CACI International Inc logo
CACI International Inc
Posted 33 days agoVerified live 7h ago

Application Security Engineer

Brief overview

Remote
UndergradOr in progress
$75k–$158k/yrStated range
3+ yrsMinimum
Application SecuritySecure SDLCSASTFortifyDASTPenetration TestingOWASP Top 10Secure Code ReviewSecret or TS ClearanceCEHSonarQubeDevSecOpsCI/CD Security IntegrationPython

Job description

Summary

CACI International Inc is a mission-driven company supporting critical Department of Defense missions through cybersecurity solutions. The Application Security Engineer will embed security practices throughout the secure software development lifecycle, perform SAST and DAST, support penetration testing, conduct secure code reviews, track vulnerability remediation, and validate application security controls.

Responsibilities

  • Perform SAST using Fortify across assigned applications
  • Conduct continuous code quality and security analysis using SonarQube
  • Execute DAST to identify runtime vulnerabilities
  • Coordinate and execute penetration testing engagements
  • Conduct secure code reviews and document findings with actionable guidance
  • Track and verify vulnerability remediation through closure
  • Validate application security controls against program and DoD requirements
  • Author application security assessment and penetration test reports
  • Support the Cybersecurity Architect with secure SDLC process design

Skills

  • Active Secret or TS clearance
  • 3–5 years of experience in application security, secure development, or penetration testing
  • Hands‑on experience with **SAST** platforms (Fortify preferred)
  • Working knowledge of **OWASP Top 10** and common application vulnerability classes
  • Demonstrated experience conducting or supporting penetration tests
  • DoD 8140.03M DCWF Basic Tier — CEH
  • **DoD 8140 Interim Education Options**
  • **Required to travel to Scott Airforce base on a quarterly basis**
  • DoD 8140.03M DCWF Intermediate Tier — one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP‑A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+
  • Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems, IT, or Software Engineering
  • Experience with **SonarQube** or similar secure code analysis platforms
  • Familiarity with **DevSecOps** pipelines and CI/CD security integration
  • Scripting or development experience in Python, Java, or similar languages

Qualifications

Must Haves

  • Active Secret or TS clearance
  • 3–5 years of experience in application security, secure development, or penetration testing
  • Hands‑on experience with **SAST** platforms (Fortify preferred)
  • Working knowledge of **OWASP Top 10** and common application vulnerability classes
  • Demonstrated experience conducting or supporting penetration tests
  • DoD 8140.03M DCWF Basic Tier — CEH
  • **DoD 8140 Interim Education Options**
  • **Required to travel to Scott Airforce base on a quarterly basis**

Nice to Haves

  • DoD 8140.03M DCWF Intermediate Tier — one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP‑A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+
  • Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems, IT, or Software Engineering
  • Experience with **SonarQube** or similar secure code analysis platforms
  • Familiarity with **DevSecOps** pipelines and CI/CD security integration
  • Scripting or development experience in Python, Java, or similar languages

Benefits

  • Flexible time off benefit
  • Robust learning resources
  • Healthcare benefits
  • Wellness benefits
  • Financial benefits
  • Retirement benefits
  • Family support benefits
  • Continuing education benefits
  • Time off benefits

More jobs like this