Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Application Security Engineer image - Rise Careers
Job details

Application Security Engineer

Important Notice for Applicants:


At Bixal, we want to ensure a transparent and secure application process for all candidates. Official communication will come from an email address ending in @bixal.com or from talent@bixal.com. Messages from other sources may be fraudulent, and you should exercise care to avoid any links or attachments included. If you experience any challenges with your submission, please contact us at talent@bixal.com.  We're here to help!


Bixal will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. If you require any accommodation as part of our recruitment process, please contact us at Talent@bixal.com. You can expect a response from a team member within 24 hours during the regular work week and on the next operating day during the weekend or holidays.


About Us:

Bixal is a consulting company based in Fairfax, VA, working alongside governments and organizations to help them deliver better services and experiences to the communities they serve. Using evidence-based knowledge and technology, Bixal empowers clients to deliver on their missions more effectively by fostering a culture of learning and continuous improvement.


Location

This role can work remotely from anywhere in the USA. You must be legally authorized to work in the US. Bixal does not provide visa sponsorship.  

 


What will you do?

Bixal, a fast-growing agency providing holistic Digital Transformation to clients based in Fairfax VA, is seeking an Application Security Engineer to join our dynamic team. You will provide support to Application Development and Design teams to maintain ongoing production needs as well as create new offerings on federal public facing websites and internal/external digital products.

 

This is a full-time position contingent on contract award by our client, with a defined performance period of up to three years. This role offers you a unique opportunity to make a meaningful impact on a project that aligns with Bixal’s mission of delivering innovative, human-centered solutions. While the role has a fixed duration, we are committed to transparency and collaboration, keeping you informed about contract updates and new opportunities. At Bixal, we support your professional journey, ensuring your experience reflects our inclusive, purpose-driven culture and prepares you for future success.


Responsibilities
  • Provide application security expertise, continuous integration, software delivery, software quality, and systems documentation support to digital assets, including the client’s public facing web site, as well as internal software tools
  • Work with the Application Development Team to discuss and implement security remediations for web products
  • Work closely with Cyber Security and Systems Engineering teams to support compliance, secure baseline development, CVE remediation, and the use of best practices in an AWS FISMA moderate environment
  • Provide support to the Application Development Team in configuring and operating continuous integration and delivery (CI/CD) pipelines, incorporating security into build process using tools such as PrismaCloud, and identifying and resolving issues in the build-deploy operation lifecycle
  • Use and apply the findings of robust application security monitoring tools, including assisting in the securing and maintenance of the client’s website and internal software tools
  • Assist in building a strong technical foundation in build, release, and production using continuous integration tools such as Jenkins
  • Engage with various client personnel to understand requirements in order to develop better software for the client and identify new ways in which the development team can easily solve client issues
  • Assist the  Application Development team with security focus through participation in daily standup meetings, monitoring, development, and creating issues in the ticket system
  • Provide training on a variety of security methodologies, best-practices, and tools along with insight into new technologies and solutions that could help the Application Team and the client at large; and
  • Assist in the development of Use Cases, Requirements Definition Documents, User and Administration Manuals, Detailed Design Specifications, and Training Manuals and Plans
  • Perform other duties as required


Qualifications
  • Bachelor's Degree, at least 4 years of relevant experience.
  • Configure, operate, maintain, and monitor various application security tools and services.
  • Experience working with vulnerability scanning tools to identify and resolve security vulnerabilities.
  • Expertise in integrating security testing in automated continuous delivery pipelines (Jenkins/Travis/Ansible).
  • Experience working with a modern web development stack and toolchain.
  • Experience working with open source and community solutions.
  • Experience in FedRamp IaaS/SaaS.
  • Experience with monitoring software dependencies and automating the creation of an SBOM (software bill of materials).
  • Collaborate, champion, and mentor software development teams and other stakeholders on secure software development, delivery, and operations.


$95,000 - $105,000 a year

Perks & Benefits:

Competitive base salary

Flex hours

Work from home flexibility

401K with matching incentive

Parental Leave

Medical/dental/vision benefits

Flex Spending Account

Company provided short-term disability

Company provided life insurance

Commuter benefits

Generous PTO

11 Paid holidays

Professional development opportunities

New business referral bonus


Please note that candidates selected may undergo a background investigation and, if applicable, meet eligibility requirements for suitability.


Bixal is an equal opportunity and affirmative action employer. It ensures equal employment opportunity without discrimination or harassment based on race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity or expression, age, disability, national origin, marital or domestic/civil partnership status, genetic information, citizenship status, veteran status, or any other characteristic protected by law. We are dedicated to promoting diversity, equity, and inclusion within our organization and beyond.

Bixal Glassdoor Company Review
3.5 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Bixal DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Bixal
Bixal CEO photo
Carla Briceno
Approve of CEO

Average salary estimate

$100000 / YEARLY (est.)
min
max
$95000K
$105000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Application Security Engineer, Bixal

Are you ready to make a real difference in the world of application security? At Bixal, we're looking for an Application Security Engineer to join our dynamic team in Washington, D.C. This full-time position is a fantastic opportunity for a motivated individual who wants to play a crucial role in supporting application development teams and securing federal public-facing websites and internal digital products. You'll be on the frontline of ensuring the security of our cutting-edge solutions, working closely with Cyber Security and Systems Engineering teams to implement best practices in an AWS FISMA moderate environment. Your expertise will be essential for conducting vulnerability assessments, securing CI/CD pipelines, and educating the team on security methodologies. With a competitive salary between $95,000 and $105,000 and perks like remote work flexibility and generous PTO, you’ll find a supportive environment that champions professional growth and collaboration. Bixal is committed to fostering a culture of learning and diversity, and we're excited to see how you'll help us deliver innovative and human-centered solutions. So, if you’re looking to take the next step in your career while making a meaningful impact, we’d love to hear from you!

Frequently Asked Questions (FAQs) for Application Security Engineer Role at Bixal
What are the main responsibilities of the Application Security Engineer at Bixal?

As an Application Security Engineer at Bixal, you will provide application security expertise and support the Application Development Team by implementing security remediations for web products, configuring CI/CD pipelines, and utilizing robust application security monitoring tools. You will also work to ensure compliance and best practices within an AWS FISMA moderate environment.

Join Rise to see the full answer
What qualifications are required for the Application Security Engineer position at Bixal?

To qualify for the Application Security Engineer position at Bixal, candidates should possess a Bachelor's Degree and at least four years of relevant experience. They should also have expertise in configuring, operating, and maintaining various application security tools, as well as experience with vulnerability scanning, integrating security in automated delivery pipelines, and working with modern web development tools.

Join Rise to see the full answer
What tools and technologies should an Application Security Engineer at Bixal be proficient in?

An Application Security Engineer at Bixal should be proficient in various application security tools and services, vulnerability scanning tools, tools for automated continuous delivery like Jenkins, and be familiar with open source solutions. Experience with developing software and monitoring dependencies is also a plus.

Join Rise to see the full answer
What is the work culture like for the Application Security Engineer role at Bixal?

The work culture at Bixal for the Application Security Engineer role is inclusive, collaborative, and purpose-driven. We support continuous learning and professional development, making it a perfect environment for those looking to grow in their careers while contributing to innovative solutions.

Join Rise to see the full answer
Is remote work an option for the Application Security Engineer position at Bixal?

Yes! The Application Security Engineer position at Bixal allows for remote work flexibility, making it possible for candidates to work from anywhere in the USA, thus promoting a healthy work-life balance.

Join Rise to see the full answer
Common Interview Questions for Application Security Engineer
Can you explain the role of an Application Security Engineer in a CI/CD pipeline?

An Application Security Engineer plays a vital role in a CI/CD pipeline by integrating security testing into the automation process. This might involve using tools that scan for vulnerabilities during the build process and ensuring that security checks are a key part of the deployment stages.

Join Rise to see the full answer
What experience do you have with vulnerability scanning tools?

When discussing your experience with vulnerability scanning tools, highlight the specific tools you've used, the types of vulnerabilities you've identified and remediated, and how these experiences contributed to overall application security.

Join Rise to see the full answer
How do you stay updated on security vulnerabilities and threats?

Staying up-to-date on security vulnerabilities involves regularly reading security blogs, participating in relevant webinars or conferences, engaging in professional networks, and using threat intelligence platforms to receive updates on emerging trends and vulnerabilities in application security.

Join Rise to see the full answer
Describe a time you resolved a security vulnerability in an application.

Share a specific example of a security vulnerability you identified, the steps you took to resolve it, the outcome of your actions, and any lessons learned. Be sure to outline your problem-solving approach and how it benefited the project or team.

Join Rise to see the full answer
What methods do you use to evaluate the security of a software system?

Evaluating the security of a software system typically involves a combination of manual reviews, automated security testing tools, and compliance checks. Discuss your preferred tools and methodologies, such as static code analysis, dynamic testing, and threat modeling.

Join Rise to see the full answer
How would you explain security concepts to non-technical team members?

When explaining security concepts to non-technical team members, use simple language and relatable analogies. Your goal should be to make the information accessible while ensuring the importance of security is understood.

Join Rise to see the full answer
What is OWASP, and why is it important for application security?

OWASP, or the Open Web Application Security Project, is a nonprofit organization that focuses on improving software security. It provides valuable resources, including the OWASP Top Ten, which outlines the most critical security risks to web applications, making it a key resource for Application Security Engineers.

Join Rise to see the full answer
What role does documentation play in application security?

Documentation is crucial in application security as it ensures that processes, security protocols, and incident responses are clear and accessible. It aids in knowledge transfer, compliance, and maintaining a consistent security posture across development teams.

Join Rise to see the full answer
How do you handle security incidents when they arise?

When handling security incidents, follow a structured incident response plan that includes identification, containment, eradication, recovery, and lessons learned. Emphasize your ability to remain calm under pressure and effectively communicate during a crisis.

Join Rise to see the full answer
What is your experience with cloud security, particularly in AWS?

Discuss your cloud security experience, particularly with AWS, including knowledge of services like IAM, VPC configurations, security groups, and compliance frameworks such as FedRamp. Highlight specific projects or roles where you successfully implemented cloud security best practices.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
Klue Remote Vancouver
Posted 12 days ago
Photo of the Rise User
Convergint Federal Solutions Hybrid 6650 Eli Whitney Dr, Columbia, MD 21046, USA
Posted 5 days ago
Photo of the Rise User
Inclusive & Diverse
Feedback Forward
Collaboration over Competition
Growth & Learning
Photo of the Rise User
Ramboll Hybrid 94 New Karner Rd suite 106, Albany, NY 12203, USA
Posted 12 days ago
Select Labs Inc Remote No location specified
Posted 3 days ago
Tiger Remote No location specified
Posted 10 days ago
Photo of the Rise User
Posted 10 days ago

Bixal is determined to improve people’s lives. The work we do helps our clients unite stakeholders, optimize resources, and better serve citizens all over the world.

68 jobs
MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 27, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!