the opportunity to work remotely while supporting mission‑critical federal systems.
- Lead application security efforts across enterprise systems, including SAST, DAST, and manual source code reviews
- Design, implement, and manage enterprise‑wide Application Security programs
- Integrate security testing into CI/CD pipelines
- Develop security architectures and technical solutions for cloud‑hosted applications
- Evaluate and implement security controls for Azure and Microsoft 365 environments
- Monitor, detect, and respond to security incidents and vulnerabilities
- Conduct cyber threat, risk, and vulnerability assessments
- Administer and maintain security tools, including patching, upgrades, and integrations
- Develop security metrics, dashboards, and compliance reporting
- Participate as a member of the Incident Response Team
- Support operational implementation of FISMA, NIST, and OMB cybersecurity requirements
- Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, and Continuous Monitoring Plans
- Conduct security audits, assessments, and system reviews
- Ensure compliance with federal cybersecurity policies and standards
- Partner with IT, engineering, and business teams to implement secure solutions
- Provide expert cybersecurity guidance to technical and non‑technical stakeholders
- Manage IT security awareness and training initiatives
- Support security‑related service requests and ticket resolution to meet SLAs
- Hands‑on experience with SAST and DAST tools such as Fortify, Checkmarx, Veracode, App Scan, Snyk, Web Inspect
- Experience with manual code review and secure coding best practices
- Strong background in application vulnerability assessments using tools such as Burp Suite, OWASP ZAP, Kali Linux, Metasploit, Accunetix
- Experience securing CI/CD pipelines and implementing Dev Sec Ops practices
- Proficiency in one or more programming languages:
Java, .NET, Python, PHP, C++, C# - Experience with Azure Security Center, Sentinel, Defender, Intune, Azure WAF, MFA, PIM
- Knowledge of cloud and mobile security controls
- Strong knowledge of FISMA, NIST (800‑53, 800‑37), and federal cybersecurity regulations
- Experience with federal security documentation and audits
- Bachelor’s degree in Cybersecurity, Information Technology, or related field
- 5+ years of hands‑on experience in application security and secure SDLC
- Advanced degree preferred
- CSSLP, CCSP, OSCP, CASE, GWEB
- Microsoft Certified Azure Security Engineer Associate
- Microsoft 365 Certified Security Administrator Associate
At Seneca Resources, we are more than just a staffing and consulting firm, we are a trusted career…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).