Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions: Provides professional and technical services to government entities.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
Marriott InternationalNASDAQ: MAR: Operates and franchises a global network of hotels and resorts.
7+ YOE4+ Mgmt7+ years IT/security experience with 4+ years security leadership, bachelor\u0002s degree or equivalent, experience with AppSec testing (SAST/DAST/IAST), SCA, release management, and GitHub/JIRA/ServiceNow/Jenkins/Harness.
Washington or Cleveland or California or Colorado or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or New Jersey or New York or Vermont or Virginia or Washington
$135k-$279k/yrOnsiteFull Time
Accenture Federal ServicesNYSE: ACN: Provides technology and consulting services to U.S. federal agencies.
12+ YOE12+ years progressive cybersecurity experience with leadership across SOC, incident response, detection, vulnerability management, engineering, and AppSec; enterprise security program experience; US citizenship and clearance eligibility; up to 25% travel.
NIST, RMF, Zero Trust, AWS, Microsoft Azure, GCP, SOAR, AI, ML
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOE3+ years in product/security/appsec roles; experience with architecture/design reviews, threat modeling, secure-by-design principles; ability to obtain Secret clearance; Bachelor's degree required; strong communication and tracking skills.
Applied Intellect: Provides professional, technical, and human services to government agencies.
3+ YOE3+ years in web application or application security, proficiency with .NET/C#, modern web stacks, WAF/FIM, log analysis, DevSecOps automation, and current AppSec/offensive/foundational certifications; bachelor\u0002s degree required.
CMT Services: Provides management and technology consulting to government entities.
3+ YOE3+ years in web application security/AppSec/SSDLC, hands-on secure development, DevSecOps automation, WAF and FIM management, log/SIEM analysis, OWASP Top 10 mitigation, scripting for automation, and compliance with NIST/FedRAMP.
Deloitte: Provides professional audit, consulting, advisory, and tax services.
4+ YOEBachelor's in CS/cyber/IT/engineering/math,local to DMV with ability to work onsite up to 5 days/week,4+ years DevSecOps,4+ years CI/CD (Jenkins/GitLab CI/GitHub Actions/Azure DevOps),3+ cloud/IaC,2+ appsec integration,US work authorization required.
Jenkins, GitLab CI, GitHub Actions, Azure DevOps, Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), Terraform, AWS CloudFormation, Ansible, Docker, Kubernetes, OpenShift, SonarQube, Snyk, Prisma Cloud, Aqua, Python, PowerShell, Bash, Go
Bellevue or Chicago or New York City or San Francisco or Washington
$161k-$248k/yrHybridFull Time
OktaNASDAQ: OKTA: Provide secure identity management and authentication for enterprises.
8+ YOE8+ years in security engineering or backend development, expertise in AI threat landscape, strong coding in Python or Go, cloud (AWS/GCP) experience, and leadership/mentorship ability.
Python, Go, LangChain, Strands, Claude Agent SDK, AWS, GCP, OWASP, MITRE ATLAS, NIST AI RMF
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
2+ YOETS/SCI with polygraph required. Bachelor’s degree plus 2+ years of cyber operations experience (or 6+ years in lieu). Experience with Burp Suite, Metasploit, Cobalt Strike, Mythic, Linux/Unix, web application security, and enterprise network assessment.
5+ YOEBachelor's in CS/Data Science/AI or equivalent,5+ years in AI/ML or software development,5+ years with Docker,Kubernetes,Python and ML libraries,active Top Secret/SCI clearance with polygraph,ability to travel up to 25%.
Docker, Kubernetes, Python, PyTorch, TensorFlow, Hugging Face Transformers, vLLM, NVIDIA Triton, Ollama, Google Vertex AI, Google Cloud Platform (GCP), MITRE ATLAS, OWASP, STRIDE
MetroStar: Provides digital transformation and IT services to government agencies.
10+ YOEActive TS/SCI with CI poly,10+ years DevSecOps experience, expertise in CI/CD, IaC, containerization, AWS, scripting, STIG/SRG compliance, and government classified domains.
Identity and Access Management (IAM) Senior Consultant
Boston or Washington or Denver
$140k-$200k/yrOnsiteFull Time
Bank of AmericaNYSE: BAC: Provides global banking, investing, and financial risk management services.
10+ YOE10+ years in IAM or related disciplines, deep knowledge of cloud IAM (AWS, Microsoft Azure, Google Cloud Platform), generative AI identity risks, comparative technology assessments, security frameworks, and strong stakeholder communication.
AWS, Microsoft Azure, Google Cloud Platform, NIST AI Risk Management Framework, NIST Cybersecurity Framework, MITRE ATLAS, OWASP
Fortreum: Provides cybersecurity compliance and technical auditing services for regulated industries.
3+ YOE3+ years web and network penetration testing, 2+ years professional services, bachelor's degree or 4 years equivalent, proficiency with scripting (bash, python, PowerShell, ruby), and knowledge of security frameworks.
Waltham or Culver City or Richmond or West Valley City or Lexington or Little Rock or Allen or Phoenix or Mesa or Scottsdale or Beltsville or Birmingham or Chicago or Brentwood or Plantation or Schaumburg or Atlanta
$140k-$170k/yrRemoteFull Time
Motorola SolutionsNYSE: MSI: Provides mission-critical communications and public safety technology.
8+ YOEU.S. citizen required. 8+ years cloud infrastructure experience, 5+ years software engineering, 2+ years Kubernetes/Docker. Experience with AWS, Terraform, Helm, MySQL, CI/CD, Git, Linux/Bash, and security/compliance frameworks; ability to obtain required security clearance.
JRAD: Provides technical research and defense support to federal agencies.
0+ YOEBachelor's in CS or related, 0-3 years software development experience, Java/Spring preferred, proficiency with OOP, data structures, REST/microservices, databases, containerization, Agile, and security standards; able to pass DHS suitability screening.
Java, C#, C++, ASP.Net, Python, JavaScript, Spring MVC, Spring Boot, SSO, Scala, Http4s, ETL, Node.js, React, Angular, Vue.js, PostgreSQL, MySQL, MongoDB, RESTful APIs, microservices, Docker, Kubernetes, Git, Github, JIRA, SAFe, AWS, Microsoft Azure, Google Cloud Platform, Jenkins, GitLab CI/CD, GitHub Actions, JUnit, PyTest, Jest, OWASP, Section 508, NIST
ICFNASDAQ: ICFI: Provides strategic consulting and technology services to global organizations.
2+ YOEActive Top Secret clearance, 2+ years application security or secure software development experience, secure code review and vulnerability assessment experience, knowledge of cloud (AWS) security and federal/DoD requirements.