Application Security Engineer
Listed on 2026-09-25
-
IT/Tech
Cybersecurity
Join a culture of empowerment and connectivity.
Develop your craftLearn the skills you need to accelerate your career.
Discover benefits that support your life and work.
Innovate with intentionBuild mission-ready tech that protects the nation.
Integrate security practices throughout the sof tware development lifecycle to enhance and maintain the security posture of sof tware. Apply advanced consult ing skills and extensive technical expertise, including full industry knowledge. Develop innovative solutions to complex problems. Work without considerable direction and mentor and supervise team members.
You Have:5+ years of experience in cybersecurity, application security, product security, or sof tware engineering
Experience implementing or assessing Secure SDLC and application security programs, leading client e nga gements, managing multiple priorities, and performing architecture reviews, threat modeling, or security assessments
Experience with sof tware supply chain security concepts, including SBOMs, dependency management, code signing, artifact integrity, and secure build pipelines
Experience implementing or evaluating application security tools such as SAST, DAST, SCA, IaC scanning, container security, API security, secrets detection, and sof tware composition analysis
Experience with Agile, Scrum, and Dev Sec Ops operating models in large-scale sof tware development environments
Knowledge of secure sof tware development principles, modern application architectures, and modern sof tware architectures, including cloud-native, microservices, APIs, containers, Kubernetes, and serverless environments
Knowledge of authentication, authorization, cryptography, API security, and cloud security
Knowledge of vulnerability management processes, risk prioritization met hodologies, and remediation workflows
Ability to translate complex technical risks into executive-level briefings, business cases, and actionable roadmaps and communicate effectively with technical and executive stakeholders
Bachelor's degree in CS, Cybersecurity, Information Systems, or Engineering
Nice If You Have:Experience designing or maturing enterprise application security and product security programs
Experience with secure development requirements for regulated industries, including healthcare, finan cia l services, industrial control systems, automotive, aerospace, or critical infrastructure
Experience applying industry frameworks such as OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO / IEC 42001, IEC 62443, and MITRE ATT & CK or ATLAS
Experience developing technical proposals, responding to RFPs, creating Statements of Work ( SOWs ) , and supporting business development initiatives
Experience leading executive workshops, stakeholder interviews, and technical design sessions
Ability to mentor junior team members, provide technical leadership, and contribute to practice development and thought leadership
Ability to travel up to 50% of the time, depending on client needs
Possession of excellent written and verbal communication skills
Possession of excellent facilitation skills
Master's degree in Cybersecurity, CS, Sof tware Engineering, Information Assurance, or a related technical field
CompensationAt Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).