SW Cyber Security Engineer (Mid-Level)
On-siteReston, Virginia, United States
Job Summary
Conduct application security testing using tools like Checkmarx, Burp Suite, and Fortify within Java/AWS environments. Support secure SDLC, DevSecOps practices, and CI/CD pipeline security automation by integrating metrics reporting with Jira or ServiceNow. Identify, triage, validate, and prioritize vulnerability remediation using a risk-based approach while securing AWS cloud environments and container security across Kubernetes, Helm, and Docker. Collaborate across source code management platforms including Bitbucket, GitLab, and Jenkins. This role supports a leading healthcare payor client with mandatory onsite work in Reston, VA.
Required Qualifications
- Mid-level Software Application-focused Cyber Security Engineer
- Strong AWS Cloud Vulnerability Management and application security testing experience
- Candidates must reside in the DC, MD, or VA area
- Travel expenses will not be reimbursed
- Mandatory F2F final round in Reston, VA
- Hands-on application security, secure SDLC, and DevSecOps experience
- Proficiency in Java, JavaScript, or Python with a focus on secure coding and vulnerability management
- Strong understanding of Linux/Windows operating systems and networking protocols
- Experience with container security — Kubernetes, Helm, and Docker
- Hands-on AWS cloud security experience
- Familiarity with application security testing tools — Checkmarx, Contrast Security, TideLift, Burp Suite, OWASP Dependency Check, or Fortify
- Experience with CI/CD and SCM platforms — Bitbucket, GitLab, GitHub, Jenkins
- Experience integrating security tooling with Jira, ServiceNow, or similar platforms
Desired Qualifications
- OSCP or CEH certification preferred
- Healthcare or regulated industry background
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.