Application Security Engineer

Booz Allen Hamilton

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Washington, DC
Salary
$62,000–$141,000 / yr
Employment
Full-time
Posted
1 day ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $177k
This role $102k
$44k most similar roles pay here $227k

This role pays less than 98% of similar roles. Most pay $145,000–$209,600 — the shaded band above. At the midpoint, this role pays about $102k versus about $177k for comparable roles.

Based on 240 similar postings.

Employer

About Booz Allen Hamilton

Booz Allen Hamilton is a management and technology consulting firm that provides analytics, digital, engineering, and cybersecurity solutions primarily to U.S. government agencies and commercial clients. Industry: Management & Technology Consulting

Booz Allen Hamilton currently has 815 open roles on FindRole.

Listed pay typically runs $86,800–$198,000 across 787 roles with salary data.

Most-posted roles

View all roles at Booz Allen Hamilton

At a glance

TL;DR · Application Security Engineer

As an Application Security Engineer, you will join the security team to maintain a resilient posture for business-critical applications. You will collaborate with application owners and development teams to identify, prioritize, and remediate vulnerabilities throughout the software development lifecycle. Your daily responsibilities include leading security discussions, providing guidance on secure development practices, and performing threat modeling and assessments. You will utilize tools such as Veracode and Burp Suite DAST while applying OWASP frameworks, CVSS, CWE, WASC, and SANS-25 standards to strengthen application security. The role requires proficiency in Java, Python, .NET, or C# within Linux or UNIX environments. You will also navigate development environments like Eclipse and JDeveloper to implement enterprise-wide controls while ensuring compliance with federal standards such as NIST 800-53, FIPS, or FedRAMP for web applications.

What you'll do

  • Identify, prioritize, and remediate application security vulnerabilities throughout the software development lifecycle.
  • Perform static (SAST) and dynamic (DAST) application security testing using tools like Veracode and Burp Suite.
  • Conduct threat modeling and application-level security assessments to identify risks.
  • Provide guidance to development teams on secure coding practices and security requirements.
  • Implement effective security controls and remediation strategies based on current threats.
  • Apply OWASP frameworks and standards to strengthen the security posture of business-critical applications.
  • Advise application owners on best practices for maintaining a resilient security posture.

What we're looking for

  • 6+ years of experience with information technology and cybersecurity or application security.
  • 3+ years of experience with Java, Python, .NET, or C#.
  • 3+ years of experience using Burp Suite DAST to perform DAST.
  • 3+ years of experience designing and implementing enterprise-wide security controls for applications, systems, networks, or infrastructure.
  • 3+ years of experience with Linux or UNIX environments including system navigation and troubleshooting.
  • 2+ years of experience with Veracode and development environments like Eclipse and JDeveloper.
  • Experience securing web applications using OWASP Top 10, CVSS, CWE, WASC, and SANS-25.
  • Knowledge of federal security standards such as NIST 800-53, FIPS, or FedRAMP.
  • Ability to obtain and maintain a Public Trust or Suitability/Fitness determination.
  • HS diploma or GED.
  • Experience with Interactive Application Security Testing (IAST) capabilities and tools (preferred).

More like this

Similar roles

Senior Application Security Engineer

AbbVie

Irvine, CA 58 days ago $109,500–$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation CSPM Snyk Endor Labs OWASP Top 10 CWE
7+ yrs exp

Senior Application Security Engineer

AbbVie

Chicago, IL 58 days ago $109,500–$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation OWASP Top 10 CWE CSPM Snyk Endor Labs
7+ yrs exp

Application Security Engineer

Booz Allen Hamilton

Annapolis Junction, MD +1 8 days ago $86,900–$198,000
SAST DAST SCA IaC Scanning Kubernetes DevSecOps SBOM Threat Modeling API Security Cryptography Cloud Security OWASP SAMM BSIMM NIST SSDF NIST CSF MITRE ATT&CK ISO 27001 Microservices Container Security
5+ yrs exp

Security Engineer, Application

Genworth Financial

Richmond, VA +1 14 days ago $77,800–$117,000
Application Security DevSecOps AWS Azure GCP Infrastructure as Code Policy as Code CI/CD Python Java .NET C# PowerShell Bash Ruby PHP JavaScript HTML SOC2 ISO 27001 NIST 800-53 HIPAA PCI Threat Modeling Vulnerability Scanning
3+ yrs exp Hybrid

Lead Application Security Engineer

Booz Allen Hamilton

Colorado Springs, CO 61 days ago $99,000–$225,000
Zero Trust Palo Alto Fortinet Cisco Juniper F5 Nginx A10 NetScaler ColorTokens Illumio Terraform VS Code AWS Azure OWASP Top 10 CVSS CWE WASC SANS-25 Infrastructure-as-Code Routing Switching

Senior Application Security Engineer

Upstart

Remote (Canada) 23 days ago $166,900–$230,900
Application Security Threat Modeling SAST DAST SCA CI/CD Python Java Go Ruby API Security Microservices GraphQL REST GenAI Secrets Management Cloud-Native AWS CISSP CSSLP CCSP
5+ yrs exp Remote