Title: Senior Application Security Engineer
Location : McLean, VA
Target Start Date : ASAP
Type: contract
Pay Rate: DOE
The Senior Application Security Engineer is responsible for planning, coordinating, and implementing application security practices across all phases of the software development lifecycle (SDLC). This role focuses on identifying and remediating security vulnerabilities through testing, tool evaluation, secure code reviews, and close collaboration with engineering teams. The engineer will also help advance DevSecOps initiatives and leverage modern technologies, including GenAI, to scale and automate application security capabilities.
Key Responsibilities - Conduct application security assessments, including manual penetration testing using tools such as Burp Suite and proxy-based testing tools
- Analyze and triage findings from SAST, DAST, and IAST tools, prioritizing and supporting remediation of security vulnerabilities
- Integrate security controls into CI/CD pipelines to support DevSecOps practices
- Perform secure code reviews and support remediation efforts with development teams
- Evaluate, implement, and optimize application security tools, including SAST, DAST, IaC, and secrets detection solutions
- Leverage GenAI technologies to automate code analysis and scale application security reviews
- Conduct AWS configuration and security reviews
- Maintain clear documentation of security findings, remediation plans, policies, and compliance requirements
- Develop and interpret application security policies, standards, and procedures
- Support security compliance initiatives and audits
- Develop and deliver security training and awareness programs for developers and assurance teams
- Stay current with emerging application security threats, vulnerabilities, and mitigation strategies
Qualifications - Bachelor's degree in Computer Science, Engineering, or a related technical field
- 5+ years of experience in cybersecurity and application security
- Hands-on experience with SAST, DAST, and IAST tools
- Strong understanding of AWS and cloud security best practices
- Deep knowledge of OWASP Top 10 vulnerabilities and remediation techniques
- Proficiency in one or more programming languages (preferably Java, Python, or JavaScript)
- Experience with CI/CD tools such as Jenkins and GitLab
- Strong technical knowledge of security engineering, including authentication, cryptography, network and system security, and application security
- Experience performing application and infrastructure vulnerability testing and auditing
- Ability to effectively communicate security concepts and train engineering teams
Preferred Qualifications - Software development background
- Familiarity with GenAI tools for security automation
- Relevant certifications such as GWAPT, OSWE, or Burp Suite Certified Practitioner
Welcome to ConsultNet, a premier national provider of technology talent and solutions. Our expertise spans across project services, contract-to-hire, direct search, and managed services onshore, nearshore, and hybrid.
For over 25 years, we have connected thousands of consultants with meaningful roles through a personal, communication-driven approach, partnering with a diverse client base to build high-performing teams and create lasting impact.
Our comprehensive service offerings cover a wide range of technology and engineering positions across key markets nationwide. Learn more at
.
We champion equality and inclusivity, proudly supporting an Equal Opportunity Employer policy. We welcome applicants regardless of Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other status protected by law.