Application Security Engineer
Job Title: Application Security EngineerLocation: Remote/United StatesDepartment: Cybersecurity / Application SecurityJob Type: Full-Time About Prestige Development Group (PDG)Prestige Development Group (PDG) specializes in providing innovative human capital management solutions tailored to meet the needs of both private and public sector organizations. We are a certified SBA HUBZone and Economically Disadvantaged Woman-Owned Small Business dedicated to fostering diversity, inclusion, and operational excellence. Position SummaryWe are seeking a Application Security Engineer Specialist to support application security assessment, vulnerability management, DevSecOps enablement, and secure reference implementation activities across USCIS systems and delivery environments. This role works closely with development, security, platform, and operations teams to identify application security risks, support remediation, validate fixes, improve security automation, and maintain consistent security practices throughout the application lifecycle.The ideal candidate will also support the development of proof-of-concept reference implementations and utility applications that demonstrate secure design patterns, integrate with DevSecOps tools, and help bridge process and technology gaps between development and security teams.Key ResponsibilitiesPerform application security testing and vulnerability assessments using approved tools, processes, and techniques.Assess web applications, APIs, services, containers, dependencies, and delivery environments for security weaknesses.Support automated security scanning of applications, APIs, services, software dependencies, containers, and CI/CD pipelines.Assist with configuring and maintaining security scanning tools used during development, build, test, release, and runtime activities.Document, triage, track, and validate vulnerabilities and security findings through remediation and closure.Maintain accurate vulnerability status, remediation evidence, and closure documentation.Provide technical guidance to development teams on secure coding practices and remediation of identified weaknesses.Help development teams understand scan results, vulnerable dependency reports, policy violations, and recommended fixes.Support the integration and operation of security tools and controls within CI/CD pipelines.Help implement automated security gates, policy enforcement, and reporting workflows.Integrate DevSecOps tools through APIs to improve visibility, automation, and operational efficiency.Design and develop proof-of-concept sample applications using common technology stacks to demonstrate application security best practices.Build reference examples illustrating secure authentication, authorization, logging, dependency management, secrets handling, containerization, API security, and secure CI/CD workflows.Maintain reusable patterns and examples that development teams can reference when implementing security controls.Identify process and technology gaps between development and security teams.Design and develop utility applications, scripts, dashboards, integrations, and automation workflows that improve vulnerability management, reporting, remediation tracking, tool interoperability, and DevSecOps operations.Integrate with security, development, repository, observability, and CI/CD tools through available API interfaces.Monitor security findings and alignment with established application security standards and controls.Support security improvement initiatives aligned with Zero Trust principles and applicable NIST, CISA, and CIS security frameworks.Collect and maintain security assessment data, scan results, vulnerability evidence, remediation status, and operational metrics.Support reporting for continuous monitoring, vulnerability reduction, and application security improvement initiatives.Support enterprise DevSecOps, vulnerability reduction, secure software development, and application security modernization efforts across USCIS programs.QualificationsRequiredApplication security testing and vulnerability assessment.Secure coding practices and remediation support for development teams.Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), container scanning, and dependency security.CI/CD security integration and DevSecOps automation.Developing proof-of-concept applications or reference implementations using common technology stacks.Developing utility applications, scripts, dashboards, or tool integrations using API interfaces.Vulnerability management workflows, including triage, documentation, remediation tracking, validation, and closure.Security frameworks and guidance, including Zero Trust, NIST, CISA, and CIS.Collaborating with development, security, platform, and operations teams.Preferred:Experience with application security and DevSecOps tools, including SonarQube, Checkmarx, Nexus products, Prisma Cloud/Twistlock, and SAST, DAST, SCA, container, or IaC scanning solutions.Experience with CI/CD platforms, containerized environments, and cloud-native technologies such as Kubernetes, Docker, Harness, Jenkins, GitLab CI, GitHub Actions, or Azure DevOps.Familiarity with monitoring, logging, and project management tools such as Splunk, New Relic, Jira, and ServiceNow.Experience with software package management and build ecosystems, including Maven, Gradle, npm, PyPI, RubyGems, NuGet, and container registries.Knowledge of application security standards and frameworks, including Zero Trust, NIST, CISA, CIS Benchmarks, OWASP Top 10, CWE, CVE/CVSS, and Secure Software Development Lifecycle (SSDLC) practices.Demonstrated ability to build proof-of-concept applications, develop security automation and API integrations, analyze security findings, and translate security framework requirements into practical application security solutions.Compensation & BenefitsSalary Range: (Compliant with salary transparency laws, including California, New York, and Colorado).Equal Employment Opportunity (EEO) StatementPrestige Development Group (PDG) is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. PDG prohibits discrimination and harassment of any kind, including based on race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, disability, genetic information, or any other protected characteristic as outlined by federal, state, or local laws. Americans with Disabilities Act (ADA) StatementPDG is committed to providing reasonable accommodations for individuals with disabilities in our job application and hiring process. Background Check PolicyEmployment is contingent upon the successful completion of a background check. PDG complies with all applicable laws regarding background checks. How to ApplyInterested candidates are encouraged to submit their resume. Applications will be reviewed on a rolling basis until the position is filled.