Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions: Provides professional and technical services to government entities.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
Marriott InternationalNASDAQ: MAR: Operates and franchises a global network of hotels and resorts.
7+ YOE4+ Mgmt7+ years IT/security experience with 4+ years security leadership, bachelor\u0002s degree or equivalent, experience with AppSec testing (SAST/DAST/IAST), SCA, release management, and GitHub/JIRA/ServiceNow/Jenkins/Harness.
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOE3+ years in product/security/appsec roles; experience with architecture/design reviews, threat modeling, secure-by-design principles; ability to obtain Secret clearance; Bachelor's degree required; strong communication and tracking skills.
Washington or Cleveland or California or Colorado or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or New Jersey or New York or Vermont or Virginia or Washington
$135k-$279k/yrOnsiteFull Time
Accenture Federal ServicesNYSE: ACN: Provides technology and consulting services to U.S. federal agencies.
12+ YOE12+ years progressive cybersecurity experience with leadership across SOC, incident response, detection, vulnerability management, engineering, and AppSec; enterprise security program experience; US citizenship and clearance eligibility; up to 25% travel.
NIST, RMF, Zero Trust, AWS, Microsoft Azure, GCP, SOAR, AI, ML
CMT Services: Provides management and technology consulting to government entities.
3+ YOE3+ years in web application security/AppSec/SSDLC, hands-on secure development, DevSecOps automation, WAF and FIM management, log/SIEM analysis, OWASP Top 10 mitigation, scripting for automation, and compliance with NIST/FedRAMP.
Deloitte: Provides professional audit, consulting, advisory, and tax services.
4+ YOEBachelor's in CS/cyber/IT/engineering/math,local to DMV with ability to work onsite up to 5 days/week,4+ years DevSecOps,4+ years CI/CD (Jenkins/GitLab CI/GitHub Actions/Azure DevOps),3+ cloud/IaC,2+ appsec integration,US work authorization required.
Jenkins, GitLab CI, GitHub Actions, Azure DevOps, Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), Terraform, AWS CloudFormation, Ansible, Docker, Kubernetes, OpenShift, SonarQube, Snyk, Prisma Cloud, Aqua, Python, PowerShell, Bash, Go
Revolutional: Delivers advanced technology and mission support to federal agencies.
5+ YOEBachelor's or equivalent,5+ years penetration testing with federal experience,CISA AES required or in process,active Secret clearance,FedRAMP pen testing experience,ability to travel to agency sites.
Waltham or Culver City or Richmond or West Valley City or Lexington or Little Rock or Allen or Phoenix or Mesa or Scottsdale or Beltsville or Birmingham or Chicago or Brentwood or Plantation or Schaumburg or Atlanta
$140k-$170k/yrRemoteFull Time
Motorola SolutionsNYSE: MSI: Provides mission-critical communications and public safety technology.
8+ YOEU.S. citizen required. 8+ years cloud infrastructure experience, 5+ years software engineering, 2+ years Kubernetes/Docker. Experience with AWS, Terraform, Helm, MySQL, CI/CD, Git, Linux/Bash, and security/compliance frameworks; ability to obtain required security clearance.
BizFlow: Provides low-code software for business process management and automation.
10+ YOE10+ years backend development with strong Java and SQL, experience building REST/SOAP integrations, mentoring developers, troubleshooting across application/database/server layers, and familiarity with enterprise systems.
Java (Java 11+), Spring Framework, Spring Boot, Hibernate/JPA, Querydsl, Spring Integration, Apache Camel, BizFlow M, BizFlow AppDev, Oracle, Microsoft SQL Server, RESTful APIs, SOAP Web Services, gRPC, JSON, XML, SAML, OAuth 2.0, JWT, mTLS, OWASP, Tomcat, WildFly/JBoss, Docker, AWS, Git, GitHub, Jira, Confluence, Microsoft SharePoint, Postman, Jenkins, GitHub Actions
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
3+ YOERequires Secret clearance, high school diploma/GED with 9+ years, bachelor's with 5+ years, master's with 3+ years, or doctorate in vulnerability assessment, plus DoD IAT Level II certification such as CompTIA Security+.
ICFNASDAQ: ICFI: Provides strategic consulting and technology services to global organizations.
5+ YOEActive Top Secret clearance and 5+ years in application security, secure software development, or cybersecurity engineering; AWS cloud experience, secure code review, vulnerability assessment, and a technical bachelor's degree preferred.
AWS, AWS GovCloud, SAST, DAST, SCA, OWASP, NIST, DoD STIGs
Hewlett Packard EnterpriseNYSE: HPE: Providing global edge-to-cloud infrastructure and IT solutions for businesses.
3+ YOEBachelor's in CS/Engineering/hard sciences (Master's/PhD preferred), deep AI and data-security experience, 3+ years development experience, extensive security architecture experience with US federal/state compliance frameworks.
Software Engineer - Mid to Experienced Level (Maryland)
Fort Meade, Maryland, United States
$105k-$193k/yrOnsiteFull Time
National Security Agency: US agency providing foreign signals intelligence and cybersecurity.
3+ YOEComputer Science or Software Engineering degree with foundational CS coursework and relevant software development experience; requirements vary from 0 to 8 years by education and work level. Top Secret clearance required.
COBOL, C, C++, Java, Angular, React, Python, PIG Analytics, Pyspark, Docker, Kubernetes, Amazon Web Services (AWS), Linux, VMWare, ElasticSearch, Rust, Ansible, GitLab, NIST, ISO 27001, OWASP, TLS/SSL, Security Information and Event Management (SIEM), intrusion detection systems (IDS), hardware security modules (HSMs)
Ashburn Consulting: Provides network engineering and cybersecurity services for government agencies.
10+ YOEU.S. citizen; willing to work as W-2; DHS EOD/suitability; 10+ years in application security, DevSecOps, zero trust; experience with APT testing tools; cloud and on-prem security; AWS; Terraform/Kubernetes; security governance and compliance; strong writing and mentoring.
Noblis: Nonprofit science, technology, and strategy firm supporting government missions.
10+ YOERequires U.S. citizenship, TS/SCI clearance with CI polygraph, BS plus 12 years or master's plus 10 years of relevant experience, cybersecurity expertise, programming, malware analysis, vulnerability research, and penetration testing.
Electronic Medical Records (EMR), Microsoft Excel, AWS, Azure, Google Cloud, AES, RSA, Python, C, C++, Java, Assembly, Metasploit, Burp Suite, Kali Linux, SQL injection, Cross-Site Scripting (XSS), Buffer Overflow, NIST, OWASP, CIS Controls, ISO 27001
Birmingham or Bentonville or Phoenix or Tempe or Irvine or Los Angeles or Sacramento or San Diego or San Francisco or Santa Clara or Boulder or Denver or Hartford or Stamford or Washington or Fort Lauderdale or Jacksonville or Miami or Orlando or Tallahassee or Tampa or Atlanta or Des Moines or Boise or Chicago or Indianapolis or Louisville or Baton Rouge or New Orleans or Shreveport or Boston or Baltimore or Detroit or Minneapolis or Kansas City or St Louis or Jackson or Charlotte or Raleigh or Winston-Salem or Lincoln or Omaha or Montvale or Short Hills or Albuquerque or Las Vegas or Albany or Buffalo or Melville or New York or Rochester or Cincinnati or Cleveland or Columbus or Oklahoma City or Portland or Harrisburg or Philadelphia or Pittsburgh or Providence or Greenville or Knoxville or Memphis or Nashville or Austin or Dallas or Fort Worth or Houston or San Antonio or Salt Lake City or Ashburn or McLean or Richmond or Seattle or Milwaukee or Virginia Beach or El Segundo
$90k-$168k/yrOnsiteFull Time
KPMG: Global professional services network providing audit, tax, and advisory.
4+ YOE4+ years application security/DevSecOps experience, familiarity with CI/CD, SAST/DAST, cloud (preferably Azure), programming in Java/C#/JavaScript/Python/SQL, strong threat modeling and risk assessment skills, and U.S. work authorization without sponsorship.
Identity and Access Management (IAM) Senior Consultant
Boston or Washington or Denver
$140k-$200k/yrOnsiteFull Time
Bank of AmericaNYSE: BAC: Provides global banking, investing, and financial risk management services.
10+ YOE10+ years in IAM or related disciplines, deep knowledge of cloud IAM (AWS, Microsoft Azure, Google Cloud Platform), generative AI identity risks, comparative technology assessments, security frameworks, and strong stakeholder communication.
AWS, Microsoft Azure, Google Cloud Platform, NIST AI Risk Management Framework, NIST Cybersecurity Framework, MITRE ATLAS, OWASP