Demo

Application Security Lead Engineer

CVP
Bethesda, MD Full Time
POSTED ON 1/19/2025
AVAILABLE BEFORE 4/17/2025

CVP is seeking an Application Security Lead Engineer to execute and support the implementation of a successful program with specific focus on vulnerability management in an application development environment.

Responsibilities

  • Analyze security needs, risks and requirements of custom systems.
  • Provide solid understanding in vulnerability management and information security, including broadening awareness and use of the team services, education of security best practices and integration with other business areas.
  • Provide mentorship and support to teammates regarding vulnerability assessment, communication / rapport with other divisions and various levels of leadership, technical expertise, and career development.
  • Evaluate both system and application scans and architecture designs for security vulnerabilities providing remediation recommendations.
  • Coordinate, build and maintain relationships with internal and external stakeholders to include system developers.
  • Develop and improve KPIs, metrics, and trending for vulnerability management functions.
  • Review and provide feedback on results generated by automated scanning tools.
  • This shall include, but not be limited to, identification of false positives generated by those tools, either by using the data contained within the result set generated by the tools, or by manual investigation of the targets on which the testing tools identified security findings.
  • Review and provide feedback on false positive, mitigation, or remediation evidence provided by IT stakeholders to determine the validity and completeness of any findings identified.
  • Provide subject matter expertise concerning known vulnerabilities, and become knowledgeable of newly released vulnerabilities, and discuss methods of exploitation, methods of mitigation or remediation, severity of impact, difficulty of exploitation, and other pertinent considerations of vulnerabilities. This discussion may be required either verbally or via written presentation.
  • Use prior knowledge and experience of security configurations and concepts to help create and review existing or new security policies.
  • Identify the applicable NIST security controls, HHS security policy items, or security policy items that correspond to any finding identified via manual or automated testing.
  • Create and conduct presentations of the security testing processes / methodologies used, as well as general security best practices, regarding security of operating systems, databases, and network fabric devices, and related technology concepts.
  • Act as a liaison to external audit functions. This activity could include conducting data calls and executing ISSO-specified or approved testing activities.
  • Participate in any additional activities which directly support actions required within this Task.
  • Ensure all software applications are FISMA compliant.

Qualifications

  • Must be eligible to obtain a Public Trust government security clearance.
  • 4-year college degree in Computer Science or related field, and 2 years of experience or 5 years of experience in lieu of a college degree.
  • Experience demonstrating strong analytical, troubleshooting and problem-solving skills for cybersecurity.
  • Expertise of security standards and frameworks including : NIST CSF, FISMA, FedRAMP.
  • Knowledge of security concepts such as cyber-attacks and techniques, threat vectors, risk management, threat management, and incident management.
  • Solid understanding of cloud-based technologies such as AWS and Azure.
  • Knowledgeable of Windows and UNIX / Linux environments, MS SQL Server and Oracle DBs, and VMware.
  • Excellent communication skills, both written and oral.
  • Desired Skills :

  • CISSP, Security , MCSE, A , and / or other industry certifications.
  • Understand of the following technologies :
  • Drupal

  • Jenkins
  • Kubernetes
  • Docker
  • Public Key Infrastructure (PKI) and Secure Sockets Layer (SSL)
  • Linux
  • AWS, Azure
  • Windows Server 2016-2022 Operating System
  • J-18808-Ljbffr

    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Application Security Lead Engineer?

    Sign up to receive alerts about other jobs on the Application Security Lead Engineer career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $152,549 - $188,894
    Income Estimation: 
    $194,072 - $240,547
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $70,462 - $84,818
    Income Estimation: 
    $77,991 - $108,747
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at CVP

    CVP
    Hired Organization Address Long Beach, CA Full Time
    Customer Value Partners (CVP) is seeking a Respiratory Therapist for a job in Long Beach, California. Job Description & ...
    CVP
    Hired Organization Address Fort Stewart, GA Full Time
    Customer Value Partners (CVP) is seeking a LPN / LVN for a job in Fort Stewart, Georgia. Job Description & Requirements ...
    CVP
    Hired Organization Address Hinesville, GA Full Time
    Customer Value Partners (CVP) is seeking a LPN / LVN for a job in Hinesville, Georgia. Job Description & Requirements Sp...
    CVP
    Hired Organization Address Hinesville, GA Full Time
    CVP seeks Licensed Practical Nurses (LPNs) to join our team in providing healthcare services to our Nation's Veterans ac...

    Not the job you're looking for? Here are some other Application Security Lead Engineer jobs in the Bethesda, MD area that may be a better fit.

    Application Security Lead Engineer

    Customer Value Partners, Inc, Bethesda, MD

    Web Application Security Engineer (Senior)

    Iron Vine Security, LLC Career Center, Suitland, MD

    AI Assistant is available now!

    Feel free to start your new journey!