Application Security Engineer

$100K — $130K *
US-AnywhereRemote in United States
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active Top Secret clearance with Tier 5 background investigation
  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or related field
  • 7+ years of experience in application security, secure software development, or cybersecurity
  • Experience in secure code reviews, penetration testing, or API security testing
  • Knowledge of static and dynamic testing tools and DevSecOps integration

Responsibilities

  • Conduct secure code reviews of application logic, APIs, and backend integrations
  • Perform API security assessments for authentication and data handling
  • Support CMS hardening through secure template and module review
  • Integrate security within CI/CD pipelines using automated tools
  • Manage encryption and secure storage of API keys and credentials
  • Conduct application security testing and validate remediation measures
  • Advise developers and teams on secure coding practices
  • Collaborate with cloud engineers to ensure secure deployment processes

Benefits

  • Fully remote work environment
  • Opportunity to work on federal and DoD-aligned missions
  • Engage in a collaborative environment with cross-functional teams
  • Involvement in continuous improvement of security practices
  • Opportunity for professional development through skill enhancement and certifications
Full Job Description
Overview

DecisionPoint seeks an Application Security Engineer to perform advanced application-layer security assessments, secure coding reviews, vulnerability analysis, and security integration for enterprise applications supporting a federal and DoD-aligned mission environment. This role ensures secure development practices across CMS components, APIs, integrations, CI/CD pipelines, and custom code.

The Application Security Engineer supports secure coding standards, threat modeling, static and dynamic testing, and secure secrets management. This position plays a critical role in strengthening application-level defenses, reducing vulnerabilities, and ensuring mission systems meet stringent DoD security requirements.

This position is fully remote.

Duties & Responsibilities

The Application Security Engineer will:

  • Conduct secure code reviews, focusing on application logic, API endpoints, CMS modules, and backend integrations.
  • Perform API security assessments to validate authentication, authorization, data handling, and boundary protections.
  • Support CMS hardening by reviewing templates, modules, configurations, and custom components for secure implementation.
  • Integrate security requirements into CI/CD pipelines including SAST/DAST tools, dependency scanning, and automated controls.
  • Manage secrets handling, encryption policies, and secure storage of API keys, tokens, and credentials.
  • Conduct static and dynamic application security testing, vulnerability assessments, and remediation validation.
  • Provide secure coding guidance to developers, architects, and product teams.
  • Work with DevSecOps and cloud engineers to ensure secure build and deployment patterns.
  • Perform threat modeling and recommend mitigations for high-risk application features.
  • Review and validate authentication flows, SSO integrations, and identity-related protections.
  • Assist with security documentation including test results, remediation plans, and secure configuration records.
  • Support continuous monitoring, log analysis, and triage of application-layer security alerts.
  • Participate in sprint teams, code review cycles, and architecture discussions to embed security early.
Qualifications

Clearance Requirement

Must hold an active Top Secret clearance, supported by a Tier 5 background investigation.

Education (Required)

Bachelors degree in Computer Science, Cybersecurity, Engineering, or a related technical field.

Experience (Required)

  • Minimum 7 years of experience in application security engineering, secure software development, or cybersecurity.
  • Experience conducting code reviews, application penetration testing, or API security testing.
  • Experience with static and dynamic testing tools, dependency scanning, and software composition analysis.
  • Experience supporting secure CI/CD pipeline integration and DevSecOps practices.
  • Experience implementing secure secrets management, encryption, and authentication protections.

Technical Knowledge (Required)

  • Strong understanding of OWASP Top 10, secure coding principles, and application-layer attack vectors.
  • Experience with SAST/DAST tools, dependency scanners, and code review workflows.
  • Knowledge of API security, token-based authentication, and secure data handling.
  • Familiarity with CMS structures, template security, and module-level risk considerations.
  • Understanding of identity and access management, certificate management, and secure authentication flows.

Technical Knowledge (Preferred)

  • Experience with AWS cloud-native application security tools.
  • Familiarity with container security, Kubernetes workload protections, and microservices security.
  • Experience with modern CI/CD platforms and DevSecOps automation.

Certifications

Required:

  • Security+ or CISSP or CCSP

Preferred:

  • AWS Security Specialty
  • GIAC secure coding or cloud security certifications
  • Certified Ethical Hacker (CEH)

Skills

  • Strong analytical and problem-solving skills for identifying and remediating application-layer vulnerabilities.
  • Ability to clearly communicate technical risks, secure coding guidance, and remediation recommendations.
  • Strong attention to detail when reviewing code, configurations, and test results.
  • Ability to work collaboratively with developers, cloud engineers, PMO staff, and mission stakeholders.
  • Commitment to integrating security early and continuously throughout the development lifecycle.

Similar Jobs

More Jobs at

More Aerospace & Defense Jobs

Find similar Application Security Engineer jobs: