Demo

Application Security Tooling Engineer (Senior)

take2it
Remote, VA Remote Full Time
POSTED ON 5/31/2026
AVAILABLE BEFORE 6/30/2026

Overview
We are seeking an Application Security Tooling Engineer to design, operate, and continuously improve a defense agency’s application security (AppSec) scanning ecosystem across the software development life cycle (SDLC). This position involves managing and integrating tools such as Sonatype, Fortify, StackRox, and Burp Suite to ensure scalable, auditable, mission-ready security controls in regulated environments. The role requires collaboration with senior leaders to assess and recommend tools, optimize workflows, and support security policies.

Education & Certification Requirements
Not specified.

Clearance Requirements
Secret clearance required; Interim Secret clearance accepted.

Onsite Requirements
This role is a remote opportunity.

Responsibilities

  • Deploy, configure, harden, and maintain AppSec scanning tools in on-prem and cloud environments.
  • Manage tool upgrades, plugins, licensing, capacity planning, backup/restore, high availability, and disaster recovery.
  • Establish SLAs/SLOs, monitoring, alerting, and operational runbooks.
  • Integrate security tools into CI/CD pipelines with policy-based gating and risk management.
  • Standardize secure developer workflows, including pull request checks, nightly scans, and release criteria.
  • Develop reusable templates and reference implementations for development teams.
  • Define and tune scanning policies to reduce false positives/negatives, aligning with agency standards.
  • Maintain an auditable vulnerability workflow, including triage, remediation, and documentation.
  • Provide actionable findings with clear remediation guidance and partner with engineering teams on fixing issues.
  • Implement image scanning, runtime detections, admission controls, and policy enforcement in Kubernetes.
  • Produce metrics and dashboards to monitor vulnerability trends, remediation times, and policy compliance.
  • Support compliance and audit activities by providing scan outputs, control mappings, and procedures.

Qualifications

  • Active Secret clearance required.
  • At least 5 years of experience in application security engineering and/or DevSecOps within regulated environments.
  • Hands-on experience with Sonatype (Nexus IQ), Fortify (SCA/SSC), StackRox/Red Hat ACS, and Burp Suite.
  • Strong CI/CD and automation skills, with the ability to develop repeatable integrations and policy gates.
  • Working knowledge of Secure SDLC, OWASP Top 10, dependency risk, SBOM concepts, container/Kubernetes security.
  • Linux administration, networking fundamentals, TLS/cert management, identity integration (SSO/LDAP).
  • Familiarity with common build systems and languages such as Java/Maven/Gradle, .NET/NuGet, Node/npm, Python/pip.
  • Experience with Oracle Cloud Infrastructure is preferred.

Desired Skills

  • DoD/IC experience with RMF, STIGs, and vulnerability management processes.
  • Familiarity with registries and orchestration platforms such as Harbor, Artifactory, ECR, Kubernetes, OpenShift, Helm.
  • Experience with SIEM/SOAR systems and ticketing platforms like Splunk, ServiceNow, Jira.
  • Relevant certifications, including Security , CISSP, CSSLP, GIAC, or Kubernetes security certifications.

Salary.com Estimation for Application Security Tooling Engineer (Senior) in Remote, VA
$116,219 to $142,220
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Application Security Tooling Engineer (Senior)?

Sign up to receive alerts about other jobs on the Application Security Tooling Engineer (Senior) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$117,871 - $153,580
Income Estimation: 
$131,745 - $167,716
Income Estimation: 
$144,503 - $184,592
Income Estimation: 
$102,541 - $137,871
Income Estimation: 
$153,752 - $200,235
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at take2it

  • take2it Washington, DC
  • Job Title Senior Service Desk Analyst Overview We are seeking a dedicated Senior Service Desk Analyst to support the NTSB program in Washington DC. This ro... more
  • 1 Day Ago

  • take2it Meade, MD
  • Job Title SOAR Engineer Overview We are seeking a skilled SOAR Engineer to join our team and contribute to advanced security operations and threat detectio... more
  • 1 Day Ago

  • take2it Virginia, VA
  • Jr. Identity Security Metrics Consultant & Databricks Analyst Location: Remote (U.S.) Employment Type: Contract Clearance Requirement: Must be eligible to ... more
  • 1 Day Ago

  • take2it Arlington, VA
  • Job Title Sr Data Analyst Overview We are seeking a Part-Time Senior Data Analyst to join our team. This role involves applying advanced data analysis tech... more
  • 1 Day Ago


Not the job you're looking for? Here are some other Application Security Tooling Engineer (Senior) jobs in the Remote, VA area that may be a better fit.

  • Hired Engineer San Diego, CA
  • Industry: Manufacturing & Production Job Category: Manufacturing – Product Development About the Role We are seeking a skilled Tool & Die Maker / Tooling S... more
  • 6 Days Ago

  • EWIE Co., Inc. Three Rivers, MI
  • Looking for a change? You want to work with a company with great benefits and a flexible schedule? Be a part of a solution to help companies be more succes... more
  • 2 Months Ago

AI Assistant is available now!

Feel free to start your new journey!