{"schemaVersion":"jobsearcher.job.v1","id":"357ec9e299355a32713db417","url":"https://jobsearcher.com/jobs/357ec9e299355a32713db417","canonicalUrl":"https://jobsearcher.com/jobs/357ec9e299355a32713db417","title":"Application Security Engineer","description":"Company Description\n\nWe were early to the fight against Ubiquitous Technical Surveillance, and we’ve been pushing the edge ever since.\nOur mission is to help government and enterprise organizations understand and manage commercial data risks, shape their digital signatures, and operate with confidence in an increasingly complex information landscape. We build and integrate advanced, tech-forward solutions to problems our customers often don’t know they have – until it matters most.\nWe move fast, think critically, and deliver where it counts.\nWhat’s in it for you?\nWe work hard and do fun things.\nYou’ll work on high-impact, technically challenging problems alongside a team that values teamwork over competition. Veilant offers a solid work-life balance and flexible remote work options. At Veilant, you’ll work with the most talented software developers, systems engineers, and subject matter experts, building tools and systems that make a real difference.\n\nJob Description\n\nVeilant is looking for an Application Security Engineer to join our InfoSec team and help validate, secure, and continuously improve software developed by internal and partner engineering teams.\nThis role is ideal for someone who combines a software engineering foundation with an attacker mindset. You will review major and minor software releases before deployment, identify and validate vulnerabilities, create proof-of-concept demonstrations where appropriate, and provide practical remediation guidance that developers can act on.\nYou will not simply file security tickets and move on. You will work closely with engineering teams to understand application architecture, business logic, user workflows, data sensitivity, and production environments so that your findings are accurate, contextualized, and useful.\nYou will work collaboratively across Veilant’s software, DevSecOps, and infrastructure teams.\nIn this role, you will:\nAudit software releases across major and minor cycles to intercept and remediate security flaws before deployment.\nAnalyze source code to identify, isolate, validate, and contextualize vulnerabilities in complex application codebases.\nBuild safe proof-of-concept examples to demonstrate exploitation paths and verify the real-world impact of discovered risks.\nContextualize findings based on application business logic, user workflows, data sensitivity, and production use cases.\nAuthor clear remediation guidance and partner with development teams to implement effective patches, controls, or architectural mitigations.\nIntercept and analyze application-layer network traffic using tools such as Burp Suite or similar intercepting proxies to inspect encrypted payloads, API calls, and authentication flows.\nAssess and help secure core architectures across REST APIs, SQL databases, PostgreSQL, JWT/OAuth, identity providers, and token-based authentication mechanisms.\nPerform threat modeling for web applications based on use cases, data flows, user roles, trust boundaries, and production environments.\nImprove DevSecOps pipelines by integrating, tuning, and operationalizing SAST, DAST, SCA, IaC scanning, secrets detection, and container security tooling.\nSupport container runtime security efforts using monitoring and runtime protection tools such as Falco, NeuVector, or similar technologies.\nCreate standardized security reporting that translates technical findings into clear risk narratives for both engineering teams and executive stakeholders.\nWhat You Will Accomplish in Your First Six Months\nWithin your first six months, success in this role will look like:\nBuilding a repeatable AppSec review process for major and minor software releases, helping engineering teams identify and resolve security issues before deployment.\nIntegrating and improving SAST, DAST, and SCA checks in CI/CD pipelines so that security testing becomes a reliable part of the development lifecycle rather than a late-stage blocker.\nEstablishing threat modeling practices for web applications using common frameworks and applying them to Veilant’s Angular front-end, Java Spring Boot back-end, REST APIs, SQL databases, and authentication flows.\nPartnering with engineering and software teams to improve secure coding practices through practical feedback, remediation guidance, and collaborative reviews.\nImplementing best practices in container runtime security, including visibility, monitoring, and runtime protections for containerized workloads.\nWriting standardized security reports that clearly communicate risk, impact, and remediation steps for both executive-level stakeholders and engineering teams.\n\nQualifications\n\nWhat We Are Looking For\nStrong candidates will bring:\nAbility to obtain a Security Clearance\n2+ years of software development experience in Java.\nHands-on experience reviewing or securing applications built with Java Spring Boot, Angular, REST APIs, SQL databases, and PostgreSQL.\nWorking knowledge of authentication and authorization technologies, including JWT, OAuth, identity providers, Entra, Keycloak, and token-based access models.\nExperience intercepting, decrypting, manipulating, and analyzing web or application network traffic.\nDemonstrated ability to find, validate, and explain vulnerabilities in a real codebase.\nFamiliarity with CI/CD tools such as GitLab CI, Azure DevOps, or GitHub Actions.\nExperience with containerized environments and orchestration tools such as Kubernetes.\nExposure to infrastructure-as-code and container scanning tools such as Trivy, Kubesec, or similar technologies.\nUnderstanding of cloud hosting environments such as Azure or AWS.\nFamiliarity with secrets management tools such as GitLab Secrets Manager, AWS KMS, Azure Key Vault, or Ansible Vault.\nExperience with automated application security testing, including SAST, DAST, and SCA.\nFamiliarity with runtime security and monitoring tools for containers, such as Falco, NeuVector, or similar platforms.\nHands-on web security testing experience using Burp Suite or comparable tooling.\nStrong written communication skills, including the ability to write reports for both technical and non-technical audiences.\nOSWE, OSCP, and/or GXPN certifications are highly desirable.\nThe Kind of Person Who Will Thrive Here\nYou will do well in this role if you are curious, collaborative, and comfortable working across both code and security. You know how to speak with developers in practical terms, explain risk without creating unnecessary friction, and help teams ship secure software without slowing the mission down.\nYou are someone who can move from reviewing source code, to analyzing an API request, to modeling a threat scenario, to writing a report that an executive can understand. You enjoy solving problems at the root cause, not just documenting symptoms.\n\nAdditional Information\n\nWhy You’ll Love Working Here:\nInnovative Environment: Work in a setting where your ideas and expertise are valued.\nCollaborative Culture: Be part of a team that supports each other and works toward shared goals.\nCareer Growth: Opportunities for professional development and career advancement.\nHere are some Perks!\nFlexible PTO + holidays\nGenerous 401k match benefit up to 10%, with an automatic 3% safe harbor contribution and additional matching based on employee contributions.\nMedical (HSA & PPO Plans Available), dental, vision, disability, and life insurance\nEmployer Contribution to Health Savings Account (HSA)\nLearning & Development opportunities\nProfessional coaching services\nGet the technology you want to do your job\nWe have free daily snacks & drinks\nPhysical Requirements:\nMust be able to remain in a stationary position 50% of the time. The person in this position needs to occasionally move about inside the office\nConstantly work with computers and other information technology equipment\nThe ability to communicate information and ideas in a classroom style format, may stand at a podium for long periods of time\nWe are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, veteran status, or any other characteristic protected by law. We are proud to be an equal opportunity workplace.\nIf you require a reasonable accommodation to apply for a position with Veilant through its online applicant system, please contact Veilant's Talent Management Department at (703) 544-2424 or contact us through e-mail at contact_us@veilant.com","company":"Veilant","rawCompany":"veilant","city":"McLean","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-08-03T15:56:18.426Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application Security Engineer","description":"Company Description\n\nWe were early to the fight against Ubiquitous Technical Surveillance, and we’ve been pushing the edge ever since.\nOur mission is to help government and enterprise organizations understand and manage commercial data risks, shape their digital signatures, and operate with confidence in an increasingly complex information landscape. We build and integrate advanced, tech-forward solutions to problems our customers often don’t know they have – until it matters most.\nWe move fast, think critically, and deliver where it counts.\nWhat’s in it for you?\nWe work hard and do fun things.\nYou’ll work on high-impact, technically challenging problems alongside a team that values teamwork over competition. Veilant offers a solid work-life balance and flexible remote work options. At Veilant, you’ll work with the most talented software developers, systems engineers, and subject matter experts, building tools and systems that make a real difference.\n\nJob Description\n\nVeilant is looking for an Application Security Engineer to join our InfoSec team and help validate, secure, and continuously improve software developed by internal and partner engineering teams.\nThis role is ideal for someone who combines a software engineering foundation with an attacker mindset. You will review major and minor software releases before deployment, identify and validate vulnerabilities, create proof-of-concept demonstrations where appropriate, and provide practical remediation guidance that developers can act on.\nYou will not simply file security tickets and move on. You will work closely with engineering teams to understand application architecture, business logic, user workflows, data sensitivity, and production environments so that your findings are accurate, contextualized, and useful.\nYou will work collaboratively across Veilant’s software, DevSecOps, and infrastructure teams.\nIn this role, you will:\nAudit software releases across major and minor cycles to intercept and remediate security flaws before deployment.\nAnalyze source code to identify, isolate, validate, and contextualize vulnerabilities in complex application codebases.\nBuild safe proof-of-concept examples to demonstrate exploitation paths and verify the real-world impact of discovered risks.\nContextualize findings based on application business logic, user workflows, data sensitivity, and production use cases.\nAuthor clear remediation guidance and partner with development teams to implement effective patches, controls, or architectural mitigations.\nIntercept and analyze application-layer network traffic using tools such as Burp Suite or similar intercepting proxies to inspect encrypted payloads, API calls, and authentication flows.\nAssess and help secure core architectures across REST APIs, SQL databases, PostgreSQL, JWT/OAuth, identity providers, and token-based authentication mechanisms.\nPerform threat modeling for web applications based on use cases, data flows, user roles, trust boundaries, and production environments.\nImprove DevSecOps pipelines by integrating, tuning, and operationalizing SAST, DAST, SCA, IaC scanning, secrets detection, and container security tooling.\nSupport container runtime security efforts using monitoring and runtime protection tools such as Falco, NeuVector, or similar technologies.\nCreate standardized security reporting that translates technical findings into clear risk narratives for both engineering teams and executive stakeholders.\nWhat You Will Accomplish in Your First Six Months\nWithin your first six months, success in this role will look like:\nBuilding a repeatable AppSec review process for major and minor software releases, helping engineering teams identify and resolve security issues before deployment.\nIntegrating and improving SAST, DAST, and SCA checks in CI/CD pipelines so that security testing becomes a reliable part of the development lifecycle rather than a late-stage blocker.\nEstablishing threat modeling practices for web applications using common frameworks and applying them to Veilant’s Angular front-end, Java Spring Boot back-end, REST APIs, SQL databases, and authentication flows.\nPartnering with engineering and software teams to improve secure coding practices through practical feedback, remediation guidance, and collaborative reviews.\nImplementing best practices in container runtime security, including visibility, monitoring, and runtime protections for containerized workloads.\nWriting standardized security reports that clearly communicate risk, impact, and remediation steps for both executive-level stakeholders and engineering teams.\n\nQualifications\n\nWhat We Are Looking For\nStrong candidates will bring:\nAbility to obtain a Security Clearance\n2+ years of software development experience in Java.\nHands-on experience reviewing or securing applications built with Java Spring Boot, Angular, REST APIs, SQL databases, and PostgreSQL.\nWorking knowledge of authentication and authorization technologies, including JWT, OAuth, identity providers, Entra, Keycloak, and token-based access models.\nExperience intercepting, decrypting, manipulating, and analyzing web or application network traffic.\nDemonstrated ability to find, validate, and explain vulnerabilities in a real codebase.\nFamiliarity with CI/CD tools such as GitLab CI, Azure DevOps, or GitHub Actions.\nExperience with containerized environments and orchestration tools such as Kubernetes.\nExposure to infrastructure-as-code and container scanning tools such as Trivy, Kubesec, or similar technologies.\nUnderstanding of cloud hosting environments such as Azure or AWS.\nFamiliarity with secrets management tools such as GitLab Secrets Manager, AWS KMS, Azure Key Vault, or Ansible Vault.\nExperience with automated application security testing, including SAST, DAST, and SCA.\nFamiliarity with runtime security and monitoring tools for containers, such as Falco, NeuVector, or similar platforms.\nHands-on web security testing experience using Burp Suite or comparable tooling.\nStrong written communication skills, including the ability to write reports for both technical and non-technical audiences.\nOSWE, OSCP, and/or GXPN certifications are highly desirable.\nThe Kind of Person Who Will Thrive Here\nYou will do well in this role if you are curious, collaborative, and comfortable working across both code and security. You know how to speak with developers in practical terms, explain risk without creating unnecessary friction, and help teams ship secure software without slowing the mission down.\nYou are someone who can move from reviewing source code, to analyzing an API request, to modeling a threat scenario, to writing a report that an executive can understand. You enjoy solving problems at the root cause, not just documenting symptoms.\n\nAdditional Information\n\nWhy You’ll Love Working Here:\nInnovative Environment: Work in a setting where your ideas and expertise are valued.\nCollaborative Culture: Be part of a team that supports each other and works toward shared goals.\nCareer Growth: Opportunities for professional development and career advancement.\nHere are some Perks!\nFlexible PTO + holidays\nGenerous 401k match benefit up to 10%, with an automatic 3% safe harbor contribution and additional matching based on employee contributions.\nMedical (HSA & PPO Plans Available), dental, vision, disability, and life insurance\nEmployer Contribution to Health Savings Account (HSA)\nLearning & Development opportunities\nProfessional coaching services\nGet the technology you want to do your job\nWe have free daily snacks & drinks\nPhysical Requirements:\nMust be able to remain in a stationary position 50% of the time. The person in this position needs to occasionally move about inside the office\nConstantly work with computers and other information technology equipment\nThe ability to communicate information and ideas in a classroom style format, may stand at a podium for long periods of time\nWe are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, veteran status, or any other characteristic protected by law. We are proud to be an equal opportunity workplace.\nIf you require a reasonable accommodation to apply for a position with Veilant through its online applicant system, please contact Veilant's Talent Management Department at (703) 544-2424 or contact us through e-mail at contact_us@veilant.com","datePosted":"2026-08-03T15:56:18.426Z","dateModified":"2026-08-03T15:56:18.426Z","hiringOrganization":{"@type":"Organization","name":"Veilant","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"McLean","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"357ec9e299355a32713db417"},"url":"https://jobsearcher.com/jobs/357ec9e299355a32713db417"}}