Quick Overview
Job Description
Position Overview:
The Senior Application Security Engineer will support application onboarding, software risk assessments, vendor security reviews, and application security evaluations associated with an Apple modernization program.
The successful candidate will help accelerate the secure adoption of Apple-compatible applications while reducing application security review backlogs and improving governance around software onboarding and vendor risk management.
This is a 6-month contract opportunity focused on application security, software supply chain security, risk management, and security governance within a cross-platform Apple and Windows environment.
Responsibilities:
- Conduct security reviews of commercial, SaaS, freeware, open-source, and internally developed applications.
- Perform application risk assessments and security evaluations.
- Review vendor security questionnaires and supporting evidence.
- Support software onboarding and governance activities.
- Evaluate authentication, authorization, encryption, API security, and data handling practices.
- Perform application threat modeling and architectural reviews.
- Assess software supply chain and third-party risk.
- Develop secure configuration recommendations.
- Partner with application owners and technology teams to address security findings.
- Create repeatable application security standards and review processes.
- Perform security assessments for applications deployed natively on macOS.
- Perform security assessments for Windows applications delivered through Parallels Desktop.
- Evaluate software installation, privilege management, update mechanisms, and runtime security controls.
- Identify risks associated with mixed operating system environments.
- Assess browser-based and SaaS applications operating across macOS and Windows platforms.
- Review security implications of virtualized application delivery models.
- Deliver application security review reports, vendor security assessments, threat models, risk assessments, onboarding recommendations, remediation guidance, and governance documentation. Qualifications:Required Qualifications:
- Minimum 5 years of Application Security experience.
- Experience conducting application security assessments.
- Strong understanding of secure application design principles.
- Experience evaluating commercial, SaaS, and enterprise applications.
- Knowledge of authentication, authorization, API security, encryption, and software security fundamentals.
- Experience conducting vendor security reviews.
- Strong technical writing, presentation, and communication skills.
- Experience performing threat modeling and architectural security reviews.
- Experience assessing software supply chain risks and third-party dependencies. Preferred Qualifications:
- Experience securing applications within Apple environments.
- Familiarity with macOS application ecosystems.
- Experience with OWASP Top 10 and application security best practices.
- Experience with software composition analysis and supply chain risk management.
- Familiarity with Parallels Desktop or similar virtualization platforms.
- Healthcare and HIPAA experience.
- Experience assessing AI-enabled applications and services.
- Familiarity with cloud environments such as Microsoft Azure and/or Amazon Web Services (AWS).
- Experience supporting enterprise software governance initiatives. Tools and Technologies:Application Security & Software Supply Chain Security
- Snyk
- Dependency-Track
- DefectDojo
- JFrog Artifactory
- Software Bill of Materials (SBOM)
- OWASP Top 10
- Threat Modeling
- Vendor Risk Assessments Enterprise Technologies
- ServiceNow
- Apple macOS
- Jamf
- Microsoft Intune
- Parallels Desktop
- Windows Operating System
- Microsoft Azure (preferred)
- Amazon Web Services (AWS) (preferred)
Similar jobs
- CO
Engineer, Security Operations & Engineering
NewCollibra
Remote🇺🇸Remote5 hours agoGCPSQLAWS+8 - PS
4514 Cyber Vulnerability Analyst with Security Clearance
NewProcession Systems
Reston, VA🇺🇸Hybrid18 hours agoTechnology - XS
Security Engineer Logging and Aggregation - Secret with Security Clearance
NewXcelerate Solutions
Alexandria, VA🇺🇸$94k - $149k/yrHybrid18 hours agoTechnology - QS
Information System Security Manager with Security Clearance
NewQuantech Services
Fort Meade, MD🇺🇸Hybrid18 hours agoCSSEncryptionPKITechnology - XS
Security Engineer – Container Security with Security Clearance
NewXcelerate Solutions
Seaside, CA🇺🇸$94k - $127k/yrHybrid18 hours agoTechnology - IF
Security Engineer with Security Clearance
NewITC Federal
Washington, DC🇺🇸On-site18 hours agoAWSEncryptionAzure+7Technology