IT Security Specialist / Application Security Engineer (Level IV)

IT Security Specialist / Application Security Engineer (Level IV)

Posted Today by Zolon Tech Solutions Inc

Negotiable
Undetermined
Remote
Remote

Summary: We are looking for a senior IT Security Specialist / Application Security Engineer to support a federal client, focusing on application security, vulnerability management, Azure security engineering, and compliance in a cloud-based environment. The role requires extensive experience in cybersecurity and application security, particularly within Azure. The candidate will be responsible for conducting security assessments, designing security solutions, and ensuring compliance with federal standards. This position is remote and requires a high level of expertise in the field.

Key Responsibilities:

  • Perform application security assessments including SAST/DAST, manual code reviews, and vulnerability remediation
  • Design and support Azure security solutions (Sentinel, Defender, Log Analytics, Intune, WAF)
  • Implement and maintain DevSecOps / CI-CD security pipelines
  • Conduct risk assessments and ensure compliance with NIST/FISMA standards
  • Support incident response, vulnerability management, and security operations
  • Develop and maintain security documentation (SSPs, SARs, POA&Ms)

Key Skills:

  • 8+ years in cybersecurity / application security
  • Hands-on experience with SAST/DAST tools (Fortify, Checkmarx, Veracode, Snyk, AppScan)
  • Experience with manual code reviews (Java, .NET, Python, C#)
  • Strong Azure security experience
  • CI/CD and DevSecOps experience
  • Knowledge of NIST, FISMA, federal security standards

Salary (Rate): undetermined

City: undetermined

Country: undetermined

Working Arrangements: remote

IR35 Status: undetermined

Seniority Level: Senior

Industry: IT

Detailed Description From Employer:

We are seeking a senior IT Security Specialist / Application Security Engineer to support a federal client. The role focuses on application security, vulnerability management, Azure security engineering, and compliance in a cloud-based environment.

Key Responsibilities:

  • Perform application security assessments including SAST/DAST, manual code reviews, and vulnerability remediation

  • Design and support Azure security solutions (Sentinel, Defender, Log Analytics, Intune, WAF)

  • Implement and maintain DevSecOps / CI-CD security pipelines

  • Conduct risk assessments and ensure compliance with NIST/FISMA standards

  • Support incident response, vulnerability management, and security operations

  • Develop and maintain security documentation (SSPs, SARs, POA&Ms)

Required Skills & Experience:

  • 8+ years in cybersecurity / application security

  • Hands-on experience with SAST/DAST tools (Fortify, Checkmarx, Veracode, Snyk, AppScan)

  • Experience with manual code reviews (Java, .NET, Python, C#)

  • Strong Azure security experience

  • CI/CD and DevSecOps experience

  • Knowledge of NIST, FISMA, federal security standards

Certifications (Preferred):
CSSLP, CCSP, OSCP, GWEB, Azure Security Engineer