Leads application security engineering for enterprise systems, including SAST and DAST scanning, security control implementation, web application protection, and pipeline development. Uses Veracode, Burp tools, Linux, and programming or scripting languages to identify and remediate vulnerabilities. Applies OWASP, CVSS, CWE, federal compliance standards, and secure architecture practices while supporting scalable digital transformation initiatives. Requires Public Trust eligibility and U.S. citizenship.
About Agile Defense
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Requisition #: 1858
Job Title: Senior Application Security Engineer
Location: Remote
Clearance Level: Must be able to obtain and maintain a Public Trust Clearance
Job Description
Responsible for engineering and optimizing integrated systems that support enterprise-wide digital transformation initiatives. Develops comprehensive solutions that enhance system reliability, scalability, and security. Leads the evaluation of new technologies and system architectures, providing strategic recommendations to enhance organizational capabilities.
Education and Years of Experience
- Bachelor's degree in Systems Engineering, Computer Science, or related field, and 4+ years of experience, or equivalent relevant work experience; e.g., each year of work experience may be substituted for each year of education required.
Required Skills
- Ability to obtain and maintain a Public Trust Clearance which requires U.S. citizenship.
- 1+ year of experience with supporting Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE Plug-in environments using Veracode .
- 2+ years of experience with Java, Python, .NET, or C#.
- 3+ years of experience using the design and implementation of enterprise-wide security controls to secure applications, systems, network, or infrastructure services.
- Experience with Eclipse, JDeveloper, including pipeline development, or Visual Studio Experience with securing enterprise web applications and OWASP Top 10, CVSS, CWE, WASC, and SANS-25.
- Knowledge of federal compliance standards, including NIST 800-53, FIPS, or FedRAMP.
- 2+ years experience working in Linux based environments, including navigating and troubleshooting basic website connectivity issues
- Familiarity in Linux environment and some type of coding and/or scripting experience is a must.
- The areas of focus for this role are Burp Enterprise experience performing DAST scanning.
- Experience with Burp Professional, with focus on SAST scanning.
- Veracode experience performing SAST scanning.
Preferred Skills
- Experience with Interactive Application Security Testing (IAST) capabilities and tools.
- Experience with HackerOne.
- Experience with Selenium.
- Experience writing bash scripts.
- Experience with OWASP ZAP or Burp Proxy
Our Core Values
Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together.
What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.
- Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
- Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
- Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
- Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
- Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
- Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
Similar Jobs
Fintech • Financial Services
Conduct manual penetration tests and secure code reviews across web applications, APIs, AWS infrastructure, and AI systems. Develop AI-assisted security tooling, test LLM applications and agents, triage SAST findings, tune detection rules, support security reviews before production, and communicate risks and remediation priorities to engineering teams.
Top Skills:
Ai AgentsAPIsAWSGoLlmsPythonRubySastSecure SdlcTypescript
Healthtech • Social Impact • Software
Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development.
Top Skills:
Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling
Software
Own and implement application security across the software development lifecycle for multiple product lines. Define security controls, validation gates, standards, and guardrails; conduct architecture reviews; enhance CI/CD security; triage SAST, SCA, and penetration-testing findings; support incident response; maintain FedRAMP and CJIS compliance; and represent security practices in audits and customer engagements.
Top Skills:
Aws CodepipelineAws GovcloudAws LambdaAzure GovernmentGitlab CiJavaJenkinsNexusPastaSastSbomScaSonarqubeStrideTenableTypescript
What you need to know about the Boston Tech Scene
Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.
Key Facts About Boston Tech
- Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
- Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
- Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
- Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories



