Virtru: Provides data-centric encryption and privacy control software for organizations.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
Annapolis Junction or New York City or Annapolis or Washington
$125k-$233k/yrOnsiteFull Time
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
10+ YOE5+ Mgmt10+ years in application development and software security,5+ years leading application security teams,experience with SDLC,threat modeling,DAST/SAST/IAST/SCA,CI/CD,AI scanning,knowledge of OWASP/NIST,Bachelor's degree.
WalmartNYSE: WMT: Multinational retail operating discount stores and supermarkets.
4+ YOE4+ years application security experience with Bachelor's or 6+ years without; expertise in secure architecture, threat modeling, SAST/SCA, OWASP, automation of security validation, and strong communication skills.
Cvent: Cloud-based software for event and venue management.
5+ YOE5+ years in application security or secure software development; strong scripting in Python, JavaScript/TypeScript, or Bash; CI/CD and SDLC security integration; cloud (AWS preferred) and tool familiarity; end-to-end ownership experience.
Accenture Federal ServicesNYSE: ACN: Provides technology and consulting services to U.S. federal agencies.
7+ YOE7+ years SAP application security experience, role/authorization design, GRC tools, SAP IS-U knowledge, identity/access governance, security operations, US citizenship and eligibility for government clearance.
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions: Provides professional and technical services to government entities.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
Birmingham or Bentonville or Phoenix or Tempe or Irvine or Los Angeles or Sacramento or San Diego or San Francisco or Santa Clara or Boulder or Denver or Hartford or Stamford or Washington or Fort Lauderdale or Jacksonville or Miami or Orlando or Tallahassee or Tampa or Atlanta or Des Moines or Boise or Chicago or Indianapolis or Louisville or Baton Rouge or New Orleans or Shreveport or Boston or Baltimore or Detroit or Minneapolis or Kansas City or St Louis or Jackson or Charlotte or Raleigh or Winston-Salem or Lincoln or Omaha or Montvale or Short Hills or Albuquerque or Las Vegas or Albany or Buffalo or Melville or New York or Rochester or Cincinnati or Cleveland or Columbus or Oklahoma City or Portland or Harrisburg or Philadelphia or Pittsburgh or Providence or Greenville or Knoxville or Memphis or Nashville or Austin or Dallas or Fort Worth or Houston or San Antonio or Salt Lake City or Ashburn or McLean or Richmond or Seattle or Milwaukee or Virginia Beach or El Segundo
$90k-$168k/yrOnsiteFull Time
KPMG: Global professional services network providing audit, tax, and advisory.
4+ YOE4+ years application security/DevSecOps experience, familiarity with CI/CD, SAST/DAST, cloud (preferably Azure), programming in Java/C#/JavaScript/Python/SQL, strong threat modeling and risk assessment skills, and U.S. work authorization without sponsorship.
Chicago or California or Colorado or Florida or Georgia or Illinois or Indiana or Minnesota or Missouri or Montana or New Jersey or New York or North Carolina or Ohio or Oregon or Pennsylvania or South Carolina or Texas or Utah or Vermont or Virginia or Washington or Washington or Wisconsin
$210k-$260k/yrHybridFull Time
NinjaTrader: Provides futures brokerage services and a trading software platform.
7+ YOE7+ years in application/product/security engineering; hands-on threat modeling, vulnerability management, secure design, CI/CD integration, automation using Python/Go; experience with cloud-native AWS/GCP environments.
Atlanta or Tampa or Charlotte or Austin or Chicago or Washington or Dallas or Los Angeles or Boston or Florham Park or New York or San Francisco or California or Philadelphia or Houston
$99k-$232k/yrOnsiteFull Time
PwC: Providing audit, tax, and management consulting services to businesses.
4+ YOEBachelor's degree, 4+ years of experience, strong Workday application security and compliance skills, analytical thinking, leadership and mentoring experience; SAP experience noted as a specialism.
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
5+ YOERequires 5+ years experience managing cloud/security applications, knowledge of Azure/AWS/GCP, DevOps/CI-CD/IaC, ServiceNow, Jira/Confluence, strong communication and compliance skills.
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME (VIRTUALIZATION AND APPLICATION DEVELOPMENT SME)
Arlington or Springfield
HybridFull Time
Zermount: Provider of cybersecurity and IT solutions to government agencies.
10+ YOE10+ years in application security, cloud security, or DevSecOps with Zero Trust experience; hands-on ZT policy design and enforcement in cloud environments; strong NIST/OMB/OEA/EO-based standards.
Azure, AWS, GCP, Kubernetes, Docker, API security, CI/CD, NIST SP 800-53 SA, NIST SP 800-53 SI, NIST SP 800-53 CM, NIST SP 800-207, EO 14028
3SI Security Systems: Provides GPS tracking and surveillance for asset protection.
4+ YOE4+ years VMS/PSIM experience, team leadership, networking and video streaming expertise, Microsoft SQL Server/SQL skills, active U.S. Secret clearance, and ability to travel up to 50% OCONUS.
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME (VIRTUALIZATION AND APPLICATION DEVELOPMENT SME)
Arlington or Springfield
HybridFull Time
Zermount: Provides cybersecurity and IT consulting services to government agencies.
10+ YOE10+ years in application/cloud/DevSecOps security with Zero Trust experience, Secret clearance, CISSP or CCSP, expertise with CISA ZTMM v2.0 and NIST standards, cloud platforms (Azure/AWS/GCP), API security, Kubernetes, and CI/CD.
Anduril Industries: Defense technology building autonomous military hardware and software.
5+ YOE5+ years progressive technical security experience, active SECRET clearance, knowledge of ICD-705/IC Tech Spec, commissioning IDS/ACS, proficiency with accreditation and AO interaction, strong communication and problem solving.
SAP Application Security Lead - U.S. Citizenship Required
Fairfax or Lafayette or Lebanon or Knoxville
$101k-$246k/yrHybridFull Time
CGINYSE: GIB: Provides information technology and business consulting services.
9+ YOE5+ MgmtU.S. citizen required. Minimum 9 years SAP security experience and 5 years leading IT programs; experience with SAP security architecture, GRC, BTP, role-based authorization; strong communication and analytical skills.
SAP S/4HANA, S/4HANA Private Cloud, RISE, SAP GRC, SAP BTP, Microsoft Excel, Microsoft Project, Microsoft PowerPoint
Electrosoft Services: Federal cybersecurity, digital engineering, and IT solutions provider
9+ YOE2+ MgmtBachelor's degree, 9+ years in application architecture or related fields, 2+ years supervising technical teams, U.S. citizenship and ability to obtain security clearance, experience with cloud, APIs, SDLC, and application modernization.
Microsoft Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), DevSecOps, CI/CD, TOGAF, FEAF, Zachman, Zero Trust, Identity and Access Management (IAM)