VivSoft

Application Security Engineer

Remote
Java C# JavaScript SAST DAST OWASP AWS Azure GCP API Microservices GitHub Actions
Description

Application Security Engineer

Title: Application Security Engineer
Clearance Required: Public Trust
Location: Remote, USA
Position Type: Full-Time 

 About the company:  
At VivSoft, we aim to solve complex federal problems using emerging and open technologies in a collaborative and rewarding environment. VivSoft is a diverse team of strategists, engineers, designers, and creators experienced in building high performance effective softwares, with impactful organizational design and organizational dynamics for software delivery. We build secure Software Factories based on DoD reference designs and NIST Frameworks for Cloud and DevSecOps. These factories deliver AI/ML Applications, Data Science Platforms, Blockchain and Microservices for DoD, Healthcare and Civilian Agencies

Job Summary:
We are seeking an Application Security Engineer to support the modernization of a large-scale enterprise software development platform. This role focuses on securing CI/CD pipelines, enforcing DevSecOps best practices, and implementing automated security testing throughout the SDLC. The engineer will work closely with development and platform engineering teams to embed security into reusable templates, GitHub Actions, and deployment workflows, ensuring applications are built and deployed securely across environments.

Key Responsibilities: 
  • Using GitHub Advanced security, review security findings of the organization. 
  • Review, validate, and approve request to remediate security findings. 
  • Review, validate, and approve request to dismiss security findings.  
  • Collaborate with Federal POC and FDIC security team to create and implement application security processes and standards.  
  • Identify gaps and design solutions to improve application security at the FDIC.  
  • Provide guidance to FDIC developers in regard to remediating findings when needed.  

Required Skills:
  • Bachelor’s degree in Computer Science, Engineering, Information Technology, or related field, or equivalent professional experience.
  • Proficiency in at least one or two major enterprise languages (e.g., Java, .Net, C#, JavaScript) to effectively review code and understand development context. 
  • Experience integrating security tools (SAST/DAST/SCA) into CI/CD pipelines to automate vulnerability scanning. 
  • Proficient in conducting and interpreting results from 
  • SAST (Static Analysis Security Testing) 
  • DAST (Dynamic Analysis Security Testing) 
  • Manual Code Review for security flaws 
  • Deep understanding of the OWASP Top 10 and other common application security attack vectors (e.g., injection, XSS, broken access control). 
  • Knowledge of security considerations for large, complex enterprise architectures, which may include Cloud Security (AWS, Azure, or GCP), API security, and microservices. 
Benefits:  
  • Comprehensive Medical, Dental, and Vision Plans (Healthcare benefits are 100% employer-paid for employees only)  
  • Life Insurance  
  • Paid Time Off (Flexible/Combined PTO, Bereavement Leave, 11 Company Paid Holidays)  
  • 401K Retirement Plan with employer match  
  • Professional Development Training Reimbursement


 
VivSoft
VivSoft

0 applies

0 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say