Concept Plus
Posted 6d ago

Application Security Engineer (Full Scope Poly)

Concept Plus
Reston, Virginia, United States
OnsiteFull Time
Responsibilities
  • integrating security
  • assessing vulnerabilities
  • securing applications
Requirements
  • Requires U.S. citizenship
  • TS/SCI clearance with polygraph
  • 8+ years in application security or related fields
  • Bachelor's degree
  • Secure SDLC and cloud-native experience, and proficiency with listed security technologies and standards
Technical tools mentioned
Oracle CloudPythonJavaScriptSQLShellPL/SQLSASTDASTSCAKubernetesDockerREST APIsCI/CDOracle Cloud Infrastructure (OCI)NIST RMFNIST Secure Software Development FrameworkOWASPDISA STIGsOracle RDBMSAgile

Job description

About the role

Concept Plus is seeking a highly experienced and motivated Application Security Engineer for an exciting new contract. This role is fully onsite in Reston, VA (5 days per week required).

What you'll do

This role will be part of a team of Data, Cloud, and Security engineers delivering a cloud-native, centralized platform that provides end-to-end budget traceability. The Application Security Engineer will integrate security throughout the software development lifecycle, partnering with developers and cloud engineers to design, build, assess, and sustain secure mission applications.


Required Qualifications

  • US Citizen
  • Must possess a TS/SCI security clearance with Polygraph.
  • Technical expertise and hands-on experience in application security, secure software development, software engineering, or DevSecOps, with the ability to apply these skills to Oracle Cloud and customer mission challenges.
  • Experience integrating security throughout the software development lifecycle, including secure design and architecture reviews, threat modeling, secure code review, security testing, vulnerability remediation, and release authorization support.
  • Experience developing or reviewing applications using Python, JavaScript frameworks, SQL, Shell scripting, PL/SQL, and other programming languages, with a strong understanding of common application vulnerabilities and secure coding practices.
  • Experience with application security testing tools and processes, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and container or infrastructure vulnerability scanning.
  • Experience building and securing cloud-native applications and services using Kubernetes, containers, Docker, REST APIs, and CI/CD pipelines.
  • Experience implementing DevSecOps practices, including automated security controls and testing within build and deployment pipelines.
  • Experience with cloud-native security services and controls; Oracle Cloud Infrastructure (OCI) experience is desired.
  • Knowledge of security frameworks and standards such as NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, and applicable federal security requirements.
  • Experience securing Oracle RDBMS environments, including database access controls, encryption, auditing, and secure handling of sensitive data.
  • Ability to assess, prioritize, document, and communicate application and cloud security risks, findings, and remediation recommendations to both technical and non-technical stakeholders.
  • Passion for technology, curiosity, and willingness to continuously learn new security tools, techniques, and approaches for solving complex technical challenges.
  • Experience working in an Agile framework.
  • 8+ years of relevant experience in application security, software engineering, DevSecOps, cybersecurity, or a related technical discipline.
  • Bachelor’s Degree in engineering, computer science or related technical discipline. Master’s degree preferred.


Preferred Qualifications

  • Oracle Cloud Infrastructure (OCI) IaaS and/or PaaS certifications are preferred.
  • Security certifications such as CISSP, CSSLP, Security+, GIAC, CEH, OSCP, or comparable credentials.
  • Experience implementing identity and access management, privileged access controls, secrets management, encryption, logging, monitoring, and incident response capabilities in cloud environments.
  • Experience with AI technologies for software development and securing AI-enabled applications or development workflows.
  • Data engineering experience, including securing data validations, business rules, data transformations, and sensitive-data handling.

Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.


About Concept Plus

Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm.


Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty.


We offer competitive pay, comprehensive health, dental, and vision insurance, paid life insurance, paid time off, 11 paid holidays, performance bonuses, tuition reimbursement, unlimited training, and the opportunity to thrive in a collaborative, flexible, and innovative environment.


For more information, visit www.conceptplus.com.


About Concept Plus

Delivers enterprise IT services for federal government agencies.

Year founded
2008

Similar jobs

Application Security Engineer roles near Reston, Virginia
5d
Save
Mark Applied
Hide
Application Security Engineer
Annapolis Junction, Maryland, United States
$87k-$198k/yr RemoteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
5+ YOERequires 5+ years in cybersecurity, application or product security, or software engineering; Secure SDLC, security tools, cloud architectures, frameworks, communication, and a relevant bachelor's degree.
Secure SDLC, SBOM, SAST, DAST, SCA, IaC, Kubernetes, OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, MITRE ATT&CK, MITRE ATLAS, Artificial Intelligence
6d
Save
Mark Applied
Hide
Application Security Engineer
Annapolis Junction or Bethesda
$87k-$198k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
5+ YOERequires 5+ years in cybersecurity, application security, product security, or software engineering; Secure SDLC, application security tools, cloud-native architectures, risk management, and client leadership experience; bachelor's degree.
Microsoft Internet Explorer, Google Chrome, Mozilla Firefox, Microsoft Edge, Apple Safari, Opera Browser, Blackberry Browser, SAST, DAST, SCA, IaC, API, Agile, Scrum, DevSecOps, Kubernetes, SBOM, OWASP SAMM, BSIMM, NIST SSDF, NIST CSF, NIST AI RMF, ISO 27001, ISO/IEC 42001, IEC 62443, MITRE ATT&CK, ATLAS
1w
Save
Mark Applied
Hide
Application Security Engineer
Tysons, Virginia, United States
$115k-$145k/yr HybridFull Time
Veilant
Veilant: Protecting operations, personnel, and data from emerging surveillance threats.
2+ YOERequires 2+ years of Java development, application security testing, source-code review, web security, CI/CD, containers, cloud platforms, and strong technical communication; must be able to obtain security clearance.
Java, Java Spring Boot, Angular, REST APIs, SQL, PostgreSQL, JWT, OAuth, Entra, Keycloak, GitLab CI, Azure DevOps, GitHub Actions, Kubernetes, Trivy, Kubesec, Azure, AWS, GitLab Secrets Manager, AWS KMS, Azure Key Vault, Ansible Vault, SAST, DAST, SCA, Falco, NeuVector, Burp Suite, CI/CD, IaC
1w
Save
Mark Applied
Hide
Application Security Engineer I
Arlington, Virginia, United States
$90k-$110k/yr OnsiteFull Time
Bloomberg Industry Group
Bloomberg Industry Group: Provides legal, tax, and government intelligence and news services.
1+ YOEAssociate's degree in information security, computer science, or a related field, or equivalent experience; 1–2 years of relevant experience; programming knowledge and application security testing exposure.
Python, Java, JavaScript, GitLab, GitHub Actions, Jenkins, AWS, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), CI/CD
2w
Save
Mark Applied
Hide
Senior Engineer, Application Security
Tysons Corner, Virginia, United States
$120k-$160k/yr HybridFull Time
Cvent
Cvent: Cloud-based software for event and venue management.
5+ YOE5+ years in application security or secure software development; strong scripting in Python, JavaScript/TypeScript, or Bash; CI/CD and SDLC security integration; cloud (AWS preferred) and tool familiarity; end-to-end ownership experience.
Python, JavaScript, TypeScript, Bash, AWS, GCP, Azure, AWS CDK, Burp Suite, Checkmarx, Mend, Veracode, Fortify, ZAP, Wiz, CI/CD, SAST, DAST, SCA
3w
Save
Mark Applied
Hide
Application Security Engineer — Secure Mission Systems
United States or Laurel
RemoteFull Time
Rackner
Rackner: Builds cloud-native software and AI systems for government agencies.
6+ YOE6+ years in SAST/DAST and vulnerability remediation, bachelor’s in cybersecurity, experience with application-security testing, secure SDLC, and working with development teams to remediate findings.
Fortify, X-Ray, OWASP ZAP, GitLab, Artifactory, OpenShift, Kubernetes, WebAssembly (WASM)
1mo
Save
Mark Applied
Hide
(USA) Staff, Application Security Engineer
Bentonville or Herndon
$110k-$264k/yr OnsiteFull Time
Walmart
WalmartNYSE: WMT: Multinational retail operating discount stores and supermarkets.
4+ YOEBachelor's degree plus 4 years in application security, or 6 years of application security experience. Preferred security certifications and project leadership experience.
AI, CI/CD, IDE, CLI, PR bots, WCAG 2.2 AA
1mo
Save
Mark Applied
Hide
(USA) Staff, Application Security Engineer
Bentonville or Herndon
$110k-$220k/yr OnsiteFull Time
Walmart
WalmartNYSE: WMT: Operates a chain of hypermarkets, discount stores, and grocery stores.
4+ YOEBachelor's degree plus 4 years in application security, or 6 years' application security experience. Preferred security certifications, master's degree, and cybersecurity project leadership experience.
Machine Learning, Artificial Intelligence, IDE, CLI, PR bots, SDLC, CI/CD, WCAG 2.2 AA