Application Security Engineer
Bespoke Technologies, Inc. · Reston, VA · Yesterday
Information TechnologyFull-time
About the role
Bespoke Technologies is seeking a highly experienced and motivated Application Security Engineer for an exciting new contract. This role will be part of a team of Data, Cloud, and Security engineers delivering a cloud-native, centralized platform that provides end-to-end budget traceability.
Responsibilities
- Integrate security throughout the software development lifecycle, partnering with developers and cloud engineers to design, build, assess, and sustain secure mission applications.
- Develop or review applications using Python, JavaScript frameworks, SQL, Shell scripting, PL/SQL, and other programming languages, applying secure coding practices.
- Develop and implement automated security controls and testing within build and deployment pipelines.
- Assess, prioritize, document, and communicate application and cloud security risks, findings, and remediation recommendations to both technical and non-technical stakeholders.
- Implement identity and access management, privileged access controls, secrets management, encryption, logging, monitoring, and incident response capabilities in cloud environments.
- Secure Oracle RDBMS environments, including database access controls, encryption, auditing, and secure handling of sensitive data.
Requirements
- Technical expertise and hands-on experience in application security, secure software development, software engineering, or DevSecOps.
- Experience integrating security throughout the software development lifecycle, including secure design and architecture reviews, threat modeling, secure code review, security testing, vulnerability remediation, and release authorization support.
- Experience building and securing cloud-native applications and services using Kubernetes, containers, Docker, REST APIs, and CI/CD pipelines.
- Experience with application security testing tools and processes, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and container or infrastructure vulnerability scanning.
- Knowledge of security frameworks and standards such as NIST RMF, NIST Secure Software Development Framework, OWASP, DISA STIGs, and applicable federal security requirements.
- Passion for technology, curiosity, and willingness to continuously learn new security tools, techniques, and approaches for solving complex technical challenges.
- Experience working in an Agile framework.
Qualifications
- 8+ years of relevant experience in application security, software engineering, DevSecOps, cybersecurity, or a related technical discipline.
- Bachelor’s Degree in engineering, computer science or related technical discipline. Master’s degree preferred.
Skills
- Oracle Cloud Infrastructure (OCI) IaaS and/or PaaS certifications.
- Security certifications such as CISSP, CSSLP, Security+, GIAC, CEH, OSCP, or comparable credentials.
- Data engineering experience, including securing data validations, business rules, data transformations, and sensitive-data handling.
Benefits
Not specified.
Pay
Not specified.
Schedule
Not specified.