The Cybersecurity Engineer Journeyman designs, implements, and manages application and infrastructure security solutions across an enterprise IT environment, with a focus on aligning with DoD and NIST requirements and integrating security throughout the DevSecOps lifecycle. They work closely with development, infrastructure, and security operations teams to embed secure architecture, controls, and testing into CI/CD pipelines while maintaining compliance and documentation standards. This role combines hands-on engineering, threat modeling, and incident response expertise with governance and training responsibilities to strengthen the organization's overall security posture.
Key Responsibilities- Design and implement secure application and infrastructure architectures that comply with DoD and NIST security requirements, including Zero Trust principles, while integrating security into DevSecOps practices.
- Develop, configure, and manage security controls and tooling such as firewalls, intrusion detection/prevention systems, SIEM platforms, and identity and access management solutions to protect enterprise applications and services.
- Embed secure coding practices into the software development lifecycle, including static and dynamic analysis, manual and automated code reviews, and penetration testing activities integrated into CI/CD pipelines.
- Lead application threat modeling, risk and vulnerability assessments, and remediation activities across web and distributed applications, ensuring coverage of OWASP Top 10 and other relevant attack vectors.
- Implement and maintain strong authentication and authorization mechanisms (including RBAC), encryption and hashing, key management, and data protection measures for APIs, web services, and backend components.
- Monitor and analyze security events and logs, coordinate incident response procedures, and collaborate with development, network, and corporate security teams to investigate and resolve security incidents and weaknesses.
- Define, maintain, and enforce application security best practices, policies, and standards; perform security audits and maintain compliance documentation for internal and external stakeholders.
- Evaluate, select, and recommend application security tools and technologies (e.g., static analysis tools, intercepting proxies, configuration management and automation tools) to improve coverage, efficiency, and developer experience.
- Train developers and other team members on secure code development techniques, common vulnerabilities, secure use of frameworks and libraries, and enterprise security protocols.
Required Qualifications- Bachelor's Degree in Computer Science, Engineering, or other technical discipline, or equivalent relevant experience.
- 5-10 years of experience as an Application Security Developer, Application Security Analyst, or equivalent role with direct responsibility for securing web and distributed applications.
- Demonstrated hands-on experience implementing and reviewing application security controls and practices across the full software development lifecycle, including architecture review, secure design, code review, and integrated security testing.
- Strong experience working with Unix/Linux operating systems and modern source code management tools such as Git in a collaborative development environment.
- Solid knowledge of network, system, and application-layer security concepts, including common attack methods and mitigation techniques across TCP/IP, HTTP/HTTPS, and related protocols.
- Ability to communicate complex security issues, risks, and remediation recommendations clearly to developers, architects, and non-technical stakeholders.
- Eligibility to obtain and maintain any required background investigations and to work in a federal or similar high-compliance environment, with appropriate citizenship as specified by the client.
Preferred Qualifications- Expertise with Java application server technologies such as Spring Framework, Spring Security, Web Services, REST, and Hibernate.
- In-depth experience with single sign-on and identity management technologies, including SAML, LDAP, and related federation and access control solutions.
- Hands-on experience with static code analysis tools (e.g., HP Fortify), intercepting proxies (e.g., Burp Suite), and security engineering in JavaScript, NodeJS, or other scripting languages.
- Familiarity with DevOps/automation tooling such as Vagrant, Chef, Rake, Gradle, Jenkins, and cache databases, along with experience in Agile/Scrum development environments; experience with Axiomatics or similar ABAC platforms is a plus.
Compensation RangesCompensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
DisclaimerThe preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.