About this opportunity
Cybersecurity Jobs lists this Sr. IT Application Security Engineer opportunity in reston, Virginia. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Support enterprise application security in a hybrid role based in Reston, VA, focusing on WAF administration, container image security scanning, and SDLC/CI-CD security controls.
Responsibilities
Administer and enhance enterprise BIG-IP WAF capabilities, including building security policies, tuning rules, investigating false positives, troubleshooting application traffic issues, and maintaining web application protections
Design, implement, and operate application security controls across enterprise applications and supporting platforms
Perform container image security scanning and analyze vulnerabilities found in application and container images
Assess severity and business risk for container vulnerabilities and collaborate directly with development teams to prioritize and remediate findings
Partner with Development and DevOps teams to embed security controls into the SDLC and CI/CD pipelines
Design and operate web application and API security protections , including policy configuration, rule tuning, automation, and continuous improvement
Identify application security vulnerabilities, complete risk assessments, and recommend practical mitigation and remediation strategies
Develop and maintain application security policies, standards, procedures, and controls
Build and maintain security monitoring and telemetry for the application stack to improve proactive detection
Conduct technical investigations tied to application security incidents and vulnerabilities
Support container security activities, including image scanning, vulnerability risk assessments, and runtime security/hardening
Operate and support security technologies across cloud and/or on-premises environments
Troubleshoot security, application, and network-related issues and communicate findings and recommended actions clearly
Partner with senior IT stakeholders to interpret application security risks, priorities, and remediation needs
Requirements
6–8 years of Application Security experience designing, implementing, and operating security controls in enterprise application environments
Hands-on BIG-IP WAF administration , including building WAF policies, configuring protections, tuning rules/policies, troubleshooting in production, reducing false positives, and maintaining WAF controls
Hands-on container image security/scanning , including reviewing scan results, evaluating vulnerabilities, determining risk and remediation priorities, and working directly with development teams
Experience with a container security/scanning platform (tool not critical). Relevant examples include Prisma Cloud , Wiz , Snyk , or comparable technologies
Strong web application security knowledge, including OWASP Top 10 vulnerabilities and practical application of security controls
Experience conducting web application security scans, vulnerability assessments, and/or penetration testing
Experience partnering directly with Development and DevOps teams to integrate security into the SDLC and CI/CD pipelines
Experience with authentication and authorization technologies such as OAuth and OpenID
Strong troubleshooting and communication skills, able to explain security risks and remediation requirements to both technical teams and senior IT stakeholders
Bachelor’s degree in Information Security, Computer Science, Computer/Electrical Engineering, or a related discipline, and/or equivalent relevant professional experience
Demonstrated production experience administering BIG-IP WAF, including building and tuning WAF policies
Demonstrated hands-on experience with container image scanning and vulnerability management
Experience personally reviewing container vulnerabilities and collaborating with developers on remediation
Experience integrating security practices and controls into CI/CD and secure software development processes
Experience operating cloud-based and/or on-premises security platforms
Ability to investigate and troubleshoot security and network-related issues using established security methodologies and best practices
Strong communicator who can work effectively with developers, DevOps engineers, operations teams, and senior IT stakeholders
Collaborative and approachable, able to influence remediation and security improvements while maintaining cross-functional relationships
Proof of eligibility to work in the United States
Technologies
BIG-IP WAF
OWASP Top 10
OAuth
OpenID
Prisma Cloud
WizSnyk
CI/CD
SDLC li>
Benefits
150-180K base salary + 7% Bonus
Location
Hybrid in Reston, VA 20190
3 days on-site per week (Tues/Wed)
#J-18808-Ljbffr
Worksite address
reston, VA, 22090, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.