Application Security Engineer - Public Trust/Secret Clearance jobs in United States
cer-icon
Apply on Employer Site
company-logo

Tomorrow · 9 hours ago

Application Security Engineer - Public Trust/Secret Clearance

Tomorrow is a company focused on information technology, and they are seeking an Application Security Engineer to support the secure development and testing of applications. This role involves implementing security controls, conducting application security testing, and ensuring compliance with federal standards in a remote environment.

BankingFinanceFinancial ServicesPersonal Finance
badNo H1BnoteSecurity Clearance Requirednote

Responsibilities

Support Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE Plug-in environments using Veracode and Burp Suite
Design and implement enterprise-wide security controls to secure applications, systems, networks, or infrastructure services
Secure enterprise web applications, with a focus on mitigating OWASP Top 10 risks, CVSS scoring, CWE, WASC, and SANS Top 25 vulnerabilities
Integrate security practices into development workflows using IDEs such as Eclipse, JDeveloper (including pipeline development), or Visual Studio
Perform application security testing and automation using tools such as OWASP ZAP, Burp Proxy, Selenium, and Interactive Application Security Testing (IAST) capabilities
Write and maintain bash scripts to support security automation, testing, and troubleshooting tasks
Participate in vulnerability discovery, triage, and remediation processes, including crowdsourced security programs via platforms like HackerOne
Work in Linux or UNIX environments, including navigating file systems and troubleshooting basic website connectivity and security issues
Ensure applications and security practices align with federal compliance standards, including NIST 800-53, FIPS, or FedRAMP

Qualification

Application Security TestingVulnerability ManagementSecure Coding PracticesSASTDASTOWASP Top 10Linux/UNIX EnvironmentsBash ScriptingCollaboration with Development TeamsNIST Compliance

Required

Support Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE Plug-in environments using Veracode and Burp Suite
Design and implement enterprise-wide security controls to secure applications, systems, networks, or infrastructure services
Secure enterprise web applications, with a focus on mitigating OWASP Top 10 risks, CVSS scoring, CWE, WASC, and SANS Top 25 vulnerabilities
Integrate security practices into development workflows using IDEs such as Eclipse, JDeveloper (including pipeline development), or Visual Studio
Perform application security testing and automation using tools such as OWASP ZAP, Burp Proxy, Selenium, and Interactive Application Security Testing (IAST) capabilities
Write and maintain bash scripts to support security automation, testing, and troubleshooting tasks
Participate in vulnerability discovery, triage, and remediation processes, including crowdsourced security programs via platforms like HackerOne
Work in Linux or UNIX environments, including navigating file systems and troubleshooting basic website connectivity and security issues
Ensure applications and security practices align with federal compliance standards, including NIST 800-53, FIPS, or FedRAMP

Preferred

Clearance: Public Trust, Secret Clearance preferred

Company

Tomorrow

twittertwittertwitter
company-logo
Sustainable banking. Green Finance. A bank that funds and promotes Renewable Energy, Solar Power, Wind Power and sustainable agriculture.

Funding

Current Stage
Growth Stage
Total Funding
$34.76M
Key Investors
ABACON
2024-10-21Series Unknown· $5.41M
2021-10-20Equity Crowdfunding· $9.32M
2021-09-16Series Unknown· $16.48M

Leadership Team

leader-logo
Inas Nureldin
Founder and CEO
linkedin
leader-logo
Jakob Berndt
Co-Founder & Co-CEO
linkedin
Company data provided by crunchbase