Federal Vulnerability Mgmt & App Security Engineer (US Citizen)
$125,000–$125,000 year
RemoteUnited States
Job Summary
Drive continuous improvements in vulnerability management processes and tools by leveraging automation and data-driven insights while staying current on emerging threats to adapt the program accordingly. Evaluate and recommend vulnerability management technologies, develop regular metrics and reports for executive leadership, and assist in building a diverse program covering secure software development lifecycle, patch governance, and application security. Perform technical threat/risk assessments and manage vulnerabilities throughout their lifecycle, providing consultative support to operational teams on remediation and enabling developer success through clear guidance. Own and evolve the Application Security program by performing static, dynamic, and software composition analysis assessments, partnering with development and DevOps teams to embed security into CI/CD pipelines, and defining application risk prioritization aligned to OWASP Top 10 standards.
Required Qualifications
- 3–5+ years of combined experience in cybersecurity, application security, or vulnerability management
- Strong understanding of information security risk measurement (qualitative and quantitative) to support effective prioritization
- Working knowledge of industry security frameworks and standards (e.g., NIST CSF/800-53, ISO 27001, OWASP)
- Ability to correlate threat intelligence with vulnerability and application risk
- Solid understanding of secure application development, including common programming languages, frameworks, and architectural patterns
- Hands-on experience with Application Security testing methodologies, including: Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA)
- Familiarity with OWASP Top 10, API Security Top 10, and common application attack patterns
- Experience integrating security scanning tools into CI/CD pipelines
- Ability to perform threat modeling and design-level security assessments
- Strong understanding of authentication, authorization, session management, and data protection controls within applications
- Expertise in vulnerability management programs, including lifecycle management and remediation governance
- Experience with vulnerability scanning and reporting tools (e.g., Qualys, Tenable, CrowdStrike, or equivalent)
- Familiarity with cyber threat intelligence services and the application of threat data to prioritization decisions
- Broad technical knowledge of networks, operating systems, cloud platforms, and web applications
- US Citizen
Desired Qualifications
- Prior experience working closely with software engineering or DevOps teams is strongly preferred
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.