Application Cyber Security EngineerLocation: Hybrid – DMV area (DC, MD, VA) | Monthly onsite in Reston, VAGlint Tech Solutions is a women-owned global staffing and IT recruiting firm connecting top technical talent with leading enterprise clients across the United States.Our client, a leading healthcare payor in Reston, VA, is seeking a software-focused Application Cyber Security Engineer to support DevSecOps, AWS Cloud Security, and cloud migration initiatives. This is primarily a remote role with required monthly onsite visits to Reston, VA. Candidates must reside in the DC, MD, or VA area — travel expenses will not be reimbursed.
The interview process includes 2 rounds with a mandatory F2F final round in Reston, VA.Key ResponsibilitiesDevelop and implement application security solutions; architect and engineer trusted systems into secure systemsSupport DevSecOps practices including SAST, DAST, IAST, SCA, penetration testing, secure code review, and threat modelingSecure AWS environments across IAM, EC2, S3, Lambda, EKS, CloudTrail, Security Hub, and GuardDutyManage Kubernetes and container security including Amazon EKS, pod security, RBAC, network policies, and runtime hardeningOperate CNAPP, CSPM, KSPM, and CWPP platforms such as Wiz, CrowdStrike, or similar solutionsMap application and cloud-native controls to frameworks including NIST CSF, NIST 800-53, ISO 27001, SOC2, CIS Benchmarks, and MITRE ATT&CKImplement infrastructure-as-code and policy-as-code using Terraform, Helm, CloudFormation, and Rego/OPACollaborate with development teams to communicate security findings and drive practical remediationAdvise management on cybersecurity policies, processes, and proceduresMandatory SkillsStrong hands-on experience in Application Security, Secure SDLC, DevSecOps, Cloud Security, and Vulnerability ManagementDeep knowledge of OWASP Top 10, API Security Top 10, and secure coding practicesHands-on experience with CNAPP, CSPM, KSPM, CWPP platforms (Wiz, CrowdStrike, or similar)Hands-on AWS cloud security experience across core servicesDeep knowledge of Kubernetes and container security including Amazon EKSStrong CI/CD and DevSecOps pipeline security experienceExperience with IaC and policy-as-code tools — Terraform, Helm, CloudFormation, Rego/OPAStrong written and verbal communication skills for both technical and non-technical audiencesOne or more certifications required: CISSP, CISM, CEH, or CISANice-to-Have SkillsAWS Certified Security Specialty certificationExperience in healthcare or similarly regulated industriesBackground in cloud migration security initiatives
Application Cyber Security Engineer in reston at Unknown Company
This position is listed as full time and able to be worked remotely.