WalmartNYSE: WMT: Multinational retail operating discount stores and supermarkets.
4+ YOE4+ years application security experience with Bachelor's or 6+ years without; expertise in secure architecture, threat modeling, SAST/SCA, OWASP, automation of security validation, and strong communication skills.
WalmartNYSE: WMT: Operates a chain of hypermarkets, discount stores, and grocery stores.
4+ YOEBachelor's degree plus 4 years of application security experience, or 6 years of related experience. Expertise in secure architecture, threat modeling, security testing, SAST, SCA, and compliance controls.
SAST, SCA, OWASP, Web Content Accessibility Guidelines (WCAG), Microsoft Excel
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
10+ YOE10+ years automating infrastructure, configuration management, and CI/CD; experience with cloud (AWS/Azure), containers, Kubernetes, SAST/SCA integration, active TS/SCI clearance, and a STEM bachelor's degree.
Eccalon: High-tech cybersecurity and AI solutions for government and industry.
3+ YOE3+ years software engineering with security focus, proficiency in one or more languages (JavaScript/TypeScript, Python, Go, C#), secure coding, SAST/DAST, familiarity with NIST/CMMC/FedRAMP and AWS/Azure security.
Marriott InternationalNASDAQ: MAR: Operates and franchises a global network of hotels and resorts.
7+ YOE4+ Mgmt7+ years IT/security experience with 4+ years security leadership, bachelor\u0002s degree or equivalent, experience with AppSec testing (SAST/DAST/IAST), SCA, release management, and GitHub/JIRA/ServiceNow/Jenkins/Harness.
Denver or Washington or Seattle or Charlotte or Jacksonville or Jersey City or Chicago
$160k-$205k/yrOnsiteFull Time
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
5+ YOE5+ years pentesting/application security experience, ability to perform manual web and mobile assessments, develop PoCs, conduct code reviews, use DAST/SAST, and strong programming/debugging and threat analysis skills.
DAST, SAST, Frida, UNIX, LINUX, TCP/IP, Web APIs, SBOM, CVE, CWE, Port Swigger, LLM security
CACINYSE: CACI: Provides information technology and professional services to government clients.
5+ YOEBachelor's degree, active TS/SCI, 5+ years cyber engineering (2+ with modern software), Kubernetes security, IaC/PaaS/DevSecOps experience, Ansible and scripting, SIEM/SAST/DAST/SCA familiarity, network protocol knowledge.
Annapolis Junction or New York City or Annapolis or Washington
$125k-$233k/yrOnsiteFull Time
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
10+ YOE5+ Mgmt10+ years in application development and software security,5+ years leading application security teams,experience with SDLC,threat modeling,DAST/SAST/IAST/SCA,CI/CD,AI scanning,knowledge of OWASP/NIST,Bachelor's degree.
ASM ResearchNYSE: ACN: Provides IT and healthcare services to government agencies.
7+ YOEBachelor's or equivalent,7+ years cybersecurity engineering experience,expertise with NIST SP 800-53 and RMF,CI/CD security, SAST/DAST,SIEM,Zero Trust,incident response;U.S. citizenship and ability to obtain Secret clearance required.
Virtru: Provides data-centric encryption and privacy control software for organizations.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
SAICNASDAQ: SAIC: Provides government and defense clients with technology and engineering services.
7+ YOEExpertise in SecDevOps, CI/CD security (SAST/DAST/SCA), scripting (Python/Bash/PowerShell), full-stack development, cloud (AWS/Azure/GCP), systems engineering, Linux/Windows server, and security hardening; ability to lead projects and mentor others.
Birmingham or Bentonville or Phoenix or Tempe or Irvine or Los Angeles or Sacramento or San Diego or San Francisco or Santa Clara or Boulder or Denver or Hartford or Stamford or Washington or Fort Lauderdale or Jacksonville or Miami or Orlando or Tallahassee or Tampa or Atlanta or Des Moines or Boise or Chicago or Indianapolis or Louisville or Baton Rouge or New Orleans or Shreveport or Boston or Baltimore or Detroit or Minneapolis or Kansas City or St Louis or Jackson or Charlotte or Raleigh or Winston-Salem or Lincoln or Omaha or Montvale or Short Hills or Albuquerque or Las Vegas or Albany or Buffalo or Melville or New York or Rochester or Cincinnati or Cleveland or Columbus or Oklahoma City or Portland or Harrisburg or Philadelphia or Pittsburgh or Providence or Greenville or Knoxville or Memphis or Nashville or Austin or Dallas or Fort Worth or Houston or San Antonio or Salt Lake City or Ashburn or McLean or Richmond or Seattle or Milwaukee or Virginia Beach or El Segundo
$90k-$168k/yrOnsiteFull Time
KPMG: Global professional services network providing audit, tax, and advisory.
4+ YOE4+ years application security/DevSecOps experience, familiarity with CI/CD, SAST/DAST, cloud (preferably Azure), programming in Java/C#/JavaScript/Python/SQL, strong threat modeling and risk assessment skills, and U.S. work authorization without sponsorship.
West 4th Strategy: Provides technology and professional services to federal government agencies.
Experienced DevSecOps engineer to build and secure AWS cloud infrastructure, implement IaC, automate CI/CD with GitHub Actions, integrate SAST/DAST/SCA tooling, perform container scanning, and coach developers; U.S. citizenship and public trust eligibility required.
RIVA Solutions: Delivers digital transformation and IT solutions to government agencies.
CISSP and Public Trust clearance ability, bachelor\u0002s in related field or equivalent experience, extensive federal security architecture experience, hands-on Databricks/Unity Catalog/Mosaic AI Gateway/AWS GovCloud, and experience with DSPM, AI-DLP, CNAPP, SAST/SCA.
Databricks, Unity Catalog, Mosaic AI Gateway, AWS GovCloud, FedRAMP, DSPM, AI-DLP, CNAPP, Wiz, SAST, SCA, Snyk, NIST AI RMF, FISMA
Cooley: Global law firm providing legal services to high-growth industries.
4+ YOE4+ years building and operating cloud infrastructure and CI/CD pipelines; strong Terraform (AWS, Azure), GitHub Actions, SAST/DAST, APM/Datadog, SOC 2 change management familiarity; proficiency with Microsoft Office and iManage; ability to work extended hours and travel as required.
540: Builds mission-critical software and cloud systems for government agencies.
5+ YOEU.S. citizen with active clearance (TS/SCI eligibility). 5+ years in cybersecurity, experience with cloud (AWS/Azure/Google Cloud), RMF and NIST 800-53, eMASS ATO packages, STIGs, vulnerability scanning (SAST/Fortify), containers, CI/CD/DevSecOps, and policy-as-code. CompTIA Security+ required (or obtain within 30 days).
AWS, Azure, Google Cloud, RMF, NIST 800-53, eMASS, STIGs, SAST, Fortify, CI/CD, DevSecOps, MLOps, Linux, policy as code
Application Security Engineer — Secure Mission Systems
United States or Laurel
RemoteFull Time
Rackner: Builds cloud-native software and AI systems for government agencies.
6+ YOE6+ years in SAST/DAST and vulnerability remediation, bachelor’s in cybersecurity, experience with application-security testing, secure SDLC, and working with development teams to remediate findings.