International Monetary Fund: Provides loans and policy advice to stabilize global economies.
4+ YOE4+ years application security and vulnerability management experience (or 10+ with a bachelor), knowledge of OWASP/NIST/ISO frameworks, hands-on SAST/DAST/SCA, scripting (Java, Python, .NET, PowerShell), and stakeholder communication.
ServiceNow, Microsoft Azure, Microsoft Azure DevOps, Microsoft Power BI, Burp Suite, Sonatype Nexus Lifecycle, Checkmarx, Fortify, HCL AppScan, Veracode, Java, Python, .NET, PowerShell, SAST, DAST, SCA
Marriott InternationalNASDAQ: MAR: Operates and franchises a global network of hotels and resorts.
7+ YOE4+ Mgmt7+ years IT/security experience with 4+ years security leadership, bachelor\u0002s degree or equivalent, experience with AppSec testing (SAST/DAST/IAST), SCA, release management, and GitHub/JIRA/ServiceNow/Jenkins/Harness.
Denver or Washington or Seattle or Charlotte or Jacksonville or Jersey City or Chicago
$160k-$205k/yrOnsiteFull Time
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
5+ YOE5+ years pentesting/application security experience, ability to perform manual web and mobile assessments, develop PoCs, conduct code reviews, use DAST/SAST, and strong programming/debugging and threat analysis skills.
DAST, SAST, Frida, UNIX, LINUX, TCP/IP, Web APIs, SBOM, CVE, CWE, Port Swigger, LLM security
Eccalon: High-tech cybersecurity and AI solutions for government and industry.
3+ YOEBachelor's or equivalent experience, 3+ years software engineering with security focus; proficiency in JavaScript/TypeScript, Python, Go, or C#; experience with SAST/DAST, secure coding, NIST/CMMC/FedRAMP, and AWS/Azure security services.
JavaScript, TypeScript, Python, Go, C#, CI/CD, SAST, DAST, OWASP Top 10, DoD STIGs, IAM, Cognito, Microsoft Azure AD, SSO, SAML, OIDC, Security Hub, Microsoft Defender, Microsoft Sentinel, WAF, IaC, Docker, ECS, Prisma, Checkov, Snyk, Aqua, AWS, AWS GovCloud (US), Azure GCC High
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
10+ YOE5+ Mgmt10+ years in application development and software security,5+ years leading technical teams,experience across SDLC,DAST/SAST/IAST/SCA,CI/CD and AI scanning (Mythos),knowledge of OWASP/NIST,Bachelor's degree.
DAST, SAST, IAST, SCA, CI/CD, Mythos, OWASP, NIST, Frontier AI
CACINYSE: CACI: Provides information technology and professional services to government clients.
5+ YOEBachelor's degree, active TS/SCI, 5+ years cyber engineering (2+ with modern software), Kubernetes security, IaC/PaaS/DevSecOps experience, Ansible and scripting, SIEM/SAST/DAST/SCA familiarity, network protocol knowledge.
Annapolis Junction or New York City or Annapolis or Washington
$125k-$233k/yrOnsiteFull Time
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
10+ YOE5+ Mgmt10+ years in application development and software security,5+ years leading application security teams,experience with SDLC,threat modeling,DAST/SAST/IAST/SCA,CI/CD,AI scanning,knowledge of OWASP/NIST,Bachelor's degree.
ASM ResearchNYSE: ACN: Provides IT and healthcare services to government agencies.
7+ YOEBachelor's or equivalent,7+ years cybersecurity engineering experience,expertise with NIST SP 800-53 and RMF,CI/CD security, SAST/DAST,SIEM,Zero Trust,incident response;U.S. citizenship and ability to obtain Secret clearance required.
SAICNASDAQ: SAIC: Provides government and defense clients with technology and engineering services.
7+ YOEExpertise in SecDevOps, CI/CD security (SAST/DAST/SCA), scripting (Python/Bash/PowerShell), full-stack development, cloud (AWS/Azure/GCP), systems engineering, Linux/Windows server, and security hardening; ability to lead projects and mentor others.
Birmingham or Bentonville or Phoenix or Tempe or Irvine or Los Angeles or Sacramento or San Diego or San Francisco or Santa Clara or Boulder or Denver or Hartford or Stamford or Washington or Fort Lauderdale or Jacksonville or Miami or Orlando or Tallahassee or Tampa or Atlanta or Des Moines or Boise or Chicago or Indianapolis or Louisville or Baton Rouge or New Orleans or Shreveport or Boston or Baltimore or Detroit or Minneapolis or Kansas City or St Louis or Jackson or Charlotte or Raleigh or Winston-Salem or Lincoln or Omaha or Montvale or Short Hills or Albuquerque or Las Vegas or Albany or Buffalo or Melville or New York or Rochester or Cincinnati or Cleveland or Columbus or Oklahoma City or Portland or Harrisburg or Philadelphia or Pittsburgh or Providence or Greenville or Knoxville or Memphis or Nashville or Austin or Dallas or Fort Worth or Houston or San Antonio or Salt Lake City or Ashburn or McLean or Richmond or Seattle or Milwaukee or Virginia Beach or El Segundo
$90k-$168k/yrOnsiteFull Time
KPMG: Global professional services network providing audit, tax, and advisory.
4+ YOE4+ years application security/DevSecOps experience, familiarity with CI/CD, SAST/DAST, cloud (preferably Azure), programming in Java/C#/JavaScript/Python/SQL, strong threat modeling and risk assessment skills, and U.S. work authorization without sponsorship.
West 4th Strategy: Provides technology and professional services to federal government agencies.
Experienced DevSecOps engineer to build and secure AWS cloud infrastructure, implement IaC, automate CI/CD with GitHub Actions, integrate SAST/DAST/SCA tooling, perform container scanning, and coach developers; U.S. citizenship and public trust eligibility required.
Virtru: Provides data-centric encryption and privacy control software for organizations.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
Cooley: Global law firm providing legal services to high-growth industries.
4+ YOE4+ years building and operating cloud infrastructure and CI/CD pipelines; strong Terraform (AWS, Azure), GitHub Actions, SAST/DAST, APM/Datadog, SOC 2 change management familiarity; proficiency with Microsoft Office and iManage; ability to work extended hours and travel as required.
Application Security Engineer — Secure Mission Systems
United States or Laurel
RemoteFull Time
Rackner: Builds cloud-native software and AI systems for government agencies.
6+ YOE6+ years in SAST/DAST and vulnerability remediation, bachelor’s in cybersecurity, experience with application-security testing, secure SDLC, and working with development teams to remediate findings.