T logo

Application Security Engineer - DAST & Burp Suite Enterprise Security Testing

TOMORROW HIREWashington, District of Columbia

$120,000 - $140,000 / year

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Overview

Schedule
Full-time
Career level
Senior-level
Remote
Remote
Compensation
$120,000-$140,000/year
Benefits
Health Insurance
Dental Insurance
Vision Insurance

Job Description

Description

Application Security Engineer

Location: Fully Remote (East Coast)Clearance: Public Trust, Secret Clearance preferredEmployment Type: Full-time

Salary: $120,000-$140,000

Role Overview:

The Application Security Engineer will support the secure development and testing of applications by leveraging specialized tools, implementing security controls, and ensuring compliance with federal standards. This role involves hands-on work with application security testing (SAST, DAST, IAST), vulnerability management, secure coding practices, and collaboration with development teams to protect enterprise web applications in a federal environment.

Responsibilities:

  • Support Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE Plug-in environments using Veracode and Burp Suite.
  • Design and implement enterprise-wide security controls to secure applications, systems, networks, or infrastructure services.
  • Secure enterprise web applications, with a focus on mitigating OWASP Top 10 risks, CVSS scoring, CWE, WASC, and SANS Top 25 vulnerabilities.
  • Integrate security practices into development workflows using IDEs such as Eclipse, JDeveloper (including pipeline development), or Visual Studio.
  • Perform application security testing and automation using tools such as OWASP ZAP, Burp Proxy, Selenium, and Interactive Application Security Testing (IAST) capabilities.
  • Write and maintain bash scripts to support security automation, testing, and troubleshooting tasks.
  • Participate in vulnerability discovery, triage, and remediation processes, including crowdsourced security programs via platforms like HackerOne.
  • Work in Linux or UNIX environments, including navigating file systems and troubleshooting basic website connectivity and security issues.
  • Ensure applications and security practices align with federal compliance standards, including NIST 800-53, FIPS, or FedRAMP.
Requirements
  • Minimum 6+ years of Information Technology experience with a focus on application and security engineering.
  • 3+ years of hands-on experience supporting application security testing, including Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST).
  • Demonstrated experience with SAST, DAST, and IDE plug-in integrations using tools such as Veracode and Burp Suite.
  • Experience performing authenticated and unauthenticated crawl auditing and DAST scanning using Burp Suite Enterprise Edition, including scan configuration, issue validation, and remediation coordination.
  • Experience with Interactive Application Security Testing (IAST) tools and methodologies.
  • Proficiency using OWASP ZAP and/or Burp Proxy for web application security testing.
  • Experience participating in vulnerability discovery and remediation programs, including HackerOne.
  • Experience with test automation tools, including Selenium.
  • Proficiency in bash scripting for security automation, testing, and troubleshooting.
  • 2+ years of development experience in one or more programming languages, including Java, Python, .NET, or C#.
  • Experience integrating security into development workflows using Eclipse, JDeveloper (including CI/CD pipeline development), or Visual Studio.
  • 3+ years of experience designing and implementing enterprise-wide security controls to secure applications, systems, networks, or infrastructure services.
  • Hands-on experience securing enterprise web applications, with strong knowledge of OWASP Top 10, CVSS, CWE, WASC, and SANS Top 25 vulnerabilities.
  • Knowledge of federal compliance and security frameworks, including NIST 800-53, FIPS, and FedRAMP.
  • Working knowledge of Linux or UNIX environments, including file system navigation and troubleshooting basic website connectivity issues.
  • High School Diploma or GED required.
  • Public Trust Determination or Active Security clearance (preferred)
Benefits

Salary: $120,000-$140,000

Benefits include Health, Vision, and Dental Insurance, and PTO.

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.

pay-wall

FAQs About Application Security Engineer - DAST & Burp Suite Enterprise Security Testing Jobs at TOMORROW HIRE

What is the work location for this position at TOMORROW HIRE?
This job at TOMORROW HIRE is located in Washington, District of Columbia, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at TOMORROW HIRE?
Candidates can expect a pay range of $120,000 and $140,000 per year.
What employment applies to this position at TOMORROW HIRE?
TOMORROW HIRE lists this role as a Full-time position.
What experience level is required for this role at TOMORROW HIRE?
TOMORROW HIRE is looking for a candidate with "Senior-level" experience level.
Does TOMORROW HIRE allow remote work for this role?
Yes, this position at TOMORROW HIRE supports remote work, giving candidates the flexibility to work outside the primary office location.
What benefits are offered by TOMORROW HIRE for this role?
TOMORROW HIRE offers following benefits: Health Insurance, Dental Insurance, Vision Insurance, Paid Vacation, and Health & Wellness Programs for this position. Actual benefits may vary depending on the employer's policies and employment terms.
What is the process to apply for this position at TOMORROW HIRE?
You can apply for this role at TOMORROW HIRE either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.