AppSec Engineer – Senior

CACI International

About The Position

The Opportunity: Lead application security testing and assessment efforts across a complex DoD application portfolio Serve as the technical authority for SAST, DAST, and penetration testing operations Mentor junior engineers and drive secure development lifecycle improvements program-wide Collaborate directly with the Cybersecurity Architect on secure SDLC strategy and AppSec governance Influence how security is embedded across the development pipeline from design through deployment Responsibilities: Lead SAST operations using Fortify and own findings triage and remediation tracking Oversee SonarQube continuous code security analysis and quality gate governance Lead DAST execution and runtime vulnerability assessment activities Plan, lead, and execute penetration testing engagements Lead secure code review processes and mentor developers on remediation Own application vulnerability remediation tracking and verification Develop and maintain application security assessment and pen test report standards Drive secure development lifecycle compliance across assigned application portfolios Mentor junior and mid-level AppSec engineers Serve as AppSec liaison to the Cybersecurity Architect on SDLC security strategy

Requirements

  • Required Certification: DoD 8140.03M DCWF Intermediate tier certification — one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+
  • Required: Bachelor’s degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering
  • Active TS clearance
  • 6–9 years of experience in application security, penetration testing, or secure software development
  • Advanced proficiency with Fortify and SonarQube
  • Demonstrated experience leading penetration testing engagements and secure code reviews
  • Strong knowledge of web application, API, and mobile application vulnerability classes
  • Proven ability to mentor and develop junior AppSec staff

Nice To Haves

  • Master’s or Ph.D. in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering
  • Multiple 541 Advanced tier certifications
  • OSCP or equivalent offensive security certification
  • Experience with DevSecOps pipeline security integration
  • Prior experience developing AppSec programs or secure coding standards in a DoD environment

Responsibilities

  • Lead SAST operations using Fortify and own findings triage and remediation tracking
  • Oversee SonarQube continuous code security analysis and quality gate governance
  • Lead DAST execution and runtime vulnerability assessment activities
  • Plan, lead, and execute penetration testing engagements
  • Lead secure code review processes and mentor developers on remediation
  • Own application vulnerability remediation tracking and verification
  • Develop and maintain application security assessment and pen test report standards
  • Drive secure development lifecycle compliance across assigned application portfolios
  • Mentor junior and mid-level AppSec engineers
  • Serve as AppSec liaison to the Cybersecurity Architect on SDLC security strategy

Benefits

  • A culture of integrity. At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose – to ensure the safety of our nation.
  • An environment of trust. CACI values the unique contributions that every employee brings to our company and our customers - every day. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
  • A focus on continuous growth. Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground — in your career and in our legacy.
  • Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service