Application Security Engineer

Booz Allen Hamilton

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Annapolis Junction, MDBethesda, MD
Salary
$86,900–$198,000 / yr
Posted
4 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $178k
This role $142k
$72k most similar roles pay here $226k

This role pays less than 82% of similar roles. Most pay $145,700–$209,600 — the shaded band above. At the midpoint, this role pays about $142k versus about $178k for comparable roles.

Based on 240 similar postings.

Employer

About Booz Allen Hamilton

Booz Allen Hamilton is a management and technology consulting firm that provides analytics, digital, engineering, and cybersecurity solutions primarily to U.S. government agencies and commercial clients. Industry: Management & Technology Consulting

Booz Allen Hamilton currently has 776 open roles on FindRole.

Listed pay typically runs $86,800–$198,000 across 750 roles with salary data.

Most-posted roles

View all roles at Booz Allen Hamilton

At a glance

TL;DR · Application Security Engineer

As an Application Security Engineer, you will integrate security practices throughout the software development lifecycle to enhance and maintain the security posture of software. You will perform architecture reviews, threat modeling, and security assessments while managing multiple priorities and mentoring team members. Your daily work involves implementing or assessing Secure SDLC programs and managing software supply chain security components like SBOMs, dependency management, and secure build pipelines. You will utilize tools for SAST, DAST, SCA, IaC scanning, container security, and API security within Agile and DevSecOps environments. The role requires expertise in cloud-native architectures, microservices, Kubernetes, and serverless environments. You must possess skills in cryptography, vulnerability management, and risk prioritization to translate complex technical risks into actionable roadmaps for stakeholders while ensuring secure development for regulated industries like healthcare and financial services.

What you'll do

  • Integrate security practices throughout the software development lifecycle to enhance and maintain the security posture of software.
  • Perform architecture reviews, threat modeling, and security assessments for various applications.
  • Manage software supply chain security including SBOMs, dependency management, and secure build pipelines.
  • Implement and evaluate application security tools such as SAST, DAST, SCA, and IaC scanning.
  • Manage vulnerability remediation workflows and prioritize risks based on established methodologies.
  • Translate complex technical risks into executive-level briefings, business cases, and actionable roadmaps.
  • Mentor and supervise team members while providing technical leadership for the organization.

What we're looking for

  • 5+ years of experience in cybersecurity, application security, product security, or software engineering.
  • Experience implementing/assessing Secure SDLC, performing threat modeling, and conducting architecture reviews.
  • Experience with software supply chain security including SBOMs, dependency management, and secure build pipelines.
  • Experience evaluating tools such as SAST, DAST, SCA, IaC scanning, and container security.
  • Knowledge of modern architectures (cloud-native, microservices, Kubernetes) and core security concepts like cryptography and identity management.
  • Ability to translate complex technical risks into executive-level briefings and actionable roadmaps.
  • Bachelor's degree in CS, Cybersecurity, Information Systems, or Engineering.
  • Experience with regulated industries, industry frameworks (NIST, ISO, OWASP), or a Master's degree (preferred).

More like this

Similar roles

Application Security Engineer

Booz Allen Hamilton

Colorado Springs, CO +1 4 days ago $99,000–$225,000
F5 BIG-IP LTM APM ASM VMware NSX-T SD-WAN TLS mTLS PKI Linux UNIX RDP SSH CLI NIST 800-53 FIPS FedRAMP

Senior Application Security Engineer

Caterpillar

Chicago, IL +3 3 days ago $112,710–$183,140
Application Security DevOps SAST DAST SCA CodeQL Rapid7 OWASP Top 10 RESTful APIs Single Page Applications AWS Azure GCP Salesforce Penetration Testing

Senior Application Security Engineer

AbbVie

Chicago, IL 55 days ago $109,500–$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation OWASP Top 10 CWE CSPM Snyk Endor Labs
7+ yrs exp

Senior Application Security Engineer

AbbVie

Irvine, CA 55 days ago $109,500–$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation CSPM Snyk Endor Labs OWASP Top 10 CWE
7+ yrs exp

Lead Application Security Engineer

Booz Allen Hamilton

Colorado Springs, CO 58 days ago $99,000–$225,000
Zero Trust Palo Alto Fortinet Cisco Juniper F5 Nginx A10 NetScaler ColorTokens Illumio Terraform VS Code AWS Azure OWASP Top 10 CVSS CWE WASC SANS-25 Infrastructure-as-Code Routing Switching

Information Security Engineer (Application Security)

Lam Research

Fremont, CA 14 days ago $92,000–$211,000
Secure SDLC SAST DAST SCA CI/CD OWASP Azure Kubernetes Git Bitbucket Jenkins Azure DevOps Artifactory MLOps Prompt Injection RAG API Security Container Scanning Threat Modeling
3+ yrs exp Hybrid