Application Security Engineer

Booz Allen Hamilton•Usa, DC

About The Position

Work with clients, application owners, and development teams to maintain a resilient security posture for highly visible and business-critical applications. Collaborate with application security teams to identify, prioritize, and remediate application security vulnerabilities throughout the software development lifecycle. Lead security discussions with application teams and provide guidance on secure development practices, security requirements, and application security best practices. Perform static application security testing (SAST), dynamic application security testing (DAST), threat modeling, and application-level security assessments using tools such as Veracode and Burp Suite DAST. Apply current OWASP framework, standards, and best practices to identify risks and strengthen application security. Stay current with emerging application security threats and vulnerabilities while helping development teams implement effective security controls and remediation strategies.

Requirements

  • 6+ years of experience with information technology, and cybersecurity or application security
  • 3+ years of experience with Java, Python, .NET, or C#
  • 3+ years of experience using Burp Suite DAST to perform DAST
  • 3+ years of experience designing and implementation enterprise-wide security controls to secure applications, systems, networks, or infrastructure services
  • 3+ years of experience with Linux or UNIX environments, including system navigation and troubleshooting basic website connectivity issues
  • 2+ years of experience with Veracode and development environments such as Eclipse and JDeveloper, including pipeline development and integration
  • Experience securing enterprise web applications and frameworks, including OWASP Top 10, CVSS, CWE, WASC, and SANS-25
  • Knowledge of federal security and compliance standards, including NIST 800-53, FIPS, or FedRAMP
  • Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements
  • HS diploma or GED

Nice To Haves

  • Experience with Interactive Application Security Testing (IAST) capabilities and tools

Responsibilities

  • Maintain a resilient security posture for highly visible and business-critical applications.
  • Collaborate with application security teams to identify, prioritize, and remediate application security vulnerabilities throughout the software development lifecycle.
  • Lead security discussions with application teams and provide guidance on secure development practices, security requirements, and application security best practices.
  • Perform static application security testing (SAST), dynamic application security testing (DAST), threat modeling, and application-level security assessments.
  • Apply current OWASP framework, standards, and best practices to identify risks and strengthen application security.
  • Stay current with emerging application security threats and vulnerabilities.
  • Help development teams implement effective security controls and remediation strategies.

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service