IT Security Specialist / Application Security Engineer (Level IV)
Posted Today by Zolon Tech Solutions Inc
Negotiable
Undetermined
Remote
Remote
Summary: We are looking for a senior IT Security Specialist / Application Security Engineer to support a federal client, focusing on application security, vulnerability management, Azure security engineering, and compliance in a cloud-based environment. The role requires extensive experience in cybersecurity and application security, particularly within Azure. The candidate will be responsible for conducting security assessments, designing security solutions, and ensuring compliance with federal standards. This position is remote and requires a high level of expertise in the field.
Key Responsibilities:
- Perform application security assessments including SAST/DAST, manual code reviews, and vulnerability remediation
- Design and support Azure security solutions (Sentinel, Defender, Log Analytics, Intune, WAF)
- Implement and maintain DevSecOps / CI-CD security pipelines
- Conduct risk assessments and ensure compliance with NIST/FISMA standards
- Support incident response, vulnerability management, and security operations
- Develop and maintain security documentation (SSPs, SARs, POA&Ms)
Key Skills:
- 8+ years in cybersecurity / application security
- Hands-on experience with SAST/DAST tools (Fortify, Checkmarx, Veracode, Snyk, AppScan)
- Experience with manual code reviews (Java, .NET, Python, C#)
- Strong Azure security experience
- CI/CD and DevSecOps experience
- Knowledge of NIST, FISMA, federal security standards
Salary (Rate): undetermined
City: undetermined
Country: undetermined
Working Arrangements: remote
IR35 Status: undetermined
Seniority Level: Senior
Industry: IT
We are seeking a senior IT Security Specialist / Application Security Engineer to support a federal client. The role focuses on application security, vulnerability management, Azure security engineering, and compliance in a cloud-based environment.
Key Responsibilities:
Perform application security assessments including SAST/DAST, manual code reviews, and vulnerability remediation
Design and support Azure security solutions (Sentinel, Defender, Log Analytics, Intune, WAF)
Implement and maintain DevSecOps / CI-CD security pipelines
Conduct risk assessments and ensure compliance with NIST/FISMA standards
Support incident response, vulnerability management, and security operations
Develop and maintain security documentation (SSPs, SARs, POA&Ms)
Required Skills & Experience:
8+ years in cybersecurity / application security
Hands-on experience with SAST/DAST tools (Fortify, Checkmarx, Veracode, Snyk, AppScan)
Experience with manual code reviews (Java, .NET, Python, C#)
Strong Azure security experience
CI/CD and DevSecOps experience
Knowledge of NIST, FISMA, federal security standards
Certifications (Preferred):
CSSLP, CCSP, OSCP, GWEB, Azure Security Engineer