×
Register Here to Apply for Jobs or Post Jobs. X

Sr. IT Application Security Engineer; USC

Job in Reston, Fairfax County, Virginia, 22090, USA
Listing for: JobDiva, Inc.
Full Time position
Listed on 2026-10-03
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Systems Engineer
Salary/Wage Range or Industry Benchmark: 150000 - 180000 USD Yearly USD 150000.00 180000.00 YEAR
Job Description & How to Apply Below

Career Developers Inc., a distinguished staffing and consulting firm, is proud to celebrate 30 years of service excellence. As a GSA Contract holder, we offer comprehensive staffing solutions for both commercial and government sectors nationwide. By selectively partnering with clients who share our values, we ensure productive collaborations that set us apart in the industry. Our dedication to candidates involves managing expectations with precision through business intelligence, thorough interview preparation, transparent communication, and exceptional feedback throughout the process.

We are committed to advancing your career and look forward to supporting your professional growth.

Senior IT Application Security Engineer (SME)

Department:
Information Technology

Reports to:

Director, Information Security

Location:

Hybrid/Reston, VA - 3 days on-site in the office per week (Tues/Wed)

Salary: 150-180K + 7% Bonus

Must have the following
  • 6–8 years of Application Security experience designing, implementing, and operating security controls within enterprise application environments.

  • Hands-on BIG-IP WAF administration experience
    , including building WAF policies, configuring protections, tuning rules/policies, troubleshooting issues, reducing false positives, and maintaining WAF controls in a production environment.

  • Hands‑on container image security/scanning experience
    , including reviewing scan results, evaluating vulnerabilities, determining risk and remediation priorities, and working directly with development teams to resolve findings.

  • Experience with a container security/scanning platform.
    The specific tool is not critical
    ; experience with platforms such as Prisma Cloud, Wiz, Snyk, or comparable technologies is relevant.

  • Strong web application security knowledge, including OWASP Top 10 vulnerabilities and practical application of security controls.

  • Experience conducting web application security scans, vulnerability assessments, and/or penetration testing.

  • Experience partnering directly with Development and Dev Ops teams to integrate security into the SDLC and CI/CD pipelines.

  • Experience with authentication and authorization technologies such as OAuth and OpenID
    .

  • Strong troubleshooting and communication skills, with the ability to explain security risks and remediation requirements to both technical teams and senior IT stakeholders.

Responsibilities
  • Administer and enhance enterprise BIG-IP WAF capabilities, including building security policies, tuning rules, investigating false positives, troubleshooting application traffic issues, and maintaining effective web application protections.

  • Design, implement, and operate application security controls across enterprise applications and supporting platforms.

  • Perform container image security scanning and analyze vulnerabilities identified within application and container images.

  • Assess the severity and business risk of container vulnerabilities and partner directly with development teams to prioritize and remediate findings.

  • Work closely with Development and Dev Ops teams to embed security controls into the SDLC and CI/CD pipelines
    .

  • Design and operate web application and API security protections, including policy configuration, rule tuning, automation, and ongoing improvement.

  • Identify application security vulnerabilities, conduct risk assessments, and recommend practical mitigation and remediation strategies.

  • Develop and maintain application security policies, standards, procedures, and controls.

  • Develop security monitoring and telemetry for the application stack to improve proactive detection.

  • Conduct technical investigations related to application security incidents and vulnerabilities.

  • Support container security activities including image scanning, vulnerability risk…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary