Application Security Engineer, Senior

Feditc LLC
Tampa, FL, United States
Full-time
We are sorry. The job offer you are looking for is no longer available.

Job Details

Level

Senior

Job Location

MacDill AFB - Tampa, FL

Position Type

Full Time

Education Level

4 Year Degree

Description

FEDITC, LLC is a fast-growing business supporting DoD and other intelligence agencies worldwide. FEDITC develops mission critical national security systems throughout the world directly supporting the Warfighter, DoD Leadership, & the country.

We are proud & honored to provide these services.

Overview of position :

FEDITC is seeking a Application Security Engineer, Sr. , to work at MacDill AFB . A United States Citizenship and an active TS / SCI DoD Security Clearance is required to be considered for this position.

The on-site Continuous Integration / Continuous Delivery (CI / CD) application cybersecurity engineer will specialize in implementing security analysis tools and security gates into all stages of the CI / CD pipeline.

Primary function is to work with agile development teams to review application risks, provide remediation recommendations, and help prevent future risks by cultivating secure coding practices.

The ideal candidate is someone with a developer background, has DevSecOps experience, and has performed application cybersecurity testing in a prior role.

Must also have excellent attention to detail, strong analytic, and communication skills, as well as a working knowledge and understanding of application cybersecurity toolsets used in the CI / CD DevSecOps pipelines.

In addition, the contractor will provide application cybersecurity engineer expertise, collaborate with agile development teams, and integrate DevSecOps pipeline solutions, defining a security baseline per product to ensure proper cybersecurity and compliance.

Responsibilities :

  • Provide cybersecurity guidance and direction in the design, development and implementation of automated solutions, based on a set of standards and processes that enable CI / CD developers to easily apply cybersecurity and compliance services.
  • Responsible for, support of, and coordinating with other Engineers, Architects, and teams in implementing a comprehensive cloud and application cybersecurity program in a DevOps environment.
  • Automate cybersecurity testing using a variety of architectures and cutting-edge technologies.
  • Design, execute, and maintain automated cybersecurity testing for web applications (apps), mobile apps, and application programming interfaces (APIs).
  • Actively review and implement improvements to drive continuous improvement of the efficiency, speed, and quality of the CI / CD DevSecOps environment.
  • Leverage DevSecOps tools to build, harden, maintain and instrument a comprehensive cloud-based cybersecurity orchestration platform to be used in product CI / CD pipelines.
  • Integrate cybersecurity practices across the continuous delivery pipeline to provide a comprehensive automated cloud and application cybersecurity solution.
  • Perform risk and vulnerability assessments of CI / CD IT and IS platforms for authorization; prepare risk assessment reports for submission to the SCA and AO in accordance with DoD, USCYBERCOM, USSOCOM policies, procedures, and regulations.
  • Coordinate, manage and facilitate CI / CD application cybersecurity compliance processes with internal and external stakeholders to provide timely deliverables and rapid remediation.
  • Support the development of standards by creating templates and patterns for ease of use and increase the productivity of the cybersecurity program.
  • Foster, and build a community of practice for collective learning of the cybersecurity tools, practices, and systems across all disciplines.
  • Maintain application cybersecurity toolsets used in the development pipelines. Work hand in hand with developer teams to implement testing into their pipelines.
  • Professional curiosity that leads to learning and staying current with business best practices.
  • Work with leadership to identify and revise cybersecurity testing approaches.
  • Able to work on multiple projects and prioritize accordingly.

Qualifications

Experience / Skills :

  • 8+ years of related experience.
  • Experience with CI / CD DevSecOps integration with tools such as Jenkins, JIRA, GitLab, and Bitbucket
  • Strong experience in cloud and application cybersecurity domains.
  • Experience with OR knowledge of supporting Cloud based platforms (Google, Microsoft, Amazon Web Services (AWS), and Military Cloud (MilCloud)).
  • Experience with OR knowledge of Open Containers Initiative (OCI) compliant containers and OpenShift Container Platform technology utilizing Kubernetes orchestration technology.
  • Strong and evolving competence in one or more programming languages and scripting using Python, Personal Homepage (PHP), Just Another Virtual Architecture (JAVA), JAVA Script, Power Business Intelligence (BI) and .Net Core.
  • Experience with container cybersecurity solutions such as Twistlock and Claire to scan for vulnerabilities within OCI containers.
  • Have used source control (github / gitlab) to manage code.
  • Experience working in a Linux or Universal Network Information Exchange (UNIX) based environment.
  • Extensive experience in implementing and enforcing application cybersecurity and vulnerability management.
  • Thorough understanding of release strategies that minimize or eliminate application downtime.
  • Experience with Change Management and Ticketing Systems (Remedy).
  • A good understanding of the Software Development Life Cycle (SDLC) and Agile software development methodology
  • Experience with OR knowledge of the Risk Management Framework (RMF), Security Technical Implementation Guides (STIGs) and NIST regulations

Education :

BA / BS degree

Certifications :

IAT Level II

Clearance :

  • Active TS / SCI clearance is required.
  • Must be a US Citizen and pass a background check.
  • Maintain applicable security clearance(s) at the level required by the client and / or applicable certification(s) as requested by FEDITC and / or required by FEDITC'S Client(s) / Customer(s) / Prime contractor(s).

FEDITC, LLC. is committed to fostering an inclusive workplace and provides equal employment opportunities (EEO) to all employees and applicants for employment.

We do not employ AI tools in our decision-making processes. Regardless of race, color, religion, sex (including pregnancy), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran.

FEDITC, LLC. ensures that all employment decisions are made in accordance with applicable federal, state, and local laws.

Our commitment to non-discrimination in employment extends to every location in which our company operates.

6 days ago
Related jobs
Promoted
Lockheed Martin
Oldsmar, Florida

This requisition is for a Level-3 Hardware Production Quality Engineer at the LM Rotary & Mission Systems (RMS) business unit in Oldsmar, FL. The Quality Engineer’s responsibilities include, but are not limited to:. Identify root causes and associated corrective actions, evaluate process/product per...

Promoted
AEVEX Aerospace
Tampa, Florida

In this job you are the technical owner of an engineering product across its rapid lifecycle from prototype to production and fielded product support. Co-Chairs (with Program Management) the Air Vehicle Change Control Board (CCB) for assigned UAS platform and coordinates design upgrades and correcti...

Promoted
VirtualVocations
Saint Petersburg, Florida

Product Security Engineer, Application Security (Remote). ...

Promoted
RIT Solutions, Inc.
Tampa, Florida

Serve as the company's US lead security engineer and technical leader with responsibilities in designing and leading security assessments on company applications/infrastructure and providing recommendations on effective countermeasures. Engage software solutions architects, software engineers and ot...

Promoted
VirtualVocations
Saint Petersburg, Florida

Key Responsibilities:Evangelize the container security platform and manage associated security components and micro segmentation controlsManage, monitor, audit, and educate security teams about container security controls and underlying containerization platformsEvaluate, design, and implement secur...

Promoted
Ashley Furniture Industries Inc
Tampa, Florida

The Senior Cybersecurity Engineer is an advanced technology professional providing expertise to assure the effective performance of one or more key components of the organization's cybersecurity enterprise environments. Typically addresses challenges that Associate Engineers and Engineers require su...

Promoted
VirtualVocations
St. Petersburg, Florida

Key Responsibilities:Design, organize, and oversee activities to simulate threat actors and test security defensesPlan and participate in offensive security operations, develop program strategies, and implement key performance indicatorsInfluence department strategy, make decisions on technical appr...

Motion Recruitment
Tampa, Florida

Senior Cloud Security Engineer. A cloud-native health-tech startup based in Tampa Bay is hiring for a senior cloud security engineer. Position: Senior Azure Cloud Security Engineer. Advanced certifications such as CISSP, Azure Security Engineer, or related certifications are highly desirable. ...

00002 Citibank, N.A.
Tampa, Florida

The Senior Info Sec Data Engineer is a senior level position responsible for driving efforts to prevent, monitor and respond to information/data breaches and cyber-attacks. The overall objective of this role is to ensure the execution of Information Security directives and activities in alignment wi...

KPMG-UnitedStates
Tampa, Florida

Advanced knowledge and understanding of security engineering, system and network security, authentication and security protocols, cryptography, or application security. Minimum ten years of recent experience with at least three of the following: Security Architecture, threat modelling experience, id...