Application Security Engineer @ Onsite @ Rockville, MD (or) McLean, VA
Quick Overview
Job Description
Hi,
Hope you are doing good, this is Rajeev from FutureTech Consultants, LLC and I have a job opening with our direct client.
Please have a look at the below job description and let me know your interest. Please share me the latest copy of your resume.
Role: Application Security Engineer
Location: Rockville, MD (or) McLean, VA (Hybrid 3 days onsite)
Duration: 6 Months with possible extension
Interview process: Pre-screen, Phone, Onsite panel
Job Summary:
- The Senior Application Security Engineer is responsible for designing, implementing, and advancing application security practices across the Software Development Life Cycle (SDLC).
- This role partners closely with engineering, DevOps, and security teams to identify vulnerabilities, support remediation efforts, evaluate security tooling, and strengthen secure development practices.
- The ideal candidate brings strong hands-on application security expertise, experience integrating security into CI/CD pipelines, and the ability to leverage modern automation and GenAI technologies to scale secure code review and vulnerability analysis capabilities.
Key Responsibilities:
- Perform application security assessments, manual penetration testing, and vulnerability validation using tools such as Burp Suite and other proxy/security testing tools.
- Analyze and triage findings from SAST, DAST, IAST, IaC, and secrets detection tools to identify, prioritize, and support remediation of security vulnerabilities.
- Partner with engineering teams to integrate security controls and testing into CI/CD pipelines in support of DevSecOps initiatives.
- Conduct secure code reviews and leverage GenAI-enabled security tooling to improve scalability and efficiency of application security analysis.
- Evaluate, recommend, and implement application security tools and technologies, including emerging capabilities related to automated code analysis and cloud security.
- Perform AWS configuration and cloud security reviews to ensure adherence to security best practices and compliance standards.
- Develop and maintain documentation related to security findings, remediation activities, risk assessments, and compliance requirements.
- Contribute to the development, interpretation, and enforcement of application security policies, standards, and procedures.
- Support enterprise security compliance initiatives and participate in audit and risk management activities.
- Deliver security awareness training and educate developers and QA engineers on common application security risks, secure coding practices, and remediation techniques.
- Stay current on emerging threats, vulnerabilities, attack techniques, and security technologies to continuously improve the organization's security posture.
Required Qualifications:
- Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical field.
- 5+ years of experience in cybersecurity with a strong focus on application security.
- Hands-on experience with SAST, DAST, IAST, and related application security testing methodologies and tools.
- Strong understanding of OWASP Top 10 vulnerabilities, secure coding principles, and remediation strategies.
- Experience performing manual penetration testing and application vulnerability assessments.
- Proficiency in one or more programming or scripting languages such as Java, Python, or JavaScript.
- Experience integrating security tooling into CI/CD pipelines using platforms such as Jenkins and GitLab.
- Strong knowledge of security engineering concepts including authentication, authorization, cryptography, network security, and secure application architecture.
- Experience with AWS cloud security concepts, services, and configuration reviews.
- Excellent communication skills with the ability to collaborate effectively across engineering and security teams.
Preferred Qualifications:
- Background in software engineering or application development.
- Familiarity with GenAI-assisted security tooling and automated code analysis solutions.
- Experience with Infrastructure as Code (IaC) security scanning and secrets management tools.
- Experience conducting infrastructure or application-level vulnerability testing and security auditing.
Industry certifications such as:
- GWAPT
- OSWE
- Burp Suite Certified Practitioner
- CISSP
- CSSLP
- Experience supporting enterprise DevSecOps transformation initiatives.
Technical Environment:
- Application Security: SAST, DAST, IAST, Secure Code Review
- Cloud Platforms: AWS
- CI/CD Tools: Jenkins, GitLab
- Security Testing Tools: Burp Suite and related proxy/testing tools
- Programming Languages: Java, Python, JavaScript
- DevSecOps & Automation: Security pipeline integration, GenAI-assisted analysis
Regards
Rajeev Mudakala
Sr. Talent Acquisition Specialist
FutureTech Consultants, LLC
5655 Peachtree Parkway, Suite 212, Peachtree Corners, GA 30092
Direct:
&
Skills
Similar jobs
Cyber Security Analyst
California SoftTech, Inc. · Lansing, United States
8 minutes agoSecurity Engineer / Network Engineer (DoD | AWS GovCloud)
Credence Management Solutions · McLean, United States
8 minutes ago$120k - $150k/yrIT Security Compliance Analyst (SSP & ATO)
HTC Global Services · Lansing, United States
8 minutes agoInformation Security Engineer - NC, OH, AZ, TX
Apex Systems · Charlotte, United States
28 minutes ago$69 - $74/hrInformation Security Engineer - TX
Apex Systems · Irving, United States
28 minutes ago$53 - $57/hrCyber Digital Forensics Analyst
Eliassen Group · United States
28 minutes ago$30 - $35/hr