Position Summary
We are seeking an experienced Application Security Developer Lead to drive secure software development practices across mission-critical systems for a government agency. This role is responsible for embedding security into the Software Development Life Cycle (SDLC), leading secure coding initiatives, conducting application security assessments, and guiding development teams in mitigating vulnerabilities while ensuring compliance with government security standards.
Key Responsibilities:
Serve as the functional lead overseeing security design and assessment of application changes and cloud security solutions for client projects Evaluate, design, and implement security controls in alignment with government security requirements and best practices.
Hands on experience with Fortify, Snyk, Invicti, and BurpSuite, ensuring comprehensive scanning, remediation, and reporting.
Provide expert guidance on secure solution architecture within AWS, supporting large-scale deployments for regulated environments.
Conduct risk assessments, code reviews, penetration testing, and ensure ongoing compliance with federal and state standards.
Knowledge of secure coding in Java, C++, C, and JavaScript specifically for vulnerability identification and remediation.
Strong cross-team communication: prior client-facing roles, stakeholder engagement, and direct SDLC integration.
Required Qualifications
Bachelor s degree in Computer Science, Information Security, or related field.
8+ years of experience in software development with at least 3+ years focused on application security.
Strong experience in secure coding practices in languages such as Java, .NET, Python, or JavaScript.
Hands-on experience with application security tools (e.g., Fortify, Checkmarx, Veracode, Burp Suite).
In-depth understanding of OWASP Top 10, secure design principles, and common vulnerabilities.
Experience implementing security in DevOps/CI-CD pipelines (e.g., Jenkins, GitHub, GitLab).
Knowledge of authentication/authorization mechanisms (OAuth2, SAML, OpenID Connect).
Familiarity with cloud security (AWS, Azure, or Google Cloud Platform).
Strong analytical, problem-solving, and communication skills.
Preferred Qualifications
Experience working in government or public sector environments.
Knowledge of NIST 800-53, FISMA, or similar compliance frameworks.
Relevant certifications such as:
CISSP (Certified Information Systems Security Professional)
CSSLP (Certified Secure Software Lifecycle Professional)
CEH, GWAPT, or equivalent
Experience with container security (Docker, Kubernetes).
Exposure to Zero Trust Architecture and API security.
Key Competencies
Leadership and team mentorship
Risk assessment and mitigation
Secure system design and architecture
Stakeholder communication
Continuous improvement mindset
Work Environment
Government or public sector setting with a strong focus on data protection, compliance, and security governance.
May require background checks or security clearance depending on agency requirements.