Security Engineer
Fredericksburg, Stafford County, Virginia, 22407, USA
Listed on 2026-10-02
-
Software Development
You want more out of a career. A place to share your ideas freely - even if they're daring or different. Where the true you can learn, grow, and thrive. At Verizon, we power and empower how people live, work and play by connecting them to what brings them joy. We do what we love - driving innovation, creativity, and impact in the world.
Our V Team is a community of people who anticipate, lead, and believe that listening is where learning begins. In crisis and in celebration, we come together - lifting our communities and building trust in how we show up, everywhere & always. Want in? Join the #VTeamLife.
Our Dynamic Application Security Testing (DAST) team is a group of talented, creative thinkers who 'act like the enemy.' We focus on ensuring our web applications, mobile applications, and APIs are secure by performing ethical hacking and penetration testing on Verizon's internal and external defenses.
In this role, you will operate at the intersection of cybersecurity and automation. You won't just find vulnerabilities; you will build, maintain, and support the suite of tools and automated processes that empower our application teams to independently scan for, identify, and remediate OWASP Top 10 vulnerabilities. Additionally, you will leverage your offensive security skills to support Verizon's critical incident response and bug bounty programs.
Responsibilities include:
Integrating dynamic analysis tools (OWASP ZAP, Burp Suite) directly into Jenkins and Git Lab CI/CD pipelines to ensure continuous security testing.
Writing and maintaining custom automation scripts using Python, Java, and Bash to scale our security efforts and eliminate manual bottlenecks.
Utilizing AI to build new testing capabilities, streamline the triage of bug bounty submissions, and troubleshoot code across our tech stack.
Deploying, hosting, and maintaining containerized security testing environments using Docker and AWS.
Partnering with engineering teams to guide them through identifying and remediating OWASP Top 10 vulnerabilities.
Leveraging your offensive expertise to triage incoming bug bounty submissions and support Verizon's critical incident response efforts.
Performing ethical hacking and penetration testing against web applications, mobile apps, and APIs to uncover vulnerabilities before malicious actors do.
You'll need to have:
Bachelor's degree or one or more years of work experience.
Even better if you have one or more of the following :
2+ years of hands‑on experience in Application Security, Penetration Testing, or a Dev Sec Ops engineering role.
Deep understanding of web application architecture, APIs (REST/GraphQL), and mobile application security.
Comprehensive knowledge of the OWASP Top 10, CWEs, CVSS scoring, and how to manually validate and exploit these vulnerabilities.
Proficiency operating and configuring industry-standard dynamic analysis tools, specifically Burp Suite Professional and OWASP ZAP.
Proven experience integrating security tools into modern CI/CD pipelines using Jenkins and Git Lab CI.
Strong ability to read, write, and maintain automation scripts in Python and Bash.
Hands‑on experience working with Docker containers and deploying/ managing applications in AWS (experience with EC2s/Linux is a plus).
Ability to clearly explain complex security vulnerabilities (and why remediating them is important) to software engineers who may not have a security background.
Experience using AI assistants (ideally Gemini or Claude Code) for scripting, debugging code, or day to day productivity improvements.
In this remote role, you'll work from home with occasional in-person trainings and meetings.
Scheduled Weekly Hours40
Eq…(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).